PULSE NAME
DISGOMOJI Malware Used to Target Indian Government
WHITE UTA0137 AlienVault 2024-06-18 Modified: 2024-07-18
254
IOCs
HIGH VOLUME
Volexity identified a cyber-espionage campaign by a suspected Pakistan-based threat actor tracked as UTA0137 targeting government entities in India. The campaign leveraged the DISGOMOJI malware, a Golang-based Linux trojan that uses Discord for command and control via emojis. Key capabilities include data exfiltration, persistence mechanisms, and the ability to execute arbitrary commands. Volexity uncovered UTA0137's use of the DirtyPipe exploit against vulnerable BOSS Linux systems, as well as their post-exploitation tactics like network scanning and tunneling. The intrusions appear successful, highlighting UTA0137's evolving tradecraft and persistent interest in Indian targets.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
DISGOMOJI
Indicators of Compromise (254)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2022-0847 2024-06-18
CVE CVE-2024-3400 2024-06-18
FileHash-MD5 2d4a5050c7ea6c83665807df151e067e 2024-06-18
FileHash-MD5 8bf9cf1363e404a9ad3e0fa9e53057cb 2024-06-18
FileHash-MD5 d5f2e3fafbb0701dc0f1adccc7141e63 2024-06-18
FileHash-SHA1 0d4111ab5471c7f5b909bff336ba8cd66f9d8630 2024-06-18
FileHash-SHA1 1443e58a298458c30ab91b37c0335bdadbacd756 2024-06-18
FileHash-SHA1 2dfe824d0298201e0efb30f16b3ce8a409ffe006 2024-06-18
FileHash-SHA1 3dff44bede709295fffd3ae3e9599f6ab8197af4 2024-06-18
FileHash-SHA1 e1bdb995998ab338fc596777a78121fc49f002b5 2024-06-18
FileHash-SHA1 e5182d13d66c3efaa7676510581d622f98471895 2024-06-18
FileHash-SHA256 1e45d68106ca78f46be508427362b8ce24fdf5485c368f9369c913935cf04f99 2024-06-18
FileHash-SHA256 c981aa1f05adf030bacffc0e279cf9dc93cef877f7bce33ee27e9296363cf002 2024-06-18
FileHash-SHA256 d9f29a626857fa251393f056e454dfc02de53288ebe89a282bad38d03f614529 2024-06-18
URL http://ordai.quest/vmcoreinfo 2024-06-18
domain clawsindia.in 2024-06-18
domain ordai.quest 2024-06-18
FileHash-MD5 01c34ccd7ca7c5cdf88272d8c9071004 2024-06-18
FileHash-MD5 04a3f16c76f2e6d9eba34dd132fc8c27 2024-06-18
FileHash-MD5 13ee4bd10f05ee0499e18de68b3ea4d5 2024-06-18
FileHash-MD5 199c855998aedb0ce46e8d34c05eb0cb 2024-06-18
FileHash-MD5 20b4eb5787faa00474f7d27c0fea1e4b 2024-06-18
FileHash-MD5 237961bbba6d4aa2e0fae720d4ece439 2024-06-18
FileHash-MD5 2bf596603c432fa46b494dc3edd2d30f 2024-06-18
FileHash-MD5 2c06e31bc2969df108697061325b2e8a 2024-06-18
FileHash-MD5 2d4a5050c7ea6c83665807df151e067e MD5 of e5182d13d66c3efaa7676510581d622f98471895 2024-06-18
FileHash-MD5 3ce8dfb3f1bff805cb6b85a9e950b3a2 2024-06-18
FileHash-MD5 3d4e5dbf9b7a6e7336a354b71d4d1a8b 2024-06-18
FileHash-MD5 49cbbf586ba1480599be02915e5a8b34 MD5 of 31a1b6e836684c6d7b5d8f7a099dbe090282cbb0 2024-06-18
