PULSE NAME
Information Technology Sector Cyber Threat Intel - Key Insights (April 2022)
WHITE Informational SVThreatIntel 2022-05-09 Modified: 2022-06-08
99
IOCs
HIGH VOLUME
In April, a campaign was spotted targeting the Russian officials, that points to a Chinese threat actor known as Mustang Panda. The attackers had employed phishing lures with English docs (named in the Russian language), which pretend to be released by the European Union and come with the details regarding sanctions against Belarus. Other Major Incidents Emotet operators (TA542) were spotted testing new attack techniques. Rocket Kitten was observed abusing a CVE-2022-22954 flaw to deploy the Core Impact Backdoor. A large-scale Monero crypto-mining campaign including LemonDuck malware was targeting the Docker APIs on Linux servers. Modified versions of malicious shell scripts belonging to the TeamTNT threat group were observed. A new Prynt stealer was spotted on the cybercrime forums.
Indicators of Compromise (99)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 53505356c3f1fbf3254deec5bc0408f9 MD5 of 9315e055f4570b7a392447300dcc2ec06f09b57858c131a35e012bd0bb2356cd 2022-05-09
FileHash-MD5 a00bbf635695b13c55e132ca2563755c MD5 of 5e1af7f4e6cf89cff44ee209399a9fab3bfd8f1ca9703fb54cee05cce2b16d4c 2022-05-09
FileHash-MD5 bdb404a243e374cda8948a5480f263e6 MD5 of 33c8591edd61c6e968e727683a63fba0352b5b6b59a0b3005628c38848dd7dd3 2022-05-09
FileHash-MD5 dd89ab7314e13989bdcae176a82078ac MD5 of 1b72088fc6d780da95465f80ab26ba094d89232ff30a41b1b0113c355cfffa57 2022-05-09
FileHash-SHA1 26752d1733f9f7c67d5e0d088af032a6beed94d4 SHA1 of 5e1af7f4e6cf89cff44ee209399a9fab3bfd8f1ca9703fb54cee05cce2b16d4c 2022-05-09
FileHash-SHA1 98bea07044c2a756f5179b8bc776971f9a03b7db SHA1 of 33c8591edd61c6e968e727683a63fba0352b5b6b59a0b3005628c38848dd7dd3 2022-05-09
FileHash-SHA1 9ed46a6dde1dc1de4eed8185c1d622a5fc97092c SHA1 of 1b72088fc6d780da95465f80ab26ba094d89232ff30a41b1b0113c355cfffa57 2022-05-09
FileHash-SHA1 a3b74e6b547a85175ab4faa93ee42d6af6933c93 SHA1 of 9315e055f4570b7a392447300dcc2ec06f09b57858c131a35e012bd0bb2356cd 2022-05-09
FileHash-SHA256 1b72088fc6d780da95465f80ab26ba094d89232ff30a41b1b0113c355cfffa57 2022-05-09
FileHash-SHA256 33c8591edd61c6e968e727683a63fba0352b5b6b59a0b3005628c38848dd7dd3 2022-05-09
FileHash-SHA256 5e1af7f4e6cf89cff44ee209399a9fab3bfd8f1ca9703fb54cee05cce2b16d4c 2022-05-09
FileHash-SHA256 9315e055f4570b7a392447300dcc2ec06f09b57858c131a35e012bd0bb2356cd 2022-05-09
