TLP:WHITE145 IOCs
Beyond the Surface: the evolution and expansion of the SideWinder APT group
Diamond Model
Adversary
Infrastructure(6)
Capability
Victim
5W+H Threat Analysis
Analysis unavailable
Indicators of Compromise
Indicators of Compromise145
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| Domain | dirctt88.co indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | aliyum.tech loadermalwarenetwork | High | 68 | Jun 2, 26 |
| MD5 | c3ce4094b3411060928143f63701aa2e file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | kernet.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | asyn.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | u1x.co indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 101a63ecdd8c68434c665bf2b1d3ffc7 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | d0d1fba6bb7be933889ace0d6955a1d7 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | moittpk.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | tsinghua-edu.tech indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | tex-ideas.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | pmd-office.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | tazze.co indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | colot.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | dafpak.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | ntcpak.org indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 2f4ba98dcd45e59fca488f436ab13501 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | directt888.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | newoutlook.live indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 5718c0d69939284ce4f6e0ce580958df file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 1be93704870afd0b22a4475014f199c3 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | detru.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | update-govpk.co indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | nventic.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | scrabt.tech indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | numzy.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | decoty.tech indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | kretic.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | bol-south.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | mfagov.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | widge.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | dirctt88.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | defenec.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | govpk.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | cnsa-gov.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | nactagovpk.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | ujsen.net indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 4a5e818178f9b2dc48839a5dbe0e3cc1 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | condet.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | ntcpak.live indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 2011658436a7b04935c06f59a5db7161 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | paknavy-gov.org indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | b69867ee5b9581687cef96e873b775ff file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | shipping-policy.info indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | d885df399fc9f6c80e2df0c290414c2f file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | dgps-govpk.co indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | ntcpk.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | numpy.info indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 423e150d91edc568546f0d2f064a8bf1 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | download-file.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | mfa-govt.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | mod-gov-pk.live indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | office-drive.live indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | dytt88.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | sjfu-edu.co indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | ausibedu.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | ntcpk.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | pafgovt.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | pmd-office.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | direct888.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | nopler.live indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | updtesession.online indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | bf16760ee49742225fdb2a73c1bd83c7 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | dgps-govpk.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | paknavy-govpk.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | pdfrdr-update.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | fia-gov.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | grouit.tech indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | b3650a88a50108873fc45ad3c249671a file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | donwload-file.com indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 26aa30505d8358ebeb5ee15aecb1cbb0 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | dynat.tech indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | aliyumm.tech indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 3ede84d84c02aa7483eb734776a20dea file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | fia-gov.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | jmicc.xyz indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | healththebest.com indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 54aadadcf77dec53b2566fe61b034384 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | gtrec.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | lforvk.com indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | f840c721e533c05d152d2bc7bf1bc165 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 92dd91a5e3dfb6260e13c8033b729e03 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 0fbb71525d65f0196a9bfbffea285b18 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | c87eb71ff038df7b517644fa5c097eac aptespionagefile-hash | High | 68 | Jun 2, 26 |
| MD5 | 8d7c43913eba26f96cd656966c1e26d5 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | pdfrdr-update.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | alit.live loadermalwarenetwork | High | 68 | Jun 2, 26 |
| Domain | 163inc.com loadermalwarenetwork | High | 68 | Jun 2, 26 |
| Domain | mfa-gov.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | mshealthcheck.live indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | mofagovs.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | govpk.net indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 5cc784afb69c153ab325266e8a7afaf4 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 86eeb037f5669bff655de1e08199a554 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | gov-govpk.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | pmd-office.live indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 8e8b61e5fb6f6792f2bee0ec947f1989 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | comptes.tech indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | direct88.co indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | tni-mil.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | navy-mil.co indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 47f51c7f31ab4a0d91a0f4c07b2f99d7 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | e1x.tech indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | f3058ac120a2ae7807f36899e27784ea file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 515d2d6f91ba4b76847301855dfc0e83 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 412b6ac53aeadb08449e41dccffb1abe file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 3a6916192106ae3ac7e55bd357bc5eee file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 4c40fcb2a12f171533fc070464db96d1 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 8f83d19c2efc062e8983bce83062c9b6 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | e1ix.mov indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 1ed7ad166567c46f71dc703e55d31c7a file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | newmofa.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | conft.live indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | 126-com.live loadermalwarenetwork | High | 68 | Jun 2, 26 |
| Domain | defpak.org indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | mfas.pro indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 1c36177ac4423129e301c5a40247f180 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | mfa-gov.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | mofa.email indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | afmat.tech loadermalwarenetwork | High | 68 | Jun 2, 26 |
| MD5 | e1bdfa55227d37a71cdc248dc9512296 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 6cf6d55a3968e2176db2bba2134bbe94 aptespionagefile-hash | High | 68 | Jun 2, 26 |
| Domain | dinfed.co indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | paknavy-govpk.info indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 2f0e150e3d6dbb1624c727d1a641e754 file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | 3a036a1846bfeceb615101b10c7c910e file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | tumet.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | moittpk.net indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 7e97cbf25eef7fc79828c033049822af file-hashloadermalware | High | 68 | Jun 2, 26 |
| MD5 | ea4b3f023bac3ad1a982cace9a6eafc3 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | mitlec.site indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 44dbdd87b60c20b22d2a7926ad2d7bea file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | ptcl-net.com indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 873079cd3e635adb609c38af71bad702 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | mfacom.org indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 8202209354ece5c53648c52bdbd064f0 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | downld.net indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | eef9c0a9e364b4516a83a92592ffc831 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | support-update.info indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | dowmload.net indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | donwloaded.com indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | 3233db78e37302b47436b550a21cdaf9 file-hashloadermalware | High | 68 | Jun 2, 26 |
| Domain | downloadabledocx.com indicatornetwork | High | 68 | Jun 2, 26 |
| Domain | donwloaded.net indicatornetwork | High | 68 | Jun 2, 26 |
| MD5 | e706fc65f433e54538a3dbb1c359d75f file-hashloadermalware | High | 68 | Jun 2, 26 |
IOC Relationship Graph
IOC Relationship Graph145 total IOCs
DomainMD5