FileHash-MD5 501a6d48fd8f80a134cf71db3804cf95 2024-06-18
FileHash-MD5 50fe93394528a0ede52f9eec6c1bf505 2024-06-18
FileHash-MD5 52992eb3a59d7acb736cf9b607337d62 MD5 of 1c8cfa8f36897b6b1179dc4bce49b0e2f86e1a4e 2024-06-18
FileHash-MD5 55c90ff429e4fd72034922383aa31078 2024-06-18
FileHash-MD5 56cb95b63162d0dfceb30100ded1131a 2024-06-18
FileHash-MD5 56cc70b66be99e01d354ba2aaf88041e MD5 of 749a8d081e075b921436d07e323964da88bff609 2024-06-18
FileHash-MD5 60fc5dc410b7482566a74d03549d8246 2024-06-18
FileHash-MD5 635864ff270cf8e366a7747fb5996766 2024-06-18
FileHash-MD5 777cbc972609d26fe6597a442cdf4589 2024-06-18
FileHash-MD5 898bfd3df2ccd9508e0bfab672f5f61a MD5 of 5b7b0b0d7d59e616b0cf75a25ad67dfca89495c4 2024-06-18
FileHash-MD5 8bf9cf1363e404a9ad3e0fa9e53057cb MD5 of 3dff44bede709295fffd3ae3e9599f6ab8197af4 2024-06-18
FileHash-MD5 9012904377e6934797c8689b8c9268c6 2024-06-18
FileHash-MD5 95e17125be0b0f4a4ea1b3d01cc73238 2024-06-18
FileHash-MD5 9821c180f81512f1b72c46e462fc759a MD5 of d0aff8489c02230d4c0935e21125f81895bf6cde 2024-06-18
FileHash-MD5 9f24f757b151a1d81f714075fe7d33d4 2024-06-18
FileHash-MD5 9f3359ae571c247a8be28c0684678304 2024-06-18
FileHash-MD5 a9182c812c7f7d3e505677a57c8a353b 2024-06-18
FileHash-MD5 b4983913d49a2a49545ebe59cd27a7d1 2024-06-18
FileHash-MD5 c9969ece7bb47efac4b3b04cdc1538e5 2024-06-18
FileHash-MD5 cd7067d58e2319ebc8ed0ecd6b61b2b6 2024-06-18
FileHash-MD5 d5f2e3fafbb0701dc0f1adccc7141e63 MD5 of 0d4111ab5471c7f5b909bff336ba8cd66f9d8630 2024-06-18
FileHash-MD5 da745b60b5ef5b4881c6bc4b7a48d784 2024-06-18
FileHash-MD5 db0676733eb4ee2c490bdc4fe488b40f MD5 of 765b17c1e2e1ab3d2fbdba3ccffcdcc4bd750102 2024-06-18
FileHash-MD5 de115e15a6689cf32519c3a046a78626 2024-06-18
FileHash-MD5 e0102071722a87f119b12434ae651b48 2024-06-18
FileHash-MD5 e6667ab32fbda86a2d2a72ed7e52b146 2024-06-18
FileHash-MD5 ee8d767069faf558886f1163a92e4009 2024-06-18
FileHash-MD5 f14e778f4d22df275c817ac3014873dc 2024-06-18
FileHash-MD5 f2501e8b57486c427579eeda20b729fd 2024-06-18
FileHash-MD5 f5d8664cbf4a9e154d4a888e4384cb1d 2024-06-18
FileHash-MD5 f68b17f1261aaa4460d759d95124fbd4 2024-06-18
FileHash-MD5 fbcd468dcd05cd1bf2ee25f16d09c227 2024-06-18
FileHash-MD5 fc61b985d8c590860f397d943131bfb5 2024-06-18
FileHash-SHA1 038ae7e6e6708cb58db96512515177d84b71e8c2 2024-06-18
FileHash-SHA1 0d4111ab5471c7f5b909bff336ba8cd66f9d8630 2024-06-18
FileHash-SHA1 1443e58a298458c30ab91b37c0335bdadbacd756 2024-06-18
FileHash-SHA1 1c8cfa8f36897b6b1179dc4bce49b0e2f86e1a4e 2024-06-18
FileHash-SHA1 25dc7c1237e5076c80fb867fb11d058387e1d154 2024-06-18
FileHash-SHA1 2c99e7e8a8a2965a6581729ec5b254f1b2bbda4b 2024-06-18
FileHash-SHA1 2dfe824d0298201e0efb30f16b3ce8a409ffe006 2024-06-18
FileHash-SHA1 31a1b6e836684c6d7b5d8f7a099dbe090282cbb0 2024-06-18