FileHash-MD5 0da186f3e1f8c89c5fbe5672cbdf05b6 MD5 of f82ea98d1dc5d14817c80937b91b381e9cd29d82367a2dfbde60cfb073ea4316 2022-05-09
FileHash-MD5 12e307a30e453c6695669413ed7c08b6 MD5 of 030f3a45d2c0a5200a7fed4734fead988eea4bc1ec48b92e6530610ffd082afe 2022-05-09
FileHash-MD5 4f476e9ea8aed60e29bf06ffe758f841 MD5 of de651f9bc4e26a09a0d1ebc63a36c6139593bef6625822d59b2ccf37452ef716 2022-05-09
FileHash-MD5 51a4ba442533bd0d69e0da7dd46e3d9c MD5 of 024445ae9d41915af25a347e47122db2fbebb223e01acab3dd30de4b35464965 2022-05-09
FileHash-MD5 572c47986c61bf2fcd7f134299fcd5b2 MD5 of af2cf9af17f6db338ba3079b312f182593bad19fab9075a77698f162ce127758 2022-05-09
FileHash-MD5 5ced59b26bef542236d3c11e38cc67d5 MD5 of 79bb16aa326a401e9cd1716d0ea1d6e1fdfdac945a7b4f4f4480be3a1e77cdd3 2022-05-09
FileHash-MD5 69ab42012ddce428c73940dcf343910e MD5 of 698d1ade6defa07fb4e4c12a19ca309957fb9c40 2022-05-09
FileHash-MD5 940c1c591677efbe91d165751296dddd MD5 of ea02410b2983cfa8cf6740f1f0dbd41d3d07da3f8d2b64ca85defa83060cae72 2022-05-09
FileHash-MD5 9ae176daeba86137a994770ec4b4510c MD5 of 2d85b47cdb87a81d5fbac6000b8ee89daa1d8a3c8fbb5d2bce7a840dd348ff1d 2022-05-09
FileHash-MD5 9ca7f7e428ff5e3dbe943efe8ed0df31 MD5 of 7856273b2378b5a46e87fd8f91411c3c068a28c20d120d953e5307d5704ae0a2 2022-05-09
FileHash-MD5 a5f280ef28bf7eea8785db7c05115d01 MD5 of c991bedd44ce0425a157aa0c1fd03d39c5ae2bc019be4518fd979be780889537 2022-05-09
FileHash-MD5 a8415b189839b9585193e2b2ec63d6f3 MD5 of 19575166abd57feccf7cb0a1459daf476e736b7386c54a2b3320b2fc6ae12b9d 2022-05-09
FileHash-MD5 abcfb2660a661a8c0bc4db1417361dd7 MD5 of 451a4cbb6b931d8bb8392f08e7c9ec517b1b1ef06f42e1c8105e4feaafd6b157 2022-05-09
FileHash-MD5 ad3ddb4cbe7ece8cb723f63f3b855b85 MD5 of 6856bb506a0858cc5597666d966b5b7499e38542 2022-05-09
FileHash-MD5 b0a7b7a1cb4bf9a1de7f4b1af46ed956 MD5 of 937975e3ea50c15476aef050295f4031f5fda2a4 2022-05-09
FileHash-MD5 b20ab8eb3c3db7d20cecf44024762bd2 MD5 of 5dc3daf24fcef6ccaef2fec45bbb554f8090930d92a76f5d4c5a1f2487e484e0 2022-05-09
FileHash-MD5 b4da99888db0f0d6e89beaf8e2a23c78 MD5 of 8388b707ddacfa551642a9a20a0eb3b7d40b9bdb8024e4f9c0ce8ee9e8a56d7d 2022-05-09
FileHash-MD5 bcf76b649b5c6016b4071d197b1ce111 MD5 of cef2707760086718175235810e3e49a7bbfedce482dee09eef3d302247e97142 2022-05-09
FileHash-MD5 bd9c6ba78ef91549f38ef76c22a55359 MD5 of 0ae5c1ddf91f8d5e64d58eb5395bf2216cc86d462255868e98cfb70a5a21813f 2022-05-09
