PULSE NAME
Government Sector Cyber Threat Intel - Key Insights (March 2022)
WHITE Informational SVThreatIntel 2022-04-07 Modified: 2022-05-07
129
IOCs
HIGH VOLUME
In March, a Transparent Tribe campaign was found targeting the Indian government and military entities. The attacker was infecting victims with CrimsonRAT along with new stagers and implants. Further, the attackers created fake domains mimicking legitimate military and defense organizations. Other Major Incidents Cybercriminals identified as Curious Gorge, Ghostwriter APT, and COLDRIVER were targeting NATO and Eastern European countries by launching phishing and malware attacks. Mustang Panda, UNC1151, and SCARAB were using war-related themes to target mostly Ukraine in a spear-phishing campaign. Hong Kong’s electoral office apologized after an employee failed to follow guidelines and sent the personal details of voters to a random email address.
Indicators of Compromise (21 / 129 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 341610a5a0cc430f99f9f9bd694b04a9 MD5 of c7dd490adb297b7f529950778b5a426e8068ea2df58be5d8fd49fe55b5331e28 2022-04-07
FileHash-MD5 039c162d7fcd8640b337173e323f94d8 MD5 of 84841490ea2b637494257e9fe23922e5f827190ae3e4c32134cadb81319ebc34 2022-04-07
FileHash-MD5 1a080ac310668e90e3b035cc3ee1a226 MD5 of 56f04a39103372acc0f5e9b01236059ab62ea3d5f8236280c112e473672332b1 2022-04-07
FileHash-MD5 1ee6d95284b64bdf5a8b44db68498ba1 MD5 of e3e9bbdaa4be7ad758b0716ee11ec67bf20646bce620a86c1f223fd2c8d43744 2022-04-07
FileHash-MD5 2a189ad9398044ecf0087abc4d331910 MD5 of 5c341d34827c361ba2034cb03dea665a873016574f3b4ff9d208a9760f61b552 2022-04-07
FileHash-MD5 3365d7f306693a4466ed8ff6546fceb7 MD5 of dd23162785ed4e42fc1abed4addcab2219f45c802cccd35b2329606d81f2db71 2022-04-07
FileHash-MD5 47285fad72b725671074d9beeebc8bcd MD5 of 1ba7cf0050343faf845553556b5516d96c7c79f9f39899839c1ca9149cf2d838 2022-04-07
FileHash-MD5 49e8853801554d9de4dd281828094c8a MD5 of 85fa43c3f84b31fbe34bf078af5a614612d32282d7b14523610a13944aadaacb 2022-04-07
FileHash-MD5 4d499b6d7b4106c52e650607cd9e25e7 MD5 of 9d4640bde3daf44cc4258eb5f294ca478306aa5268c7d314fc5019cf783041f0 2022-04-07
FileHash-MD5 529ba5d2c599a72bb56a4b66214af1ae MD5 of a0f6963845d7aeae328048da66059059fdbcb6cc30712fd10a34018caf0bd28a 2022-04-07
FileHash-MD5 56302037bdffd6bf5a0d06bfc71de559 MD5 of 67ad0b41255eca1bba7b0dc6c7bd5bd1d5d74640f65d7a290a8d18fba1372918 2022-04-07
FileHash-MD5 5cbcc3485f4286098b3a111ceec8ce54 MD5 of d2113b820db894f08c47aa905b6f643b1e6f38cce7adf7bf7b14d8308c3eaf6e 2022-04-07
FileHash-MD5 68d73d596a7103e517967f7f4e22cecb MD5 of 99e6e510722068031777c6470d06e31e020451aa86b3db995755d1af49cc5f9e 2022-04-07
FileHash-MD5 9dadf9ce41994f869e8c35e1917b8238 MD5 of b3bc8f9353558b7a07293e13dddb104ed6c3f9e5e9ce2d4b7fd8f47b0e3cc3a5 2022-04-07
FileHash-MD5 ae20da9a88c7624a6b3f81a20bc8065c MD5 of 124023c0cf0524a73dabd6e5bb3f7d61d42dfd3867d699c59770846aae1231ce 2022-04-07
FileHash-MD5 b03e0568a5f26addc51c8a3e32baeb7f MD5 of 5911f5bd310e943774a0ca7ceb308d4e03c33829bcc02a5e7bdedfeb8c18f515 2022-04-07
FileHash-MD5 b579c4a8dd622af458463ac3c76412ca MD5 of 4d14df9d5fa637dae03b08dda8fe6de909326d2a1d57221d73ab3938dfe69498 2022-04-07
FileHash-MD5 c08e1509f379755df710d5a8fd4ff175 MD5 of aadaa8d23cc2e49f9f3624038566c3ebb38f5d955b031d47b79dcfc94864ce40 2022-04-07
FileHash-MD5 cd701c7bbec38a22903205b2c68780d0 MD5 of 5e645eb1a828cef61f70ecbd651dba5433e250b4724e1408702ac13d2b6ab836 2022-04-07
FileHash-MD5 d9481ffdea223ab650226f09cbcd0929 MD5 of c828bccfc34f16983f624f00d45e54335804b77dd199139b80841ad63b42c1f3 2022-04-07
FileHash-MD5 e389c230bf9e0839a8977bf1f7fc59cd MD5 of d9037f637566d20416c37bad76416328920997f22ffec9340610f2ea871522d8 2022-04-07