PULSE NAME
StrongPity APT March-May Campaign
WHITE StrongPity AlienVault 2020-04-20 Modified: 2020-06-26
44
IOCs
MEDIUM VOLUME
StrongPity activity in Turkey, occurring from March into May. See the referenced Alien Labs blog for context on the adversary and how they continue to operate.
Indicators of Compromise (44)
All domain FileHash-SHA256 FileHash-MD5 FileHash-SHA1 URL
TYPEINDICATORDESCRIPTIONCREATED
domain safecopydisk.com 2020-04-20
FileHash-SHA256 1af0958f8590b626bedfcd1972cd3ea49d9576db86f1e768e5520f9615d01a19 2020-04-20
FileHash-MD5 20825af5e06059c5a19f6f77c93d9406 MD5 of 1af0958f8590b626bedfcd1972cd3ea49d9576db86f1e768e5520f9615d01a19 2020-04-20
FileHash-SHA1 3c2f6ebb17c99d08087501173933066fbb8b5b3c SHA1 of 1af0958f8590b626bedfcd1972cd3ea49d9576db86f1e768e5520f9615d01a19 2020-04-20
domain hybirdcloudreportingsoftware.com 2020-04-20
FileHash-SHA256 c72bf8537fc189b81855666d7f59ad8e24011c735921a15932275757a485e7a4 2020-04-20
FileHash-MD5 b647c95b334625c5d94a694ebd483e17 MD5 of c72bf8537fc189b81855666d7f59ad8e24011c735921a15932275757a485e7a4 2020-04-20
FileHash-SHA1 1b8abdba3a95ce3bb7df1a5e8a8fe2a150370177 SHA1 of c72bf8537fc189b81855666d7f59ad8e24011c735921a15932275757a485e7a4 2020-04-20
FileHash-SHA256 12e670dc36ac50e86a58f759fa4a5de25e574227a19e1942aaa788c82540a910 2020-04-20
FileHash-SHA256 2d9bccd93603a60bfb17bf61c032d82adaaf024f21476cdca8c5f4fc11ed7c8b 2020-04-20
domain dangerposedbyhaving.com 2020-04-20
FileHash-SHA256 fbd66a4f385e8c573c51c19a49c7e9c2ffa1639f4648721591b7ea0af845a313 2020-04-20
FileHash-MD5 a2207e7c1910b1fd95b4e178d8613265 MD5 of fbd66a4f385e8c573c51c19a49c7e9c2ffa1639f4648721591b7ea0af845a313 2020-04-20
FileHash-SHA1 e9408833659f6748b5afe215d264667e5d461002 SHA1 of fbd66a4f385e8c573c51c19a49c7e9c2ffa1639f4648721591b7ea0af845a313 2020-04-20
FileHash-SHA256 57b654f88cdec7e5234a698538c99ef1cb2a45a20d8bbcc58f0c3ff19ca87818 2020-04-20
FileHash-SHA256 ef93cfbde5180a90cf19d0c777692501b460ad78ed0a8ab49b3d37da15f608de 2020-04-20
domain mentiononecommon.com 2020-04-20
FileHash-SHA256 e843af007ac3f58e26d5427e537cdbddf33d118c79dfed831eee1ffcce474569 2020-04-20
FileHash-MD5 d7aae4694291a7811c18ccc0af9d4b53 MD5 of e843af007ac3f58e26d5427e537cdbddf33d118c79dfed831eee1ffcce474569 2020-04-20
FileHash-SHA1 a77edc1290e3cf89f570e307036fe23fe9650ea5 SHA1 of e843af007ac3f58e26d5427e537cdbddf33d118c79dfed831eee1ffcce474569 2020-04-20
domain mailtransfersagents.com 2020-04-20
FileHash-SHA256 65041a83c88ba90e489de8ac275688815c51b93ae568c627b74fc160d2db6bab 2020-04-20