FileHash-MD5 c491a19742c352b2c6221037dfac7a4a MD5 of 6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207 2022-05-09
FileHash-MD5 d0295e4ffb268b65f19e7e315f6ec5c6 MD5 of 0dab485f5eacbbaa62c2dd5385a67becf2c352f2ebedd2b5184ab4fba89d8f19 2022-05-09
FileHash-MD5 e2fcb71452e7e4057d144bd1c525432a MD5 of 5483941dcb2fb017850f3d358e4b1cc45837f30f517ebbbb0718947c5c4d5d50 2022-05-09
FileHash-MD5 ec5e39b2e10d2a76df21ab3d9143de42 MD5 of 0085bf33d4e4e051a15a1bd70636055d709aeef79025080afc7a8148ece55339 2022-05-09
FileHash-MD5 f61cb1d3521a5d57440a65fd28c4d5c4 MD5 of 8ee2296a2dc8f15b374e72c21475216e8d20d4e852509beb3cff9e454f4c28d1 2022-05-09
FileHash-MD5 fb3346a3cb6add01efade50b53dd211f MD5 of 96a52109973d50174252b05be64f3ddf0182137fc4186d7a5cef989a4604010d 2022-05-09
FileHash-MD5 fd486a6a0c30fea7fdc578fb576dcd8b MD5 of 721d15556bd3c22f3b4c6240ff9c6d58bfa60b73b3793fa8cdc64b9e89521c5b 2022-05-09
FileHash-SHA1 0164ad6ed68acd956395202fe8fd6561fe10e62c SHA1 of 0dab485f5eacbbaa62c2dd5385a67becf2c352f2ebedd2b5184ab4fba89d8f19 2022-05-09
FileHash-SHA1 0abd884cbd0e633ee45478d827384aeb42f9c188 SHA1 of 7856273b2378b5a46e87fd8f91411c3c068a28c20d120d953e5307d5704ae0a2 2022-05-09
FileHash-SHA1 1ca62ab8821ec9e90cea1fcd0b787478585670e9 SHA1 of 5483941dcb2fb017850f3d358e4b1cc45837f30f517ebbbb0718947c5c4d5d50 2022-05-09
FileHash-SHA1 260b829fbf48e4b75e7273e80d575a5ca3c7a67b SHA1 of 721d15556bd3c22f3b4c6240ff9c6d58bfa60b73b3793fa8cdc64b9e89521c5b 2022-05-09
FileHash-SHA1 2a385fe259a58a878de185fe9b0cc2c6b7c8b394 SHA1 of 8388b707ddacfa551642a9a20a0eb3b7d40b9bdb8024e4f9c0ce8ee9e8a56d7d 2022-05-09
FileHash-SHA1 40c71e31824e73a13cc8837544796a56d038452f SHA1 of 5dc3daf24fcef6ccaef2fec45bbb554f8090930d92a76f5d4c5a1f2487e484e0 2022-05-09
FileHash-SHA1 452c230aa23f0aa222fcf6c57e967909d422b5a1 SHA1 of c991bedd44ce0425a157aa0c1fd03d39c5ae2bc019be4518fd979be780889537 2022-05-09
FileHash-SHA1 48193cee044078ba308b958cc50a42564c581159 SHA1 of af2cf9af17f6db338ba3079b312f182593bad19fab9075a77698f162ce127758 2022-05-09
FileHash-SHA1 4df66291739eb8b5e368cdb4e89b7d768b4e224b SHA1 of de651f9bc4e26a09a0d1ebc63a36c6139593bef6625822d59b2ccf37452ef716 2022-05-09
FileHash-SHA1 5018d8097aadc500c41cbbe6eb314be2f0f13746 SHA1 of 19575166abd57feccf7cb0a1459daf476e736b7386c54a2b3320b2fc6ae12b9d 2022-05-09
FileHash-SHA1 6856bb506a0858cc5597666d966b5b7499e38542 2022-05-09
FileHash-SHA1 698d1ade6defa07fb4e4c12a19ca309957fb9c40 2022-05-09
