PULSE NAME
Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine
WHITE Gamaredon eric.ford 2022-12-20 Modified: 2023-01-19
1047
IOCs
HIGH VOLUME
Unit 42, a Palo Alto Networks cybersecurity research team, provides an update on Russia's advanced persistent threat (APT) group, Trident Ursa, which invaded Ukraine in February 2014 and continues to operate in cyberspace.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Shadow Chaser
Indicators of Compromise (101 / 1047 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 11475e0cb3b045c0570d5af08ec00f93 MD5 of 3e72981a45dc4bdaa178a3013710873ad90634729ffdd4b2c79c9a3a00f76f43 2022-12-20
FileHash-MD5 284aab4eada2fd522740315ee90efeed MD5 of 0b63f6e7621421de9968d46de243ef769a343b61597816615222387c45df80ae 2022-12-20
FileHash-MD5 2a814cefda8663bce70e7f635fc3d597 MD5 of 499b56f3809508fc3f06f0d342a330bcced94c040e84843784998f1112c78422 2022-12-20
FileHash-MD5 391bb4b08de9e27a22c2514e5b372894 MD5 of ac1f3a43447591c67159528d9c4245ce0b93b129845bed9597d1f39f68dbd72f 2022-12-20
FileHash-MD5 3baec0926b59ebe0cf6274d6a4b3cfe2 MD5 of 0d51b90457c85a0baa6304e1ffef2c3ea5dab3b9d27099551eef60389a34a89b 2022-12-20
FileHash-MD5 6a228d9b6d22c87b0a894d08b1eac926 MD5 of a79704074516589c8a6a20abd6a8bcbbcc5a39a5ddbca714fbbf5346d7035f42 2022-12-20
FileHash-MD5 99027f9e62dfd72ac41d47fd3ab151bd MD5 of c22b20cee83b0802792a683ea7af86230288837bb3857c02e242fb6769fa8b0c 2022-12-20
FileHash-MD5 fb69fdb35859be1141a85a2af804340b MD5 of 303abc6d8ab41cb00e3e7a2165ecc1e7fb4377ba46a9f4213a05f764567182e5 2022-12-20
FileHash-MD5 0155514d07c946140f32660e13fcdb98 MD5 of b9c8ec91559a62baf87305e0ee387bb777da7830a6d9fc72c630e873858ec465 2022-12-20
FileHash-MD5 01d62ba5273d56899f582fe74c6687e6 MD5 of 2b3522012ca39b7a3437e22fa4f88b475c1c7bd5a118a73578aafdf8b274d10d 2022-12-20
FileHash-MD5 0f5a6455191ffce67e0463af46df08e0 MD5 of 74ef9e9a9e11a7e3a95d5689a8479b2c232ba8ff3fc19cf4b78dada092876f66 2022-12-20
FileHash-MD5 150c3cb65f22a5b3438222a53e97226b MD5 of 3dc703eb1eef7f065b567b0fbc00e59792c21ebfcd8e86d9a92e5969786ad99f 2022-12-20
FileHash-MD5 16575e709af0c7143921fa5c56f12b88 MD5 of 461435696303217e3cd5a3d4dd66566983467d7d110866c3bfff2ace8817fe30 2022-12-20
FileHash-MD5 17e0fde738e245dad6d1aaad595c2010 MD5 of a2966cd84a931e6d5bac273e685fa35c637502d023abe45f8573fcb922a7fc5e 2022-12-20
FileHash-MD5 19aed072338e8eb44d26629abd85e7ec MD5 of 0c77295d85214e6f6804af2ad5f4d7fc33eb170a38fad96ca5047ea26a797efb 2022-12-20
FileHash-MD5 21a2e24fc146a7baf47e90651cf397ad MD5 of 2d99e762a41abec05e97dd1260775bad361dfa4e8b4120b912ce9c236331dd3f 2022-12-20
FileHash-MD5 21a643c6cd068e4e6c7fe761defe4ead MD5 of 346e04e4aac231d8bbf050413c7035e45d0b55abe34b689c162b4254cdcfdec2 2022-12-20