FileHash-SHA1 34cefe42aa8347c39a04eaca5a464fa35d6f1e62 2024-06-18
FileHash-SHA1 3dff44bede709295fffd3ae3e9599f6ab8197af4 2024-06-18
FileHash-SHA1 40e4b466e41b440ff62d9ef35f7034fd157ca625 2024-06-18
FileHash-SHA1 465ef9d21e73493e9d531378756f91917f9567f4 2024-06-18
FileHash-SHA1 4e2b14b18f5d68ce3dada1061526b03eafcd50b8 2024-06-18
FileHash-SHA1 513b4b604d198f44041ed494ee8c7a7f94ac5038 2024-06-18
FileHash-SHA1 5b7b0b0d7d59e616b0cf75a25ad67dfca89495c4 2024-06-18
FileHash-SHA1 5dd201fa53cb5c76103579785a3d220d578dd12a 2024-06-18
FileHash-SHA1 616661c324a8dfb836bd88a3c1325dc79e030ddd 2024-06-18
FileHash-SHA1 630530b11cbde6de840d7326152c1cb6bae06e0a 2024-06-18
FileHash-SHA1 6f3f3c533a2b9031362d88bb7414bf332c93dc9d 2024-06-18
FileHash-SHA1 749a8d081e075b921436d07e323964da88bff609 2024-06-18
FileHash-SHA1 7515a93da10b7d3f4619a38cc3f1a1bd25ddb847 2024-06-18
FileHash-SHA1 765b17c1e2e1ab3d2fbdba3ccffcdcc4bd750102 2024-06-18
FileHash-SHA1 7679f0e499edc2079a812cca945841c3680256d5 2024-06-18
FileHash-SHA1 789b41ddcee0166349cc106044932c76bfcb8cc0 2024-06-18
FileHash-SHA1 88949119f88b15722a2b75ca84db7a6bfc822948 2024-06-18
FileHash-SHA1 892d434f3f59b3b8bd4ca500218a75d39c13ee5b 2024-06-18
FileHash-SHA1 8c969dbe0fe30244802cda1c8e33b04040831466 2024-06-18
FileHash-SHA1 9244a07ce8f961317ba49e497009e55889f1d50d 2024-06-18
FileHash-SHA1 af137c7d1481e45217abd24a96f8aa2b416d294c 2024-06-18
FileHash-SHA1 b8fd89cf6e9aae16321553a2e632e31b2cf2f057 2024-06-18
FileHash-SHA1 bcadcb345fc65a9c3d7c78566ad72a77c6076a11 2024-06-18
FileHash-SHA1 bfdd02fa593d3858399da6bf591aeb10b2d1da40 2024-06-18
FileHash-SHA1 c1916403a6ad05fed4da5fb53ce743b6ce49e0cb 2024-06-18
FileHash-SHA1 c1a80dd5be2de92a5a32d81a9fc146d4fd52ddb6 2024-06-18
FileHash-SHA1 c1c3454ed5bf32f22c855b19618bcd16e6549df8 2024-06-18
FileHash-SHA1 c45e1cc5cd0c98388ec71221278950f9b1257ed8 2024-06-18
FileHash-SHA1 caa130a8e3f5ca0a7f33de4b2b26e0e25dd10775 2024-06-18
FileHash-SHA1 d0aff8489c02230d4c0935e21125f81895bf6cde 2024-06-18
FileHash-SHA1 d6855190e00276cad29a31573f819558256abe7f 2024-06-18
FileHash-SHA1 dab2f50307c86544719ae5f72d386ac8bc4d01e3 2024-06-18
FileHash-SHA1 e19c23d82d7e7e8e45b1d830ddc7ddb85087c4cc 2024-06-18
FileHash-SHA1 e1bdb995998ab338fc596777a78121fc49f002b5 2024-06-18
FileHash-SHA1 e5182d13d66c3efaa7676510581d622f98471895 2024-06-18
FileHash-SHA1 e76c3f3a7158c16c28176053286dcb88ac646dbf 2024-06-18
FileHash-SHA1 fc5ccb2b0a0b536ccb9687c67cc4ce735b866635 2024-06-18
FileHash-SHA256 03666fb1c21d8a8cf38219691d2218d78eef5b00d20f26c25afde5d9e1daf80a 2024-06-18
FileHash-SHA256 0b5cf9bd917f0af03dd694ff4ce39b0b34a97c9f41b87feac1dc884a684f60ef 2024-06-18
FileHash-SHA256 0c284271e3d90a6673d84cf6291f92f32ade7c7f760bbe135880b949b38046ee 2024-06-18
