IOC Radar
TLP:WHITE93 IOCs

Unholy trinity: werewolves target law enforcers

BI
BI.ZONE
Published April 16, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREhttps://synchro-servi…http://203.161.56.226…https://battleflight.…CAPABILITYSliverVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise93

TypeIndicatorConfidenceScoreFirst Seen
SHA256e321a2348bfba68e642f8b13bbdbebc394a4364bddbdadf8b37e4bff80200de1
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://synchro-service.com/array8/array8.json
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256bbbb345cf004992fd8a0ca8c900458f15d6ae939f7f41a60c28a67475af59289
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttp://203.161.56.226/public/starlink
intel-blogmalwarenetwork
High
58
Jun 2, 26
URLhttps://battleflight.org/download/installer
aptespionageexploit
High
58
Jun 2, 26
URLhttps://newfolder.click/?cid=9ebeb834a451460e&amp;mod=main</pre><h4>Domains</h4><pre>stardebug.app<br
intel-blogloadermalware
High
58
Jun 2, 26
Domaincurtainbeatdisturbance.com
c2exploitintel-blog
High
64
Jun 2, 26
SHA256d55a9680b9df14da5e434d5839734c1ed7d9a44348bfd4868e36682203282cc4
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttps://updateserv.net:443/backup/update-subtask-status
intel-blogmalwarenetwork
High
58
Jun 2, 26
URLhttps://servupdate.net/array/array9.json
c2intel-blogmalware
High
58
Jun 2, 26
SHA256a20870bee771efe1ea01761d7978cc7b68b0a3c32c617675464f9c4dbe0a5d66
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttp://203.161.56.226/public/catalog/machine/register
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256c9c9cf72eaf105be6345aef989c88c27d75bbad935efbc349232b84939d59499
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttps://battleflight.pro/static/media/BattleFlight_Installer.exe;
aptespionageexploit
High
58
Jun 2, 26
SHA2565c23d87edca803f7579129a0f6cc18796f67bf55b0c9d053e47edd5f9b501b62
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256edb4e02547daba247fea1f95d5a45f4cf0cc2a35259cd2e07ae5f99c76910751
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttps://web-tellegram.org/socket.io/?EIO=4&amp;transport=polling&amp;t=ikzknftw&amp;sid=0TY7i-pDpxsIn8b4ABJ6.
aptespionageintel-blog
High
58
Jun 2, 26
SHA256dc6243760263153e4245d8ca37821d2ff2889c78bcd9e9849050e10e26ac3fb3
file-hashintel-blogmalware
Medium
53
Jun 2, 26
Domainre-link.space
aptespionageexploit
High
58
Jun 2, 26
SHA2564263c458ef216f8e2524462ea3efe79be44492d51143a519081c429c3c24c166
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://updateserv.net:443/file/uploadChunk
intel-blogmalwarenetwork
High
58
Jun 2, 26
URLhttp://203.161.56.226/public/starlink/starlink-v2
intel-blogmalwarenetwork
High
58
Jun 2, 26
URLhttps://www.alphafly-drones.com/downloads/AlphaFlyInstallV1-2.msi.
exploitintel-blogmalware
High
58
Jun 2, 26
IP104.194.158.63
aptespionageexfiltration
High
58
Jun 2, 26
SHA256aa52dd66071b673416947a798d1f5118405eb94476db08a2ada2eaa5bdeeb276
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://prodacserv.net/array/array10.json
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256d8ad86cf071b914cc0e828c5b3ff68a72fb5ce776f49dd2aa3f56e7d8af142f8
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA25610b6d2cb69d9902afc2157c81b31b066ffd53e9deb156787b68e4fdea2c081b4
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256f8c10fd2b3d254cff0c7927c188a7751568fe7ff3eace1de83bb3148bc14a339
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256df1d20e392f7b7c5c408bdda317e0733e5ec27a973e3bf75034c6566343aa67f
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256ef72cd3ed4b2d86466ad674b09f077f68909038fba8015f95cfddbf4f53900d4
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256aa5f6d919f0f7055e7a22c566463615f208f0b70e5cc56a927baa95796432dcb
file-hashintel-blogmalware
Medium
53
Jun 2, 26
Domainserverscreen.net
intel-blogmalwarenetwork
High
58
Jun 2, 26
URLhttps://updateserv.net:443/check
intel-blogmalwarenetwork
High
58
Jun 2, 26
URLhttps://newfolder.click/?cid=9ebeb834a451460e&amp;mod=main.
aptespionageintel-blog
High
58
Jun 2, 26
Domainmystarlink.org
aptespionageexploit
High
58
Jun 2, 26
SHA256677c5ad47c8feaf6a5c0b084060347bcf48f0ccadcdf951b3d48553f4520feaa
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA2563fe1405a47d1f58c1f7b54d12de574542b32e6d67586d43f119575b906da0a38
file-hashintel-blogloader
Medium
53
Jun 2, 26
Domainupdateserv.net
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA2566498d18edb1d440783ae1e7921ebd491872b81b91968bcb246086bf1e08b68f6
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://updateserv.net:443/cmd/upload-result
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domaintoolsserv.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256ea312fc2bc4dffcaa69d4308ed9d58ae26051285777bbf05665eb625d94dab27
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttps://certcheck.online/certificate/check/Wi5kyh3yFeUF2VhIiFX572eR3870GxYrk7f1Q7MLV5vJ3xGnf4
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256e8de53d4c7558b836f701af0f2e6db5807b10cf9a0d10543bb53357c17b936b3
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256bcc9f8baa79c96e6adfbef6dc35d841b63b5c09029f9845fe52bcd76b53a51b9
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256dbf9a2d1936df83e9764c0233623b581c8e0bf9e331ff0a636721438ce7a1dd5