FileHash-MD5 2409920929c71b8d2b3504a1fbdc14c7 MD5 of 2de7c6cbb107b72c67711008a704284f24a0e7294316109b87bb6ff1b06fe397 2022-12-20
FileHash-MD5 25386348beb9a15dad1d0b102a1d5269 MD5 of 49005a01e22fefdf05bf73895884258b1f90f35b041563368683910fa5acb199 2022-12-20
FileHash-MD5 26fc6f9843e9e50cb8e82ff8db3d4d59 MD5 of 1ceb22701a5b3dd25761e67b0792cea0fafbab79fb900feea5bd86a63383a048 2022-12-20
FileHash-MD5 2900cabd26068b3715f5043091917085 MD5 of b0c9075097e67ce828731842152ede79895c40b80e86f411c7192661478f43bf 2022-12-20
FileHash-MD5 2b333fc9d4ad9eed100a3644d40b4755 MD5 of 0608ae0f28510591798a1603adabde86a9dbd67e1bfb1713c3f397d0d1a306d1 2022-12-20
FileHash-MD5 2bc17039f0e498f1fde6d20bc5eb95cc MD5 of b730daebaacd060d2fb44b24bc54f02639d01617e7e496cecfe869bd3fe0b536 2022-12-20
FileHash-MD5 2d2b658ba19196327d5354f6bfcd5223 MD5 of b4bfe31ef8c15fbb2cd99a9dbd3ed86b7b10542043985c12d822c7f783481a78 2022-12-20
FileHash-MD5 341879622d76cdb6a8fc2c73e4313783 MD5 of 50733868622234239cedcaaf56a6a980d4caf95e0122ffdfbef1c8f4e0ed0006 2022-12-20
FileHash-MD5 3864263b8b3d86a1f6861b15c646aab0 MD5 of 1281abff0809bbb1de56bed6f5ebfa111c3c42918732ededae63b76007364582 2022-12-20
FileHash-MD5 3c29a13a0469b3b79987baaa2e398657 MD5 of 2f35cce3c4ece454ac24a6764d00239b88baaf0db4056de24c9bb4c4bf27f8a9 2022-12-20
FileHash-MD5 3e0330d3d549be99c743d319231fb158 MD5 of 12fdbc94c9bf46a2081c6a97ac3eed304538efd9720f3ea43067f52c4905a842 2022-12-20
FileHash-MD5 429667d2f3bff40ac115ad98b8c1e128 MD5 of 6f23b8092414e2b2df8747b0a2336b9b5851871b0eb0f5052e720696db946f2d 2022-12-20
FileHash-MD5 4476e879f83e434bbd9a20813ffd3276 MD5 of 0b2b1726727042f6936705e4080df0ae356a478966955e893bccf33a51db3f01 2022-12-20
FileHash-MD5 483658b2432fa32b1a357c38f63a4a15 MD5 of 511f2cb7e0f499e70c7898101b37eceb95f92735ee6a13ac25672d29f03cfc47 2022-12-20
FileHash-MD5 49dd0cea1108cde66d0ec4410cc41688 MD5 of 227394b8a4d575e7350193ac328e6fdb00f64ae96ef080324befe98f8ff07f15 2022-12-20
FileHash-MD5 52cacc019dfbcb3abf84ad302722c359 MD5 of 15328c18410b9fd66a1e4ce8e6a758e2a0d57d9967aa30fac0d5137204309a52 2022-12-20
FileHash-MD5 53db8d539dd1b8f61840812cc8fd0982 MD5 of ac862717600c531846895f8884841d23e52c8332e708ca11c17a5c162ce43432 2022-12-20
FileHash-MD5 54d541e348355bc3cc071fc4571b9791 MD5 of 73638b5f462873785f4af7ca1d2aa31cd631e13e10ee1dcc3ec0f65899f5eff7 2022-12-20
FileHash-MD5 595af9c01c44d733ae4d0c400500e652 MD5 of 10e1b27d4e614972e5a058bf0a42eedc53198713c12c805791c8405486874a39 2022-12-20
FileHash-MD5 5ae91dc5c2f16efbed5548f489f87b93 MD5 of 1ec69271abd8ebd1a42ac1c2fa5cdd9373ff936dc73f246e7f77435c8fa0f84c 2022-12-20
FileHash-MD5 5dc457fe660452cfb5921b80cae81d52 MD5 of 91833e38cb8cf06a1dedbb8f79bd38fe03d42a11b4cdb9e7d1064364decd8a8c 2022-12-20