FileHash-SHA1 6ad3b3d768526e3e43ad01dbb40d24e235dead2d SHA1 of 451a4cbb6b931d8bb8392f08e7c9ec517b1b1ef06f42e1c8105e4feaafd6b157 2022-05-09
FileHash-SHA1 7130d3b630c1702748f53a280cd5b025003bd333 SHA1 of 96a52109973d50174252b05be64f3ddf0182137fc4186d7a5cef989a4604010d 2022-05-09
FileHash-SHA1 75735eee72da072763a716e1457f8e17ebf10868 SHA1 of 0085bf33d4e4e051a15a1bd70636055d709aeef79025080afc7a8148ece55339 2022-05-09
FileHash-SHA1 7a0bf738469861712184b08c1a985099415e2a9c SHA1 of 6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207 2022-05-09
FileHash-SHA1 817e6dde5b33a353c51449b58b3ee4b32679c3d7 SHA1 of 024445ae9d41915af25a347e47122db2fbebb223e01acab3dd30de4b35464965 2022-05-09
FileHash-SHA1 8bccac4c0b2070af21dab7a042035c012cc654b0 SHA1 of ea02410b2983cfa8cf6740f1f0dbd41d3d07da3f8d2b64ca85defa83060cae72 2022-05-09
FileHash-SHA1 8e555384549cc023404fd5d54f59e9ae7f8f4d21 SHA1 of 030f3a45d2c0a5200a7fed4734fead988eea4bc1ec48b92e6530610ffd082afe 2022-05-09
FileHash-SHA1 937975e3ea50c15476aef050295f4031f5fda2a4 2022-05-09
FileHash-SHA1 a5b8141996640c3a594530ce2e2ced5ab20d4a92 SHA1 of 8ee2296a2dc8f15b374e72c21475216e8d20d4e852509beb3cff9e454f4c28d1 2022-05-09
FileHash-SHA1 a917ab4301ab25749d6e867a1812e61b3b09df3f SHA1 of f82ea98d1dc5d14817c80937b91b381e9cd29d82367a2dfbde60cfb073ea4316 2022-05-09
FileHash-SHA1 d569811642f1a77d6fb48c1a6a1483c9cde60693 SHA1 of 79bb16aa326a401e9cd1716d0ea1d6e1fdfdac945a7b4f4f4480be3a1e77cdd3 2022-05-09
FileHash-SHA1 de91c0bff09bc793bbbc52c2e66b7c86307905aa SHA1 of 0ae5c1ddf91f8d5e64d58eb5395bf2216cc86d462255868e98cfb70a5a21813f 2022-05-09
FileHash-SHA1 e7ad20f142e4faad7f37fe06ab6a0e0212387796 SHA1 of 2d85b47cdb87a81d5fbac6000b8ee89daa1d8a3c8fbb5d2bce7a840dd348ff1d 2022-05-09
FileHash-SHA1 f4bb851898a35378e6856181cb1ffc18436ed50b SHA1 of cef2707760086718175235810e3e49a7bbfedce482dee09eef3d302247e97142 2022-05-09
FileHash-SHA256 0085bf33d4e4e051a15a1bd70636055d709aeef79025080afc7a8148ece55339 2022-05-09
FileHash-SHA256 024445ae9d41915af25a347e47122db2fbebb223e01acab3dd30de4b35464965 2022-05-09
FileHash-SHA256 030f3a45d2c0a5200a7fed4734fead988eea4bc1ec48b92e6530610ffd082afe 2022-05-09
FileHash-SHA256 0ae5c1ddf91f8d5e64d58eb5395bf2216cc86d462255868e98cfb70a5a21813f 2022-05-09
FileHash-SHA256 0dab485f5eacbbaa62c2dd5385a67becf2c352f2ebedd2b5184ab4fba89d8f19 2022-05-09
FileHash-SHA256 19575166abd57feccf7cb0a1459daf476e736b7386c54a2b3320b2fc6ae12b9d 2022-05-09
FileHash-SHA256 2d85b47cdb87a81d5fbac6000b8ee89daa1d8a3c8fbb5d2bce7a840dd348ff1d 2022-05-09
