PULSE NAME
Credential Phishing Campaign targetting Governments
WHITE Kimsuky AlienVault 2019-09-02 Modified: 2019-09-03
1098
IOCs
HIGH VOLUME
During its investigations and with the cooperation of multiple partners, ANSSI has discovered several clusters of malicious activity, including domain names, subdomains and email addresses, used in a large attack campaign with traces going back to 2017. The threat actor registered multiple domain names, and created several subdomains with a naming pattern revealing its potential targets.
Indicators of Compromise (1 / 1098 total)
All email domain FileHash-SHA256 hostname FileHash-MD5 FileHash-SHA1 URL IPv4
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 9c6f6db86b5ccdda884369c9c52dd8568733e126e6fe9c2350707bb6d59744a1 2019-09-02