FileHash-MD5 5f82a6e9801fdbaa9f6b58c3ad83f113 MD5 of 9aa39497b7b2d883a40ff9619f1f0f9052ff19c5f612cfbfe1cc2331c70fd054 2022-12-20
FileHash-MD5 62f8a6689497bb8f2eff1578571f4b3d MD5 of 765081b7cab88b3285da08bf7ec775f066fb5ba7751dd6b316adedee08797b45 2022-12-20
FileHash-MD5 636b5f0398d4c8a8c59936f6ea8b7dcc MD5 of bb58d2e94c3b6de1311018bedca8ae8751470d398d39ed0420b5c6bff436e4cb 2022-12-20
FileHash-MD5 679438c9bd48d1c13be8e88180554653 MD5 of 00ca57feac8695e915664398e82131d9c70a45a68f741b78f13c88ad61c49cda 2022-12-20
FileHash-MD5 68e49d476cabc87e67681963b786e015 MD5 of a39db7794f99327f70f69e31bd4910d1ea30ed7888456a3638534bd1efff2e18 2022-12-20
FileHash-MD5 6a4f94df94670949b2d527fff8e3cd2d MD5 of b90e6e7238c56d80b0b99f154ddfa7d6aa6357523bcf5c21da5eb553501968c7 2022-12-20
FileHash-MD5 6c6fb946f9118c0fbede776838e623db MD5 of 1392a1d3e8853d15db47372849d544650e6ce0bc7f49c8e74746dcb63226e88b 2022-12-20
FileHash-MD5 7208e37192ad6f1d970a94d29ff02073 MD5 of 8f429996f5be9d59d86ba4346de535a25b9a2c3e89cf2e29dbc053d13ae99269 2022-12-20
FileHash-MD5 731d0d62bbf5cde9fadf0ebcff7a9d91 MD5 of 3bdc2d69d7e1625913cf7a9802396b693004ad84a43ee9e57230d22679b46839 2022-12-20
FileHash-MD5 76bdfe083b9038ab35757ba8cfac9a97 MD5 of 7a36935f624855f21c03b17b9b6e652f9b400aec79f6d1f221ef7380f2f9c02e 2022-12-20
FileHash-MD5 776143df6928bc8c81e49b9323aae3fa MD5 of 24ad6b2e079c63fc3f3bf03155b173eec278ebfceff35c8dce811628e34aebc0 2022-12-20
FileHash-MD5 78f25d7b76944b940a92ef0e744841a9 MD5 of 02ed10858a777d2cf2c6cd22dfeccb338aa7ce381273de4eebaf6894334c7a34 2022-12-20
FileHash-MD5 7b71adcc342e48adcae25e9770e75270 MD5 of 0720a9b5ecd98163208ad5d6d041679c0a6954d80685695df55b0e105dca7b09 2022-12-20
FileHash-MD5 872ef25c5c544b277b6185d75f33f9fb MD5 of 09472d6bfb1c142a3b02f73175254a5e961f91e792dc9b347b099944bcfeab6f 2022-12-20
FileHash-MD5 890104bff9ce28d79eac2b86745609d7 MD5 of 581ed090237b314a9f5cd65076cd876c229e1d51328a24effd9c8d812eaebe6a 2022-12-20
FileHash-MD5 8b67098090239bd0d01684410a5d9728 MD5 of 94599c02df35d8cae57136db16dab3b6bba5bccdd73b64f58e0a9e9d0e95b666 2022-12-20
FileHash-MD5 8b8db5fae74aaeb6ffb53fa23faeda22 MD5 of 96d84d3972312dbe93f18ece57d094ad7106a0c74baacdf9db54013d1d53b587 2022-12-20
FileHash-MD5 8cbc6c61e5331432d070dabd84e4e060 MD5 of 4c2f1450e7dfec25f8197c46b2255926dc3e4409a2e1ede6516ba4d83663e66b 2022-12-20
FileHash-MD5 8d0d1be8d63e67c81cdbd74533a56563 MD5 of 53f01a60bcea5a94207cf10d470fccd8ff7785e8a5800e640711697fdc880847 2022-12-20
FileHash-MD5 9c753b6b2ced2d9218ece0fb58bb099f MD5 of 88aed5172c3c225020d97d60b34e815c8883a29a7adf4a19df6680ad5c3c8897 2022-12-20
FileHash-MD5 9c89d9cad32f521fbcf98b492a9cd3ad MD5 of 5c6bd779523cc3e2e2324e64add277359c66ef0e263f0decd447aca95da5b120 2022-12-20
