PULSE NAME
TAG-124’s Multi-Layered TDS Infrastructure and Extensive User Base
WHITE TAG-124 InformationTechnogyISAC 2025-01-30 Modified: 2025-03-01
383
IOCs
HIGH VOLUME
https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base Insikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Rhysida Interlock SocGholish
Indicators of Compromise (383)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 13fd064b0795dfd75a9304243c2f0bd6 MD5 of 77dc705cecbc29089c8e9eea3335ba83de57a17ed99b0286b3d9301953a84eca 2025-01-30
FileHash-MD5 1d93573d0d4457c8933526cfe3c57120 MD5 of 92d2488e401d24a4bfc1598d813bc53af5c225769efedf0c7e5e4083623f4486 2025-01-30
FileHash-MD5 44cd8679a006933ba745e3b89bdbb8fa MD5 of 941fa9119eb1413fdd4f05333e285c49935280cc85f167fb31627012ef71a6b3 2025-01-30
FileHash-MD5 53ef19d7be0ba3e806e8dc558737725a MD5 of 2da62d1841a6763f279c481e420047a108da21cd5e16eae31661e6fd5d1b25d7 2025-01-30
FileHash-MD5 614cc21ab0f47b6006bebef6f6dfe19a MD5 of 43f4ca1c7474c0476a42d937dc4af01c8ccfc20331baa0465ac0f3408f52b2e2 2025-01-30
FileHash-MD5 b4311ca7f93f5bd2725d41a6e0d2631a MD5 of 430fd4d18d22d0704db1c4a1037d8e1664bfc003c244650cb7538dbe7c3be63e 2025-01-30
FileHash-MD5 c35d379eb011c6d6c31118eb66b24f60 MD5 of 342b889d1d8c81b1ba27fe84dec2ca375ed04889a876850c48d2b3579fbac206 2025-01-30
FileHash-SHA1 0626f176f9d24f8dd41954e24a301a6d4b7a7877 SHA1 of 43f4ca1c7474c0476a42d937dc4af01c8ccfc20331baa0465ac0f3408f52b2e2 2025-01-30
FileHash-SHA1 1b18cf1c2325bfe253bb6b3da2c15e2d5854c1f1 SHA1 of 92d2488e401d24a4bfc1598d813bc53af5c225769efedf0c7e5e4083623f4486 2025-01-30
FileHash-SHA1 2607db4eb60651d1b09ca511bd584738fc661acd SHA1 of 342b889d1d8c81b1ba27fe84dec2ca375ed04889a876850c48d2b3579fbac206 2025-01-30
FileHash-SHA1 542cc1115675079d40f993014879eceb5c95c5f3 SHA1 of 77dc705cecbc29089c8e9eea3335ba83de57a17ed99b0286b3d9301953a84eca 2025-01-30
FileHash-SHA1 6dd9c8ae9b94c71656a79c24a3df4ba902ec23de SHA1 of 2da62d1841a6763f279c481e420047a108da21cd5e16eae31661e6fd5d1b25d7 2025-01-30
FileHash-SHA1 7a07d078c17f785df4e44706036b796682836c53 SHA1 of 941fa9119eb1413fdd4f05333e285c49935280cc85f167fb31627012ef71a6b3 2025-01-30
FileHash-SHA1 a1dd0b18821b2b389c1e5d0b6c1e6b432f5f406b SHA1 of 430fd4d18d22d0704db1c4a1037d8e1664bfc003c244650cb7538dbe7c3be63e 2025-01-30
FileHash-SHA256 183c57d9af82964bfbb06fbb0690140d3f367d46d870e290e2583659609b19f2 2025-01-30
FileHash-SHA256 22dc96b3b8ee42096c66ab08e255adce45e5e09a284cbe40d64e83e812d1b910 2025-01-30
FileHash-SHA256 28c49af7c95ab41989409d2c7f98e8f8053e5ca5f7a02b2a11ad4374085ec6ff 2025-01-30
FileHash-SHA256 2da62d1841a6763f279c481e420047a108da21cd5e16eae31661e6fd5d1b25d7 2025-01-30
FileHash-SHA256 342b889d1d8c81b1ba27fe84dec2ca375ed04889a876850c48d2b3579fbac206 2025-01-30
FileHash-SHA256 42c1550b035353ae529e98304f89bf6065647833e582d08f0228185b493d0022 2025-01-30
FileHash-SHA256 42d7135378ed8484a6a86a322ea427765f2e4ad37ee6449691b39314b5925a27 2025-01-30
