PULSE NAME
Hellsing APT
WHITE Hellsing AlienVault 2015-04-20 Modified: 2017-08-24
121
IOCs
HIGH VOLUME
The Hellsing APT group is currently active in the APAC region, hitting targets mainly in the South China Sea area, with a focus on Malaysia, the Philippines and Indonesia. The group has a relatively small footprint compared to massive operations such as "Equation". Smaller groups can have the advantage of being able to stay under the radar for longer periods of time, which is what happened here.
Indicators of Compromise (59 / 121 total)
All hostname FileHash-MD5 CVE email domain YARA
TYPEINDICATORDESCRIPTIONCREATED
hostname longc.indiadigest.in 2017-08-24
hostname hosts.mysaol.com 2017-08-24
hostname aac.indiadigest.in 2017-08-24
hostname second.photo-frame.com 2017-08-24
hostname webb.huntingtomingalls.com 2017-08-24
hostname freebsd.extrimtur.com 2017-08-24
hostname web01.crabdance.com 2017-08-24
hostname guaranteed9.strangled.net 2017-08-24
hostname philippinenews.mooo.com 2017-08-24
hostname cdi.indiadigest.in 2017-08-24
hostname imgs09.homenet.org 2017-08-24
hostname ld.indiadigest.in 2017-08-24
hostname articles.whynotad.com 2017-08-24
hostname ny.philstarnotice.com 2017-08-24
hostname my.philippinenewss.com 2017-08-24
hostname ng.philstarnotice.com 2017-08-24
hostname df4.huntingtomingalls.com 2017-08-24
hostname afc.philippinenewss.com 2017-08-24
hostname dec.huntingtomingalls.com 2017-08-24
hostname philnews.twilightparadox.com 2017-08-24
hostname web.huntingtomingalls.com 2017-08-24
hostname ima03.now.im 2017-08-24
hostname email.philippinenewss.com 2017-08-24
hostname df2.huntingtomingalls.com 2017-08-24
hostname df3.huntingtomingalls.com 2017-08-24
hostname df5.huntingtomingalls.com 2017-08-24
hostname df1.huntingtomingalls.com 2017-08-24
hostname pic.philstarnotice.com 2017-08-24
hostname img02.mooo.com 2017-08-24
hostname email.philstarnotice.com 2017-08-24
hostname news.huntingtomingalls.com 2017-08-24
hostname pm.philstarnotice.com 2017-08-24
hostname ccid.mooo.com 2017-08-24
hostname mail.philippinenewss.com 2017-08-24
hostname ny.huntingtomingalls.com 2017-08-24
hostname webmm.indiadigest.in 2017-08-24
hostname login.philstarnotice.com 2017-08-24
hostname knl.russkoeumea.com 2017-08-24
hostname af.huntingtomingalls.com 2017-08-24
hostname pop.philippinenewss.com 2017-08-24
hostname afnews.philippinenewss.com 2017-08-24
hostname gr.philippinenewss.com 2017-08-24
hostname de.philippinenewss.com 2017-08-24
hostname news.philstarnotice.com 2017-08-24
hostname new.philippinenewss.com 2017-08-24
hostname shoping.jumpingcrab.com 2017-08-24
hostname ack.philippinenewss.com 2017-08-24
hostname flags13.twilightparadox.com 2017-08-24
hostname files.philippinenewss.com 2017-08-24
hostname so.philippinenewss.com 2017-08-24
hostname na.philstarnotice.com 2017-08-24
hostname na.huntingtomingalls.com 2017-08-24
hostname wg.philippinenewss.com 2017-08-24
hostname pop.philstarnotice.com 2017-08-24
hostname ns01.now.im 2017-08-24
hostname premium9.crabdance.com 2017-08-24
hostname zq.philippinenewss.com 2017-08-24
hostname d6.philippinenewss.com 2017-08-24
hostname files.philstarnotice.com 2017-08-24