IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE5 IOCs

From Russia With Code: Disarming Atomic Stealer

RU
RussianPanda
Published January 15, 2024Original Report

Threat Actors

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYSandwormINFRASTRUCTURE5.42.65.108185.106.93.154CAPABILITYunknownVICTIMunknown
Adversary(1)
Infrastructure(2)
Capability
Victim

Indicators of Compromise

Indicators of Compromise5

TypeIndicatorConfidenceScoreFirst Seen
MD5bf7512021dbdce0bd111f7ef1aa615d5
file-hashintel-blogmalware
Medium
53
Oct 9, 26
MD557db36e87549de5cfdada568e0d86bff
file-hashindicatorintel-blog
Medium
53
Oct 9, 26
MD5dd8aa38c7f06cb1c12a4d2c0927b6107
file-hashintel-blogmalware
Medium
53
Oct 9, 26
IP5.42.65.108
intel-blogmalwarenetwork
High
58
Oct 9, 26
IP185.106.93.154
intel-blogmalwarenetwork
High
58
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph5 total IOCs
MD5IP
MD53IP2Actors1REPORTFrom Russia With Code: DisSandworm
scroll to zoom · drag to pan · click IOC to open