IOC Radar
TLP:WHITE19 IOCs

AA24-241A Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations

BO
Botvrij.eu OSINT Feed
Published September 12, 2024Original Report

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTURE45.76.65.42fortigate.forticloud.…api.gupdate.netCAPABILITYunknownVICTIMunknown
Adversary
Infrastructure(6)
Capability
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise19

TypeIndicatorConfidenceScoreFirst Seen
IP45.76.65.42
networkvictim-context
High
68
Jun 2, 26
Domainfortigate.forticloud.online
indicatornetwork
High
68
Jun 2, 26
Domainapi.gupdate.net
indicatornetwork
High
68
Jun 2, 26
IP206.71.148.78
indicatornetwork
High
68
Jun 2, 26
IP193.149.190.248
networkvictim-context
High
68
Jun 2, 26
CVECVE-2023-3519
exploitvulnerability
High
68
Jun 2, 26
CVECVE-2019-19781
exploitvulnerability
High
68
Jun 2, 26
Domaincloud.sophos.one
indicatornetwork
High
68
Jun 2, 26
Domainngrok.io
networkvictim-context
High
68
Jun 2, 26
Domainfiles.catbox.moe
networkvictim-context
High
68
Jun 2, 26
IP167.99.202.130
indicatornetwork
High
68
Jun 2, 26
IP134.209.30.220
indicatornetwork
High
68
Jun 2, 26
IP138.68.90.19
indicatornetwork
High
68
Jun 2, 26
IP78.141.238.182
indicatornetwork
High
68
Jun 2, 26
CVECVE-2022-1388
exploitvulnerability
High
68
Jun 2, 26
CVECVE-2024-24919
exploitvulnerability
High
68
Jun 2, 26
IP193.149.187.41
indicatornetwork
High
68
Jun 2, 26
Domainlogin.forticloud.online
indicatornetwork
High
68
Jun 2, 26
CVECVE-2024-3400
exploitvulnerability
High
68
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph19 total IOCs
IPDomainCVE
IP8Domain6CVE5REPORTAA24-241A Iran-based Cyber
scroll to zoom · drag to pan · click IOC to open