FileHash-SHA256 430fd4d18d22d0704db1c4a1037d8e1664bfc003c244650cb7538dbe7c3be63e 2025-01-30
FileHash-SHA256 43f4ca1c7474c0476a42d937dc4af01c8ccfc20331baa0465ac0f3408f52b2e2 2025-01-30
FileHash-SHA256 46aac6bf94551c259b4963157e75073cb211310e2afab7a1c0eded8a175d0a28 2025-01-30
FileHash-SHA256 4fa213970fdef39d2506a1bd4f05a7ceee191d916b44b574022a768356951a23 2025-01-30
FileHash-SHA256 57e9e1e3ebd78d4878d7bb69e9a2b0d0673245a87eb56cf861c7c548c4e7b457 2025-01-30
FileHash-SHA256 6464cdbfddd98f3bf6301f2bf525ad3642fb18b434310ec731de08c79e933b3e 2025-01-30
FileHash-SHA256 67b5b54c85e7590d81a404d6c7ea7dd90d4bc773785c83b85bcce82cead60c37 2025-01-30
FileHash-SHA256 700f1afeb67c105760a9086b0345cb477737ab62616fd83add3f7adf9016c5e5 2025-01-30
FileHash-SHA256 7683d38c024d0f203b374a87b7d43cc38590d63adb8e5f24dff7526f5955b15a 2025-01-30
FileHash-SHA256 77bd80e2a7c56eb37a33c2a0518a27deb709068fdc66bd1e00b5d958a25c7ad8 2025-01-30
FileHash-SHA256 77dc705cecbc29089c8e9eea3335ba83de57a17ed99b0286b3d9301953a84eca 2025-01-30
FileHash-SHA256 7b8d4b1ab46f9ad4ef2fd97d526e936186503ecde745f5a9ab9f88397678bc96 2025-01-30
FileHash-SHA256 7ea83cca00623a8fdb6c2d6268fa0d5c4e50dbb67ab190d188b8033d884e4b75 2025-01-30
FileHash-SHA256 7f8e9d7c986cc45a78c0ad2f11f28d61a4b2dc948c62b10747991cb33ce0e241 2025-01-30
FileHash-SHA256 8d911ef72bdb4ec5b99b7548c0c89ffc8639068834a5e2b684c9d78504550927 2025-01-30
FileHash-SHA256 92d2488e401d24a4bfc1598d813bc53af5c225769efedf0c7e5e4083623f4486 2025-01-30
FileHash-SHA256 941fa9119eb1413fdd4f05333e285c49935280cc85f167fb31627012ef71a6b3 2025-01-30
FileHash-SHA256 950f1f8d94010b636cb98be774970116d98908cd4c45fbb773e533560a4beea7 2025-01-30
FileHash-SHA256 95b9c9bf8fa3874ad9e6204f408ce162cd4ae7a8253e69c3c493188cb9d1f4da 2025-01-30
FileHash-SHA256 97105ed172e5202bc219d99980ebbd01c3dfd7cd5f5ac29ca96c5a09caa8af67 2025-01-30
FileHash-SHA256 9d508074a830473bf1dee096b02a25310fa7929510b880a5875d3c316617dd50 2025-01-30
FileHash-SHA256 ccdf82b45b2ee9173c27981c51958e44dee43131edfbce983b6a5c146479ac33 2025-01-30
FileHash-SHA256 d738eef8756a03a516b02bbab0f1b06ea240efc151f00c05ec962d392cfddb93 2025-01-30
domain 1stproducts.com 2025-01-30
domain 3hti.com 2025-01-30
domain 527newagain.top 2025-01-30
domain abhbdiiaehdejgh.top 2025-01-30
domain academictutoringcenters.com 2025-01-30
domain adednihknaalilg.top 2025-01-30
domain adpages.com 2025-01-30
domain adsbicloud.com 2025-01-30
domain advanceair.net 2025-01-30
domain airbluefootgear.com 2025-01-30
domain airinnovations.com 2025-01-30
domain allaces.com.au 2025-01-30
domain ambir.com 2025-01-30
domain ambiwa.com 2025-01-30
domain amdradeon.shop 2025-01-30
domain americanreloading.com 2025-01-30
domain anjmhjidinfmlci.top 2025-01-30
domain antiagewellness.com 2025-01-30
domain apple-online.shop 2025-01-30
domain architectureandgovernance.com 2025-01-30
domain astromachineworks.com 2025-01-30
domain athsvic.org.au 2025-01-30