FileHash-SHA256 0cb88c8b8e2969af26678df4d3c395101c49c7c808d2cb2d7a0f00f60bdddcba 2024-06-18
FileHash-SHA256 1387b77a41e5a244c03ea7f5c90a2e528abe0ed7a4e6cb659183f7112c546046 2024-06-18
FileHash-SHA256 1844156b1a72a7daa8de4139175a2bdeb4bd326b9e3e1fb4dd2ae00b313b0a44 2024-06-18
FileHash-SHA256 1b1d1d775571232235ed6fb84413eb60593340c1c1ea3b77bd72d3b68058f55c 2024-06-18
FileHash-SHA256 1cdf1f32f31e226f037fda562985e481b7aa0b809971f2e40b713b034cf1d44e SHA256 of 765b17c1e2e1ab3d2fbdba3ccffcdcc4bd750102 2024-06-18
FileHash-SHA256 1e45d68106ca78f46be508427362b8ce24fdf5485c368f9369c913935cf04f99 SHA256 of 3dff44bede709295fffd3ae3e9599f6ab8197af4 2024-06-18
FileHash-SHA256 1e657d3047f3534dcd4539ce54db9f5901f7e53999bae340a850cc8d2aacc33c SHA256 of 749a8d081e075b921436d07e323964da88bff609 2024-06-18
FileHash-SHA256 207334927fc39278e37afe124769ed980e9a8ae86b0346408af64c86a7c99e6a 2024-06-18
FileHash-SHA256 26bf853b951e8d8ba6007e9d5c77f441faa739171e95f27f8d3851e07bc65b11 2024-06-18
FileHash-SHA256 2abaae4f6794131108adf5b42e09ee5ce24769431a0e154feabe6052cfe70bf3 SHA256 of d0aff8489c02230d4c0935e21125f81895bf6cde 2024-06-18
FileHash-SHA256 2cec6bd5e9ff046771623cfa0802cacd78b7521bf61b144e9c8dfa77d994927c 2024-06-18
FileHash-SHA256 37bfa72c2820bcf9adb8707ae624452e0b769bc1c1f2a24ebb518c6e1794f3e2 2024-06-18
FileHash-SHA256 3845877017eb07be71820e8514502a3dcd24177540591c5ce2c13aca94caa4ac 2024-06-18
FileHash-SHA256 38e1c0ca15ed83ed27148c31a31e0b33de627519ab2929d4aa69484534589086 2024-06-18
FileHash-SHA256 3d1b3ba5e1c1d1626595098f042913bc39601c80ab2c934cb994d3c053f218c5 2024-06-18
FileHash-SHA256 4ddf0c70be0b81ab44f018521f788213de2ccf72b7a7f452f327b81172014182 2024-06-18
FileHash-SHA256 51a372fee89f885741515fa6fdf0ebce860f98145c9883f2e3e35c0fe4432885 2024-06-18
FileHash-SHA256 5821744413146654397903128fece87d7d9d71c4ade5fd40cdcf3cece2faf8f0 2024-06-18
FileHash-SHA256 5ecbc33fe3b345f2956cff566203e33b9390a3ed9923b990a46804880ae2f59b SHA256 of 1c8cfa8f36897b6b1179dc4bce49b0e2f86e1a4e 2024-06-18
FileHash-SHA256 5ef431a481c9baeb1d8cfaf6e1c323531a57c14a5b878575b267f2f969451fdb 2024-06-18
FileHash-SHA256 6c2f18f5d70f794b8826ee2575d973ddb07cbf9d15115973fe92df74079b6412 2024-06-18
FileHash-SHA256 74e0af32c47e3bbe6becfb4027bbdcc01fbe36c92c70ce8edd676cc9aa3d6437 2024-06-18
FileHash-SHA256 76d9654f28bcaa713a99caa2839a572fc999a726827a0216da71ac184cee6d19 2024-06-18
FileHash-SHA256 8c8ef2d850bd9c987604e82571706e11612946122c6ab089bd54440c0113968e 2024-06-18
FileHash-SHA256 9709b0876c2a291cb57aa0646f9179d29d89abb2f8868663147ab0ca4e6c501b 2024-06-18
FileHash-SHA256 98b24fb7aaaece7556aea2269b4e908dd79ff332ddaa5111caec49123840f364 2024-06-18
FileHash-SHA256 9c1ffafe0bb4388569fed2a8d4af591ce65ae00f47793ee97c07f686c5fab100 2024-06-18
FileHash-SHA256 ae59ba12ec6a42ee5b08c3e2ce91ec02071b2f5ad9338e3a19d690bd68acb860 2024-06-18