FileHash-SHA256 4ee465d58613c03c15c0e92728bba76a065149d4773a1ce59c76d414d70fb190 2020-04-20
FileHash-SHA256 a1ce1b78cc1a9d6092b086f2d0796cde519033ec0935d9cecdea86b6cda87882 2020-04-20
FileHash-MD5 932deeb78301a3edfb0bdc10734f8a4c MD5 of 4ee465d58613c03c15c0e92728bba76a065149d4773a1ce59c76d414d70fb190 2020-04-20
FileHash-MD5 52a895199380705c514dd0a23ba52414 MD5 of a1ce1b78cc1a9d6092b086f2d0796cde519033ec0935d9cecdea86b6cda87882 2020-04-20
FileHash-MD5 2b9ef4ae5ebd8429d6d84c894ecc8fab MD5 of 65041a83c88ba90e489de8ac275688815c51b93ae568c627b74fc160d2db6bab 2020-04-20
FileHash-SHA1 eca4cebc30fcc93ee073185a7a6b2862c116fbd2 SHA1 of 65041a83c88ba90e489de8ac275688815c51b93ae568c627b74fc160d2db6bab 2020-04-20
FileHash-SHA1 b9386ba100f88764cf1472bd1b704146cc992883 SHA1 of 4ee465d58613c03c15c0e92728bba76a065149d4773a1ce59c76d414d70fb190 2020-04-20
FileHash-SHA1 daa7130a286d82b1bd054261514397954ca62e78 SHA1 of a1ce1b78cc1a9d6092b086f2d0796cde519033ec0935d9cecdea86b6cda87882 2020-04-20
FileHash-SHA256 e26a76def39740596843a57c3edcfe9f5000af5f5b538215a5799db58f41fe33 2020-05-04
FileHash-SHA256 40e99d0dfc27c66170ed57610a1c3cc9a0b6e87a0d544d739f828f10faf2758b 2020-05-27
FileHash-SHA256 fcfd34f99b0a5f4bb91c0d6eaa9b2fdcc3bf9b3dd594213a389a056828a537c1 2020-05-27
domain hostoperationsystems.com 2020-05-27
FileHash-SHA256 c2c333a5f46eb5894f05f3323ab8aea87b3c2e9ba0221c28dcf46b0842592ac6 2020-05-27
FileHash-SHA256 5b5b0a0ff8e5bdf11657e0134a638a818e31af9517e5feffea247eaa2660ee23 2020-05-27
URL https://hostoperationsystems.com/parse_ini_file.php 2020-05-27
FileHash-MD5 06752c080a5c00baf971243be65a49b8 MD5 of 5b5b0a0ff8e5bdf11657e0134a638a818e31af9517e5feffea247eaa2660ee23 2020-05-27
FileHash-MD5 faa1ba96a35259af5cdaf48ea76ad984 MD5 of c2c333a5f46eb5894f05f3323ab8aea87b3c2e9ba0221c28dcf46b0842592ac6 2020-05-27
FileHash-SHA1 33c77f4e017fce4fc25809433b58dce27e2f8bfc SHA1 of 5b5b0a0ff8e5bdf11657e0134a638a818e31af9517e5feffea247eaa2660ee23 2020-05-27
FileHash-SHA1 9302b21b03b452007fab6f62adc0d703edc0f81f SHA1 of c2c333a5f46eb5894f05f3323ab8aea87b3c2e9ba0221c28dcf46b0842592ac6 2020-05-27
FileHash-SHA256 91e20fb663b1809279666fb1e7ef7bd8da42ae51e0c05b51515ba851e2a991ac 2020-06-26
FileHash-MD5 d4057c628387f461b15ec7ad78de6ca1 MD5 of 91e20fb663b1809279666fb1e7ef7bd8da42ae51e0c05b51515ba851e2a991ac 2020-06-26
FileHash-SHA1 368fcaaad87f28e2ab2552dc47b701f3b49b02c0 SHA1 of 91e20fb663b1809279666fb1e7ef7bd8da42ae51e0c05b51515ba851e2a991ac 2020-06-26