FileHash-MD5 a01f80bb586f104343b2a02badb7853f MD5 of 782a8cc34746ca1ffc7cd83a9cc4cd64c60de2e69622a06d2a01792df2e2573c 2022-12-20
FileHash-MD5 a367898f46c7a8ce0ba6d6e9690cc4b7 MD5 of 94f4b54060f50523380082879ac262e67477acf5656aec3912078e1d756e9f1f 2022-12-20
FileHash-MD5 a4bc385ffef2f9e2da8773f2b2c22523 MD5 of 7c2c376300c1fc562521196458c2594edac152f1ad944c517927b5a12193980c 2022-12-20
FileHash-MD5 a56d1a1a42aa75ff52412668bf64f5c9 MD5 of be79d470c081975528c0736a0aa10214e10e182c8948bc4526138846512f19e7 2022-12-20
FileHash-MD5 a66f3d3e55ce6737b78219bf55771233 MD5 of bad16409348fca445f2e779c22896f3af2326df464f12dbb9c3a0ec591be5d92 2022-12-20
FileHash-MD5 a6fa37788bd599d0196bb74c183fe863 MD5 of 60539634489764d9e590433ef632727aa465075befcb4f2d4f60405c0f8e600c 2022-12-20
FileHash-MD5 a7369742e09707f94c9e4054be133097 MD5 of 731bd088b6413d90c43ba71d41a6c15f0daa06e8acdd6fb7fe0f6a7d12ca7b61 2022-12-20
FileHash-MD5 a73b0a556563b6d285b12f03c79ffa05 MD5 of 7e67d339ef20b288401a5caae6133a7e769f4d8a5fd87daf3331b6e6de26ed1d 2022-12-20
FileHash-MD5 aa8bcae7a54b82bd8ba1510ad2248897 MD5 of aa00b8713ca0340c6526ea60ca3e6538126c61267ed5f6b4777a73fb5c1f4f16 2022-12-20
FileHash-MD5 ab8600c3150ff6a5a803130438fdfae9 MD5 of 53f472e9a3d3471a76f13d12417229d23efd11b047353db8b71793feacafb029 2022-12-20
FileHash-MD5 ae2f35e2bcc863cea728fbb2642a084e MD5 of 570278275cadd350bd65343e67b08c15839c0c4d94b865351a921ced541a91f1 2022-12-20
FileHash-MD5 afab9804b082c31877fddfd509859ca6 MD5 of 449dea773d5d5c156bc72873616df2443a95cbefb9c4a09f86ddb65357edf09e 2022-12-20
FileHash-MD5 b06e5f7a899c631c7df69f8a4cfc75fc MD5 of 19888c043afde1f63f25a807192170bc65377e6c89f693ad7af70c0a03a349ed 2022-12-20
FileHash-MD5 b33161ec3f8931400359f381682b7b8a MD5 of 01da7d2722477522bf5cb0a757d922cfe07575984e15df56cd3658722a907f1b 2022-12-20
FileHash-MD5 b35d924d97aea60a0dbefb0611f479c5 MD5 of b00b5eb4276888a58503d24bc837b15a2992506f9182f33044f0ded0fb52b444 2022-12-20
FileHash-MD5 b5eeb375bb97ca69f2b4ffe6e026f766 MD5 of 78c6b489ac6cebf846aab3687bbe64801fdf924f36f312802c6bb815ed6400ba 2022-12-20
FileHash-MD5 bdd3021c3dcb2f25753cd3fd7b796b33 MD5 of 87c52feffbadf0762f61fb33eda483f9833cd459e4ce05858384b1531cc4f7d3 2022-12-20
FileHash-MD5 c315c7660b28d2a2ae8bc56a26336366 MD5 of 4c92057965c17755edad03110fbd7762c938ebdc92531575f919f9790939488e 2022-12-20
FileHash-MD5 c51ffce3241cee45a861c214670e3ea7 MD5 of 8294815c2342ff11739aff5a55c993f5dd23c6c7caff2ee770e69e88a7c4cb6a 2022-12-20
FileHash-MD5 c9b0e7bf08a61b9e4d91642788533724 MD5 of 0d141ec2034ad934dff08183a7a334605dd11ca9075bdcd6ab176dfb014acfcf 2022-12-20
FileHash-MD5 cef654008f6f530b37ceb884752cd4f9 MD5 of be7d70fb705c74f2de86db2b34f3e7587e5b3ded2d02eaad48fcfee426379372 2022-12-20