domain avayehazar.ir 2025-01-30
domain azure-getrequest.icu 2025-01-30
domain azurearc-cdn.top 2025-01-30
domain azuregetrequest.icu 2025-01-30
domain bastillefestival.com.au 2025-01-30
domain bigfoot99.com 2025-01-30
domain bkkeiekjfcdaaen.top 2025-01-30
domain bluefrogplumbing.com 2025-01-30
domain boneyn.com 2025-01-30
domain calbbs.com 2025-01-30
domain canadamotoguide.com 2025-01-30
domain canadanickel.com 2025-01-30
domain capecinema.org 2025-01-30
domain castellodelpoggio.com 2025-01-30
domain catholiccharities.org 2025-01-30
domain chamonixskipasses.com 2025-01-30
domain changemh.org 2025-01-30
domain chewels.com 2025-01-30
domain chhimi.com 2025-01-30
domain chicklitplus.com 2025-01-30
domain cignjjgmdnbchhc.top 2025-01-30
domain ckebfjgimhmjgmb.top 2025-01-30
domain cljhkcjfimibhci.top 2025-01-30
domain clmfireproofing.com 2025-01-30
domain cmcebigeiajbfcb.top 2025-01-30
domain cmcuauec.top 2025-01-30
domain coeshor.com 2025-01-30
domain comingoutcovenant.com 2025-01-30
domain complete-physio.co.uk 2025-01-30
domain complete-pilates.co.uk 2025-01-30
domain conical-fermenter.com 2025-01-30
domain cryptoslate.cc 2025-01-30
domain cryptotap.site 2025-01-30
domain cssp.org 2025-01-30
domain dating2go.store 2025-01-30
domain deathtotheworld.com 2025-01-30
domain dechromo.com 2025-01-30
domain deerfield.com 2025-01-30
domain denhamlawoffice.com 2025-01-30
domain dhusch.com 2025-01-30
domain digimind.nl 2025-01-30
domain discoves.com 2025-01-30
domain djnito.com 2025-01-30
domain dncoding.com 2025-01-30
domain dotnetreport.com 2025-01-30
domain drcolbert.com 2025-01-30
domain dsassoc.com 2025-01-30
domain dzyne.com 2025-01-30
domain earthboundfarm.com 2025-01-30
domain ecrut.com 2025-01-30
domain eebchjechginddk.top 2025-01-30
domain ehnediemcaffbij.top 2025-01-30
domain eivcapital.com 2025-01-30
domain ejlhaidjmhcmami.top 2025-01-30
domain elamoto.com 2025-01-30
domain elitetournaments.com 2025-01-30
domain elizgallery.com 2025-01-30
domain eliztalks.com 2025-01-30
domain enerjjoy.com 2025-01-30
domain enethost.com 2025-01-30
domain ergos.com 2025-01-30
domain esaleerugs.com 2025-01-30
domain esfna.org 2025-01-30
domain espumadesign.com 2025-01-30
domain evolverangesolutions.com 2025-01-30
domain exceptionalindividuals.com 2025-01-30
domain experiencebrightwater.ca 2025-01-30
domain expressbuycomputers.shop 2025-01-30
domain fastard.com 2025-01-30
domain faybzuy3byz2v.top 2025-01-30
domain firstpresbyterianpaulding.com 2025-01-30
domain fpziviec.top 2025-01-30
domain fractalerts.com 2025-01-30
domain franklinida.com 2025-01-30
domain fusionstone.ca 2025-01-30
domain futnbuzj3nh.top 2025-01-30
domain gbkffjcglabkmne.top 2025-01-30
domain gcafin.com 2025-01-30
domain gdihcicdghmcldd.top 2025-01-30
domain genhil.com 2025-01-30
domain get-azurecommand.icu 2025-01-30
domain get-iwrreq.top 2025-01-30
domain getazurecommand.icu 2025-01-30
domain global-engage.com 2025-01-30
