Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
TLP:WHITE14 IOCs
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Threat Actors
Malware Families
Diamond Model
Adversary(1)
Infrastructure(6)
Capability(1)
Victim
Indicators of Compromise
Indicators of Compromise14
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| SHA256 | 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 botnetfile-hashintel-blog | High | 86 | Aug 1, 26 |
| IP | 38.146.28.75 aptespionageexploit | High | 72 | Jul 24, 26 |
| IP | 31.57.243.154 aptespionageexploit | High | 72 | Jul 24, 26 |
| URL | https://213.145.86.112/cdn/chunks/polyfill-7e2b.min.js intel-blogmalwarenetwork | High | 58 | Aug 1, 26 |
| IP | 38.146.28.132 aptespionageintel-blog | High | 69 | Aug 1, 26 |
| IP | 107.189.26.194 aptespionageintel-blog | High | 69 | Aug 1, 26 |
| Domain | owa-ms365.com aptespionageintel-blog | High | 72 | Jul 24, 26 |
| SHA256 | be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c botnetfile-hashintel-blog | High | 86 | Aug 1, 26 |
| IP | 104.194.159.150 aptespionageexploit | High | 75 | Jul 24, 26 |
| Domain | m365-owa.com aptespionageintel-blog | High | 72 | Jul 24, 26 |
| URL | https://213.145.86.112/t/event intel-blogmalwarenetwork | High | 58 | Aug 1, 26 |
| Domain | ms365-live.com aptespionageintel-blog | High | 72 | Jul 24, 26 |
| URL | https://213.145.86.112/t/pixel.gif intel-blogmalwarenetwork | High | 58 | Aug 1, 26 |
| Domain | ms365-device.com aptespionageintel-blog | High | 72 | Jul 24, 26 |
IOC Relationship Graph
IOC Relationship Graph14 total IOCs
SHA256IPURLDomain