PULSE NAME
CERT-UA Report: UAC-0198: Mass distribution of ANONVNC (MESHAGENT) among government organizations of Ukraine
WHITE AlienVault 2024-08-13 Modified: 2024-09-12
26
IOCs
MEDIUM VOLUME
According to the report, cyber operations related to the ongoing military conflict between Russia and Ukraine are ongoing. The report highlights the potential risks and threats posed by Russian state-sponsored actors, including the deployment of wiper malware, distributed denial-of-service (DDoS) attacks, and data leaks targeting Ukrainian government and critical infrastructure organizations. It also warns of the possibility of collateral impact on other countries and sectors due to the interconnected nature of cyberspace.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (26)
All FileHash-MD5 FileHash-SHA256 URL domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 5b1323cfcddc4fd7de98c94ce9ce8b66 2024-08-13
FileHash-MD5 6ab9f278a420ac86fc7ec85647ce99f1 2024-08-13
FileHash-MD5 ce65c8134821032063d54ca07e8a73ae 2024-08-13
FileHash-SHA256 02ec55a5a2ad775adccd333edd94ac0bd82129a233736f7240044e085b73b0b3 2024-08-13
FileHash-SHA256 4c4872202abb5a60a8764bf44b370578a2b3d6f449b3881e96cc38f1b55f9cda 2024-08-13
FileHash-SHA256 a7297883de84d73fb4965c00228144a0e53c573ad3b7291be39bc6d9c284454c 2024-08-13
URL http://filedn.eu/lodwtgn8sswha6pn8hxwe1j/.........../ 2024-08-13
URL http://filedn.eu/lodwtgn8sswha6pn8hxwe1j/1.../ 2024-08-13
URL http://filedn.eu/lodwtgn8sswha6pn8hxwe1j/tox/ 2024-08-13
URL http://filedn.eu/lodwtgn8sswha6pn8hxwe1j/tox2/ 2024-08-13
URL http://filedn.eu/lodwtgn8sswha6pn8hxwe1j/tox2/scan_docs#40562153.msi 2024-08-13
URL http://gbshost.net/ 2024-08-13
domain anonvnc.com 2024-08-13
domain gbshost.net 2024-08-13
domain gbshost.org 2024-08-13
domain hiddenvnc.com 2024-08-13
domain invoice-traffic.com 2024-08-13
domain smart-vnc.com 2024-08-13
domain smartcloudflare.com 2024-08-13
email chafik.zaalouk@ac-strasbourg.fr 2024-08-13
hostname syn.hiddenvnc.com 2024-08-13
hostname sync.anonvnc.com 2024-08-13
hostname sync.hiddenvnc.com 2024-08-13
hostname sync.invoice-traffic.com 2024-08-13
hostname sync.smart-vnc.com 2024-08-13
hostname sync.smartcloudflare.com 2024-08-13