domain gmdva.org 2025-01-30
domain gnmdjjckbgddaie.top 2025-01-30
domain gobrightwing.com 2025-01-30
domain gov2x.com 2025-01-30
domain gubyzywey6b.top 2025-01-30
domain gwcomics.com 2025-01-30
domain habfan.com 2025-01-30
domain hdtele.com 2025-01-30
domain hksusa.com 2025-01-30
domain hmgcreative.com 2025-01-30
domain hoodcontainer.com 2025-01-30
domain hospitalnews.com 2025-01-30
domain housingforhouston.com 2025-01-30
domain houstonmaritime.org 2025-01-30
domain howmanychairs.com 2025-01-30
domain hrsoft.com 2025-01-30
domain hungryman.com 2025-01-30
domain iadkainhkafngnk.top 2025-01-30
domain icmcontrols.com 2025-01-30
domain ijmtolldiv.com 2025-01-30
domain ikhgijabfnkajem.top 2025-01-30
domain ikjfjkkagafbdke.top 2025-01-30
domain ilsotto.com 2025-01-30
domain imfiejalbhhgijl.top 2025-01-30
domain incalzireivar.ro 2025-01-30
domain innsbrook.com 2025-01-30
domain iognews.com 2025-01-30
domain jewelryexchange.com 2025-01-30
domain jodymassagetherapyclinic.com 2025-01-30
domain joelbieber.com 2025-01-30
domain kffgkjmjangegkg.top 2025-01-30
domain khcjgjmfjgdleag.top 2025-01-30
domain kjalcimbfaaddff.top 2025-01-30
domain knewhealth.com 2025-01-30
domain lamaisonquilting.com 2025-01-30
domain levyso.com 2025-01-30
domain luxlifemiamiblog.com 2025-01-30
domain magnoliagreen.com 2025-01-30
domain magnotics.com 2025-01-30
domain manawatunz.co.nz 2025-01-30
domain mantonpushrods.com 2025-01-30
domain mcajijknegnbbga.top 2025-01-30
domain melmejkjaakiakn.top 2025-01-30
domain mercro.com 2025-01-30
domain mgjabikgjhhambm.top 2025-01-30
domain mgssoft.com 2025-01-30
domain michigantownships.org 2025-01-30
domain micronsoftwares.com 2025-01-30
domain mirugby.com 2025-01-30
domain mktgads.com 2025-01-30
domain mobileyas.shop 2025-01-30
domain monlamdesigns.com 2025-01-30
domain montessoriwest.com 2025-01-30
domain movinbed.com 2025-01-30
domain mtclibraries.com 2025-01-30
domain myrtlebeachgolf.com 2025-01-30
domain mysamsung7.shop 2025-01-30
domain nastictac.com 2025-01-30
domain ncma.org 2025-01-30
domain nvidias.shop 2025-01-30
domain nyciot.com 2025-01-30
domain oningroup.com 2025-01-30
domain opgears.com 2025-01-30
domain orlandparkprayercenter.org 2025-01-30
domain outdoornativitystore.com 2025-01-30
domain pemalite.com 2025-01-30
domain peoria.org 2025-01-30
domain peridotdentalcare.ca 2025-01-30
domain phfi.org 2025-01-30
domain piedsmontlaw.com 2025-01-30
domain pikapp.org 2025-01-30
domain prek4sa.com 2025-01-30
domain pretoria24.top 2025-01-30
domain psafetysolutions.com 2025-01-30
domain puntademita-rentals.com 2025-01-30
domain pursyst.com 2025-01-30
domain pushcg.com 2025-01-30
domain pweobmxdlboi.com 2025-01-30
domain resf.com 2025-01-30
domain retaildatallc.com 2025-01-30
domain rhodenroofing.com 2025-01-30
domain rifiziec.top 2025-01-30
domain riuzvi4tc.top 2025-01-30
domain rm-arquisign.com 2025-01-30
domain robnzuwubz.top 2025-01-30