FileHash-SHA256 af2201af8054e8e11eef7980fe15dc62eb2b7582f4f2bab4d8256f23f6db984e 2024-06-18
FileHash-SHA256 bac7e6776c120b2b5da4d171afaea26144e77ad54f7516a0325260ee020b3f52 SHA256 of 5b7b0b0d7d59e616b0cf75a25ad67dfca89495c4 2024-06-18
FileHash-SHA256 c177361992b207575b9aeb98aad7c2d522eace7ada6f1351434dd79a921ce260 2024-06-18
FileHash-SHA256 c981aa1f05adf030bacffc0e279cf9dc93cef877f7bce33ee27e9296363cf002 SHA256 of e5182d13d66c3efaa7676510581d622f98471895 2024-06-18
FileHash-SHA256 cfb9ffb83877b421e95c9a2c3f65c106b9afb42babce7ba824671f9736bf0f7c SHA256 of 31a1b6e836684c6d7b5d8f7a099dbe090282cbb0 2024-06-18
FileHash-SHA256 d3d5d0b210c3fc5c679419d6aa9014f62dcd60b0582cd8d544357f6420407b36 2024-06-18
FileHash-SHA256 d9f29a626857fa251393f056e454dfc02de53288ebe89a282bad38d03f614529 SHA256 of 0d4111ab5471c7f5b909bff336ba8cd66f9d8630 2024-06-18
FileHash-SHA256 db91e23d9715464511057f2e15c9adc97d3f27fcfa308f05ac7e2de7275fdd32 2024-06-18
FileHash-SHA256 db9afd2c59f20e04db37ddd38d1e911cdb4bddf39c24e4ce7cedda4eec984604 2024-06-18
FileHash-SHA256 dfb72668791b4fe28884706b7756b02b951b43219e528b970ceb0369c86e3fd3 2024-06-18
FileHash-SHA256 e89589e9ce043b28def17c91fa780322205ee08daa8b3cffe67b46bdae0e3a35 2024-06-18
FileHash-SHA256 ead993c1d537c239750e19a5700a58501dab319d5d271bf85137608448c1faa0 2024-06-18
FileHash-SHA256 fb30e5c67b92dc17d7a6e412f36d9b521842f8d7df38a00584c1362303b26655 2024-06-18
FileHash-SHA256 fe7e7a5a1b1d634dec3fc9c6bc91c6e96ec635fece5af10cfac894fd228ca38d 2024-06-18
domain admincoord.in 2024-06-18
domain apsdelhicantt.in 2024-06-18
domain awesindia.online 2024-06-18
domain awesscholarship.in 2024-06-18
domain certdehli.in 2024-06-18
domain clawsindia.in 2024-06-18
domain coordsec2.in 2024-06-18
domain defenseinsight.in 2024-06-18
domain emailnic-tech.email 2024-06-18
domain emailnic.online 2024-06-18
domain epar-online.in 2024-06-18
domain estbsec.in 2024-06-18
domain esttsec.in 2024-06-18
domain infosec2.in 2024-06-18
domain nic-tech.in 2024-06-18
domain ordai.quest 2024-06-18
domain parichay.online 2024-06-18
domain publicinfo.in 2024-06-18
domain secy-org.in 2024-06-18
hostname account.emailnic.online 2024-06-18
hostname accounts.emailnic.online 2024-06-18
hostname adfs.clawsindia.in 2024-06-18
hostname autoconfig.clawsindia.in 2024-06-18
hostname blog.clawsindia.in 2024-06-18
hostname cloud.publicinfo.in 2024-06-18
hostname cpanel.clawsindia.in 2024-06-18
hostname dc-mx.ae172f95f2ec.defenseinsight.in 2024-06-18
hostname dev.clawsindia.in 2024-06-18
hostname dev.nic-tech.in 2024-06-18
hostname email.apsdelhicantt.in 2024-06-18
hostname email.coordsec2.in 2024-06-18
hostname email.emailnic-tech.email 2024-06-18
hostname email.emailnic.online 2024-06-18
hostname email.estbsec.in 2024-06-18
