IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE21 IOCs

Perl based macOS/linux Stealer

RM
Randy McEoin
Published July 20, 2025Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYSandwormINFRASTRUCTUREhttp://213.108.198.22…https://cloudflare.bl…http://213.108.198.22…CAPABILITYMETA StealerVICTIMunknown
Adversary(1)
Infrastructure(6)
Capability(1)
Victim

Indicators of Compromise

Indicators of Compromise21

TypeIndicatorConfidenceScoreFirst Seen
URLhttp://213.108.198.227:8080/get_ip/$current_ip
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://cloudflare.blazing-cloud.com/linux/verify/captcha/
aptespionageintel-blog
High
58
Oct 9, 26
URLhttp://213.108.198.227/parallel
aptespionageintel-blog
High
58
Oct 9, 26
URLhttp://213.108.198.227/data_extracter
aptespionageintel-blog
High
58
Oct 9, 26
URLhttp://cloudflare.blazing-cloud.com/mac/verify/captcha/dj5fbdevxtib
aptespionageintel-blog
High
58
Oct 9, 26
SHA2562f52ced92662bfc025db92787435e0d3f73469fe888973e62c8b5bd830e08e62
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttp://213.108.198.227/start_process_data
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256eafa12df62f778180984cdbb510dabf8a3ad36a3d2cd250dad0ee12cdca1286f
exfiltrationfile-hashintel-blog
Medium
53
Oct 9, 26
SHA25650bc21ca2b8fcfd4d46d51d94ab1ac4450a25167a1607074695a7b048ce3c1b3
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttp://213.108.198.227/fileicon.tar.gz
aptespionageintel-blog
High
58
Oct 9, 26
SHA256d18aa1f4e03b50b649491ca2c401cd8c5e89e72be91ff758952ad2ab5a83135d
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttp://213.108.198.227/curl
aptespionageintel-blog
High
58
Oct 9, 26
SHA25605c922345ab0113c55824a1b2c658b0149a88c4cf4fecc01bf2409bfd81bbca1
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttp://213.108.198.227/util/upload_data/$identifier
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://www.madeinci.ci/socket.io/?EIO=4&transport=websocket
aptespionageintel-blog
High
58
Oct 9, 26
URLhttp://213.108.198.227/notes_processed/$identifier
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA2560d904998d082a51c27c05a23cd62b2f5f030a511af911110a814afffbe3fd1e4
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttp://213.108.198.227/system.pl
aptespionageintel-blog
High
58
Oct 9, 26
URLhttps://cloudflare.blazing-cloud.com/mac/verify/captcha/
aptespionageintel-blog
High
58
Oct 9, 26
SHA2567d3d2d0f17a5ddd1e9c32ad611a8c00bbd53088734784726cd4c6dcd44248a37
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttp://213.108.198.227/data_processed/$identifier
intel-blogmalwarenetwork
High
58
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph21 total IOCs
URLSHA256
URL14SHA2567Actors1Malware1REPORTPerl based macOS/linux SteSandwormMETA Stealer
scroll to zoom · drag to pan · click IOC to open