FileHash-SHA256 2da9fa07fef0855b4144b70639be4355507612181f9889960253f61eddaa47aa 2022-05-09
FileHash-SHA256 436d5bf9eba974a6e97f6f5159456c642e53213d7e4f8c75db5275b66fedd886 SHA256 of 698d1ade6defa07fb4e4c12a19ca309957fb9c40 2022-05-09
FileHash-SHA256 451a4cbb6b931d8bb8392f08e7c9ec517b1b1ef06f42e1c8105e4feaafd6b157 2022-05-09
FileHash-SHA256 5483941dcb2fb017850f3d358e4b1cc45837f30f517ebbbb0718947c5c4d5d50 2022-05-09
FileHash-SHA256 5dc3daf24fcef6ccaef2fec45bbb554f8090930d92a76f5d4c5a1f2487e484e0 2022-05-09
FileHash-SHA256 6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207 2022-05-09
FileHash-SHA256 721d15556bd3c22f3b4c6240ff9c6d58bfa60b73b3793fa8cdc64b9e89521c5b 2022-05-09
FileHash-SHA256 7856273b2378b5a46e87fd8f91411c3c068a28c20d120d953e5307d5704ae0a2 2022-05-09
FileHash-SHA256 79bb16aa326a401e9cd1716d0ea1d6e1fdfdac945a7b4f4f4480be3a1e77cdd3 2022-05-09
FileHash-SHA256 7bc14d231c92eeeb58197c9fca5c8d029d7e5cf9fbfe257759f5c87da38207d9 2022-05-09
FileHash-SHA256 8388b707ddacfa551642a9a20a0eb3b7d40b9bdb8024e4f9c0ce8ee9e8a56d7d 2022-05-09
FileHash-SHA256 8ee2296a2dc8f15b374e72c21475216e8d20d4e852509beb3cff9e454f4c28d1 2022-05-09
FileHash-SHA256 96a52109973d50174252b05be64f3ddf0182137fc4186d7a5cef989a4604010d 2022-05-09
FileHash-SHA256 af2cf9af17f6db338ba3079b312f182593bad19fab9075a77698f162ce127758 2022-05-09
FileHash-SHA256 c991bedd44ce0425a157aa0c1fd03d39c5ae2bc019be4518fd979be780889537 2022-05-09
FileHash-SHA256 ca622bdc2b66f0825890d36ec09e6a64e631638fd1792d792cfa02048c27c69f SHA256 of 6856bb506a0858cc5597666d966b5b7499e38542 2022-05-09
FileHash-SHA256 cef2707760086718175235810e3e49a7bbfedce482dee09eef3d302247e97142 2022-05-09
FileHash-SHA256 dbdbc7ede98fa17c36ea8f0516cc50b138fbe63af659feb69990cc88bf7df0ad SHA256 of 937975e3ea50c15476aef050295f4031f5fda2a4 2022-05-09
FileHash-SHA256 de651f9bc4e26a09a0d1ebc63a36c6139593bef6625822d59b2ccf37452ef716 2022-05-09
FileHash-SHA256 ea02410b2983cfa8cf6740f1f0dbd41d3d07da3f8d2b64ca85defa83060cae72 2022-05-09
FileHash-SHA256 f82ea98d1dc5d14817c80937b91b381e9cd29d82367a2dfbde60cfb073ea4316 2022-05-09
URL http://107.178.71.211/eu/docconvdll.dll 2022-05-09
URL http://107.178.71.211/eu/fontlog.dat 2022-05-09
URL http://138.124.184.220/work_443.bin_m2.ps1 746ffc3bb7fbe4ad229af1ed9b6e1db314880c0f9cb55aec5f56da79bce2f79b 2022-05-09
domain chimaera.cc 2022-05-09
domain locvnpt.com 2022-05-09
domain teamtnt.red 2022-05-09
domain zyber-i.com 2022-05-09