FileHash-MD5 d00e962cc92f71ff08b96acdc6e4efe8 MD5 of 12a9d00501a30f1162c183ed66887320b428739659dad2ea49cd0d88fcdd92bb 2022-12-20
FileHash-MD5 d06442612ea815632f5c3a6d116f0dde MD5 of 5a8703f237c1ad6e4ecf8dd21db0ff9b7ca746cc1aae98af4a091d73a1d92e8b 2022-12-20
FileHash-MD5 d3a4c5191834fb47fb49ab6c0b59d71b MD5 of 34bf1a232870df28809597d49a70d9b549d776e1e4beb3308ff6d169a59ecd02 2022-12-20
FileHash-MD5 d62d55566e85add0bb9734f71eca8cdb MD5 of 89db442ddbd539064331f32fa8e78f98d101352e1969389a9e91b543ff69a542 2022-12-20
FileHash-MD5 d8a79a528ee1d19dc7206ea913400869 MD5 of 9e8c79822a4012e7d5fc9c3fe80196d6bbe3be23449069995319c818235eebc5 2022-12-20
FileHash-MD5 defc47401dfb4f80c67550b03bf9a0f3 MD5 of 5264e8a8571fe0ef689933b8bc2ebe46b985c9263b24ea34e306d54358380cbb 2022-12-20
FileHash-MD5 df5e768a1bdf5994b54dd96b09f4068e MD5 of 3d80541e59b4bedac6bd275514c0941b1478d62d6ef8b8560720d05a83c0a910 2022-12-20
FileHash-MD5 dfc0a03230dc0fc173cef7397ad446d5 MD5 of 13ed78244c34f0b9625be4e8d3ccd9ea205ef492e04cc5fad821741b5ece8a0b 2022-12-20
FileHash-MD5 ea7acd3608fd3947a4627fa8f7bb3e13 MD5 of 5619bc25b41f378ded1f11598c87404d06e42a8e4616feeb1392036950817d41 2022-12-20
FileHash-MD5 ea7de5b8af4b00b2e790b4d29ca45ba9 MD5 of 0e0e08882bbb6b0dc2688b998aa6fa84fda3d2f50c0c739515f10cc9ed328794 2022-12-20
FileHash-MD5 ee3661a8a6a1acf33e53f52a1e3a5533 MD5 of 315fdf6913cdcc1b94d3a43df12943164c8f30b89fbd69ccf8a254ca8d2de35a 2022-12-20
FileHash-MD5 eef936dcc99ea3e4684061e6aa4e4715 MD5 of b8062b3012a911f2bf46b3dd85a5d16f1ce41ef21fdf13ab952e6d748b81fcfa 2022-12-20
FileHash-MD5 f117c2f82dd4c982197856d5eaf4455c MD5 of 5c35cd591a4ce0ea3fd685537b54f00fdfe4d0667b745cc556e034e90710d23c 2022-12-20
FileHash-MD5 f1593c4cd631d595410e246993241b5c MD5 of bf39fa0f6a90c0aeae7b01ea33253540431bc6ffcb087a2335d702445180869c 2022-12-20
FileHash-MD5 f407a39bd7d05480ac4c7f934e6d519c MD5 of ab67653691be37c79d8189ae208eb1b37d560614ee4b46d08bd0e254b6eb5cc7 2022-12-20
FileHash-MD5 f46a6211920dd75729aaee4ac9cd0856 MD5 of a9916af0476243e6e0dbef9c45b955959772c4d18b7d1df583623e06414e53b7 2022-12-20
FileHash-MD5 f59107a3d93bba3bf31d3cfe6f85ef8a MD5 of a890ae751310f3cdf83a428a4c9e123a6b74c349ea225b5cd567d38289ab6100 2022-12-20
FileHash-MD5 f72c9718260c96c77d1e0be91b30fcbf MD5 of 92667723d5956259d562e1defb44cb086c13f765087622142196b57320837117 2022-12-20
FileHash-MD5 fa8009ec4b46e0469fb42a58032fcdf7 MD5 of 1cb2d299508739ae85d655efd6470c7402327d799eb4b69974e2efdb9226e447 2022-12-20
FileHash-MD5 fd6dfe6c29042a86d7259c7dad9691ac MD5 of 4a1501eef94c1db03407130afebcaddd9cf7cf1f458636c6390640400a537d59 2022-12-20
FileHash-MD5 fef34c28f4e73d1c8d60dde708819b1a MD5 of 019e0910c6d62d6948ea6f2c83c62491b24cefa4dedc830b93b3c6176a7d9c76 2022-12-20