domain rshank.com 2025-01-30
domain rvthereyet.com 2025-01-30
domain safigdata.com 2025-01-30
domain saighbuzu32uvv.top 2025-01-30
domain satpr.com 2025-01-30
domain schroederindustries.com 2025-01-30
domain sdrce.com 2025-01-30
domain sec-group.co.uk 2025-01-30
domain selectmotors.net 2025-01-30
domain selmanc.com 2025-01-30
domain sixpoint.com 2025-01-30
domain slotomoons.com 2025-01-30
domain sokrpro.com 2025-01-30
domain sollishealth.com 2025-01-30
domain sparkcarwash.com 2025-01-30
domain spectralogic.com 2025-01-30
domain sramanamitra.com 2025-01-30
domain sustaincharlotte.org 2025-01-30
domain tayakay.com 2025-01-30
domain teamtoc.com 2025-01-30
domain terryrossplumbing.com 2025-01-30
domain theepicentre.com 2025-01-30
domain theinb.com 2025-01-30
domain theyard.com 2025-01-30
domain tibetin.com 2025-01-30
domain tickerwell.com 2025-01-30
domain tristatecr.com 2025-01-30
domain true-blood.net 2025-01-30
domain tustinhistory.com 2025-01-30
domain tysonmutrux.com 2025-01-30
domain update-chronne.com 2025-01-30
domain usbkits.com 2025-01-30
domain vectare.co.uk 2025-01-30
domain vicrin.com 2025-01-30
domain villageladies.co.uk 2025-01-30
domain walkerroofingandconstruction.com 2025-01-30
domain wildwestguns.com 2025-01-30
domain wildwoodpress.org 2025-01-30
domain winworld.es 2025-01-30
domain wlplastics.com 2025-01-30
domain worldorphans.org 2025-01-30
domain xaides.com 2025-01-30
domain zerocap.com 2025-01-30
hostname baseball.razzball.com 2025-01-30
hostname careers.fortive.com 2025-01-30
hostname cvqrcode.lpmglobalrelations.com 2025-01-30
hostname dev.azliver.com 2025-01-30
hostname development.3hti.com 2025-01-30
hostname legacy.orlandparkprayercenter.org 2025-01-30
hostname my.networknuts.net 2025-01-30
hostname ns1.webasatir.ir 2025-01-30
hostname theawningcompanc.mrmarketing.us 2025-01-30
hostname uk.pattern.com 2025-01-30
hostname www.211cny.com 2025-01-30
hostname www.6connex.com 2025-01-30
hostname www.900biscaynebaymiamicondos.com 2025-01-30
hostname www.accentawnings.com 2025-01-30
hostname www.acvillage.net 2025-01-30
hostname www.airandheatspecialistsnj.com 2025-01-30
hostname www.als-mnd.org 2025-01-30
hostname www.americancraftbeer.com 2025-01-30
hostname www.anoretaresort.com 2025-01-30
hostname www.architectureandgovernance.com 2025-01-30
hostname www.atlantaparent.com 2025-01-30
hostname www.atlas-sp.com 2025-01-30
hostname www.atmosera.com 2025-01-30
hostname www.belvoirfarm.co.uk 2025-01-30
hostname www.betterengineering.com 2025-01-30
hostname www.bluefoxcasino.com 2025-01-30
hostname www.boatclubtrafalgar.com 2025-01-30
hostname www.bordgaisenergytheatre.ie 2025-01-30
hostname www.brandamos.com 2025-01-30
hostname www.cairnha.com 2025-01-30
hostname www.cdhcpa.com 2025-01-30
hostname www.cds.coop 2025-01-30
hostname www.cgimgolf.com 2025-01-30
hostname www.cheericca.org 2025-01-30
hostname www.conwire.com 2025-01-30