hostname email.gov.in.estbsec.in 2024-06-18
hostname email.gov.in.parichay.online 2024-06-18
hostname email.parichay.online 2024-06-18
hostname email.publicinfo.in 2024-06-18
hostname epar.emailnic-tech.email 2024-06-18
hostname ftp.clawsindia.in 2024-06-18
hostname ftp.publicinfo.in 2024-06-18
hostname gate.clawsindia.in 2024-06-18
hostname help.clawsindia.in 2024-06-18
hostname imap.clawsindia.in 2024-06-18
hostname insight.defenseinsight.in 2024-06-18
hostname intranet.clawsindia.in 2024-06-18
hostname lists.clawsindia.in 2024-06-18
hostname localhost.clawsindia.in 2024-06-18
hostname login.emailnic.online 2024-06-18
hostname m.clawsindia.in 2024-06-18
hostname m.emailnic.online 2024-06-18
hostname mail.clawsindia.in 2024-06-18
hostname mail.defenseinsight.in 2024-06-18
hostname mail6.clawsindia.in 2024-06-18
hostname mailgate.clawsindia.in 2024-06-18
hostname mailrelay.clawsindia.in 2024-06-18
hostname mbox.clawsindia.in 2024-06-18
hostname mx0.clawsindia.in 2024-06-18
hostname mx10.clawsindia.in 2024-06-18
hostname mx4.clawsindia.in 2024-06-18
hostname ns1.clawsindia.in 2024-06-18
hostname old.clawsindia.in 2024-06-18
hostname outlook.emailnic.online 2024-06-18
hostname pcda.admincoord.in 2024-06-18
hostname play.emailnic.online 2024-06-18
hostname pop.clawsindia.in 2024-06-18
hostname pop3.clawsindia.in 2024-06-18
hostname portal.clawsindia.in 2024-06-18
hostname shop.clawsindia.in 2024-06-18
hostname smtp.mail.clawsindia.in 2024-06-18
hostname sql.clawsindia.in 2024-06-18
hostname test.clawsindia.in 2024-06-18
hostname webdisk.clawsindia.in 2024-06-18
hostname webdisk.defenseinsight.in 2024-06-18
hostname webdisk.estbsec.in 2024-06-18
hostname webmail.clawsindia.in 2024-06-18
hostname whm.clawsindia.in 2024-06-18
hostname ww12.epar-online.in 2024-06-18
hostname www.admincoord.in 2024-06-18
hostname www.apsdelhicantt.in 2024-06-18
hostname www.awesindia.online 2024-06-18
hostname www.awesscholarship.in 2024-06-18
hostname www.certdehli.in 2024-06-18
hostname www.clawsindia.in 2024-06-18
hostname www.coordsec2.in 2024-06-18
hostname www.defenseinsight.in 2024-06-18
hostname www.dev.clawsindia.in 2024-06-18
hostname www.emailnic-tech.email 2024-06-18
hostname www.emailnic.online 2024-06-18
hostname www.epar-online.in 2024-06-18
hostname www.estbsec.in 2024-06-18
hostname www.esttsec.in 2024-06-18
hostname www.infosec2.in 2024-06-18
hostname www.mailgate.clawsindia.in 2024-06-18
hostname www.nic-tech.in 2024-06-18
hostname www.old.clawsindia.in 2024-06-18
hostname www.ordai.quest 2024-06-18
hostname www.publicinfo.in 2024-06-18
hostname www.secy-org.in 2024-06-18
hostname www.shop.clawsindia.in 2024-06-18
hostname www.www.clawsindia.in 2024-06-18
hostname www2.clawsindia.in 2024-06-18