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttps://updateserv.net:443/backup/get-time
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA25654318d50f463de10661d13701c2acd183a3bd00ea0d01fd74ccdb778f073ea7a
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA25609c83fc5f1656cc4be749c64bfc53d2ef612c9b79dc3937b8bb137754c82216a
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://battleflight.pro/static/media/BattleFlight_Installer.exe
aptespionageexploit
High
58
Jun 2, 26
URLhttps://stardebug.app/static/files/StarDebug_1.0.1.msi
exploitintel-blogmalware
High
58
Jun 2, 26
SHA25634db59b663c15cd03cdd92bf24bdff25b756dd51f0540fecaac2a0cab47480ae
file-hashintel-blogloader
High
61
Jun 2, 26
URLhttps://updateserv.net:443/clients/files
intel-blogmalwarenetwork
High
58
Jun 2, 26
URLhttp://configurationserv.com/tunnel/register
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainservicefor8.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA2565047eae07f5d4dca559c5e04d60ecd775fce4e448d00f7b61c38b737ecbd5586
file-hashintel-blogmalware
Medium
53
Jun 2, 26
Domainupdatewin.net
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA2565d759393935faa272f3a7b2dd827d010abd40ead178aba45b360c83ebbcd5e84
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA25680419e4fbe836b59f96697a8b35acb9903d34796e12ea0cd2349b3c01fe3f9e8
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256c2a86a9fe38f46eea465290e68c8ee90e474acd3c3fa5f0b6704168965e98f8b
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD564d12e5568160c5c32de3373c88db378
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttp://127.0.0.1:5000/373fef3041ec51dd
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA25671155a0940a2c19789d8a8efb285ac3dff5d680a93902901afe6cc893f278ce9
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256487154b1e2a96627d1eeb5d679e3e37269a27701f32b8769b6aa9f9ea640a53c
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256688a1dc207ead232cb8ae6f67fcca1cf7892d83a01af024c404e636cb6ba4cb2
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://newfolder.click/9ebeb834a451460e
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256c1fbd66467449d3c8d9d07a939843a49fad9de9ac484241d52f0d5a94299ca62
file-hashintel-blogloader
Medium
53
Jun 2, 26
SHA256b97fba0accfaf94ae416c2cf1a17a01c281c5565c80fb525ee00f1191a62eff9
file-hashintel-blogmalware
Medium
53
Jun 2, 26
IP145.223.70.69
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256e1f359773da3b014389018ef8a22a15acb2157b43cff5f507237ca7093174b11
file-hashintel-blogmalware
Medium
53
Jun 2, 26
Domainobriy.airforce
aptespionageexploit
High
58
Jun 2, 26
URLhttps://web-tellegram.org/ru
aptespionageexploit
High
58
Jun 2, 26
SHA25682254b86590762b2946c6584db35d3872a5d6b85d30e8c07adb95de2126a4f97
file-hashintel-blogloader
Medium
53
Jun 2, 26
Domainalphafly-drones.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA2565869fb9280846dd77c3fb38b976cf760f889481947cda76a779cf69f48d57daa
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA2563d280f5bb4e1eba8c1a65c7d17411286f7b3dbe7db48130f7d5a3be421ffc2ae
file-hashintel-blogloader
Medium
53
Jun 2, 26
SHA2561951325e1bf6f927ae4bd57fec4d2b5b893cdac2d98c010ef716db254e8d4e7f
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://web-tellegram.org/socket.io/?EIO=4&amp;transport=polling&amp;t=ikzknftw&amp;sid=0TY7i-pDpxsIn8b4ABJ6</pre><h4>Domains</h4><pre>syncheaven.online<br
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainfor8service.net
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256376276fb34d3ce82f2e15b3b27978ffce1896320f4ba226c1eeda778e1fe5714
file-hashintel-blogloader
Medium
53
Jun 2, 26
SHA256b965badd209359e7b19c423e321193b308101b844bdf14704228e27f46c7ffe0
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256cde5ea7788856304e869254fdc90e76adf6990651b72c7351609e707fbf36c0e
file-hashintel-blogmalware
Medium
53
Jun 2, 26
URLhttp://cloudanalitics.net/tunnel/register
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256c43fea1537004b69e1d7b7897af22e7813f4a86f4a53fa44263d3998bfef3a25
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA256471e5e26a0e0796e79e0ef09a0565b7e50c3ff39da0ba42a45c35dcc3922dc2c
file-hashintel-blogloader
Medium
53
Jun 2, 26
SHA2568ac118cc76584487b7f71d91fee2c344a7e33ee8043043920895e9851fa257e2
file-hashintel-blogloader
Medium
53
Jun 2, 26
SHA256996df9ce30ace63c0c516cbacfa4e308b555a2d2c44c9d6550b543b9fccc845d
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://www.alphafly-drones.com/downloads/AlphaFlyInstallV1-2.msi
exploitintel-blogmalware
High
58
Jun 2, 26
SHA25688ebed34ab9ff0e16dc32b789fc25295ea570f86244e89cb68803c517597cfdd
file-hashintel-blogloader
Medium
53
Jun 2, 26
URLhttps://syncheaven.online/sync/now/ru/moscow/fetch
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA2565058b50371a666a585e2438b113825ea07a525b1fe3529a6988e2416d5b4e89d
file-hashintel-blogmalware
Medium
53
Jun 2, 26
SHA2569292fae9b63203cdc0cb204b53314d056e01fc760707dcaa89e66e43d688b25e
file-hashintel-blogloader
Medium
53
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph93 total IOCs
SHA256URLDomainIPMD5
SHA25650URL29Domain11IP2MD51Malware1REPORTUnholy trinity: werewolvesSliver
scroll to zoom · drag to pan · click IOC to open