hostname www.cssp.org 2025-01-30
hostname www.dces.com 2025-01-30
hostname www.de.digitaalkantoor.online 2025-01-30
hostname www.disabilityscot.org.uk 2025-01-30
hostname www.doctorkiltz.com 2025-01-30
hostname www.drivenbyboredom.com 2025-01-30
hostname www.evercoat.com 2025-01-30
hostname www.facefoundrie.com 2025-01-30
hostname www.foxcorphousing.com 2025-01-30
hostname www.genderconfirmation.com 2025-01-30
hostname www.gofreight.com 2025-01-30
hostname www.gunnerroofing.com 2025-01-30
hostname www.hayeshvacllc.com 2025-01-30
hostname www.hksusa.com 2025-01-30
hostname www.hollingsworth-vose.com 2025-01-30
hostname www.hollywoodburbankairport.com 2025-01-30
hostname www.hopechc.org 2025-01-30
hostname www.icmcontrols.com 2025-01-30
hostname www.infra-metals.com 2025-01-30
hostname www.jasperpim.com 2025-01-30
hostname www.louisvillemechanical.com 2025-01-30
hostname www.lsbn.state.la.us 2025-01-30
hostname www.mallorcantonic.com 2025-01-30
hostname www.marketlist.com 2025-01-30
hostname www.mocanyc.org 2025-01-30
hostname www.motherwellfc.co.uk 2025-01-30
hostname www.murphyoilcorp.com 2025-01-30
hostname www.myrtlebeachgolfpackages.co 2025-01-30
hostname www.napcis.org 2025-01-30
hostname www.nelsongonzalez.com 2025-01-30
hostname www.netzwerkreklame.de 2025-01-30
hostname www.onthegreenmagazine.com 2025-01-30
hostname www.orthodontie-laurentides.com 2025-01-30
hostname www.pamelasandalldesign.com 2025-01-30
hostname www.parajohn.com 2025-01-30
hostname www.parksavers.com 2025-01-30
hostname www.parmacalcio1913.com 2025-01-30
hostname www.patio-supply.com 2025-01-30
hostname www.pcbc.gov.pl 2025-01-30
hostname www.perfectduluthday.com 2025-01-30
hostname www.progarm.com 2025-01-30
hostname www.rafilawfirm.com 2025-01-30
hostname www.reddiseals.com 2025-01-30
hostname www.reloadinternet.com 2025-01-30
hostname www.robertomalca.com 2025-01-30
hostname www.sevenacres.org 2025-01-30
hostname www.sigmathermal.com 2025-01-30
hostname www.sisdisinfestazioni.it 2025-01-30
hostname www.spectralink.com 2025-01-30
hostname www.sramanamitra.com 2025-01-30
hostname www.sunkissedindecember.com 2025-01-30
hostname www.sweetstreet.com 2025-01-30
hostname www.system-scale.com 2025-01-30
hostname www.tcpa.org.uk 2025-01-30
hostname www.thatcompany.com 2025-01-30
hostname www.the-kaisers.de 2025-01-30
hostname www.thecreativemom.com 2025-01-30
hostname www.thedesignsheppard.com 2025-01-30
hostname www.therialtoreport.com 2025-01-30
hostname www.thetrafalgargroup.co.uk 2025-01-30
hostname www.totem.tech 2025-01-30
hostname www.ultrasound-guided-injections.co.uk 2025-01-30
hostname www.urbis-realestate.com 2025-01-30
hostname www.vending.com 2025-01-30
hostname www.venetiannj.com 2025-01-30
hostname www.visitarundel.co.uk 2025-01-30
hostname www.wefinanceanycar.com 2025-01-30
hostname www.wilsonsd.org 2025-01-30
hostname www.wilymanager.com 2025-01-30
hostname www.wvwc.edu 2025-01-30