PULSE NAME
From South America to Southeast Asia: The Fragile Web of REF7707
WHITE AlienVault 2025-02-12 Modified: 2025-03-14
46
IOCs
MEDIUM VOLUME
While the REF7707 campaign is characterized by a well-engineered, highly capable, novel intrusion set, the campaign owners exhibited poor campaign management and inconsistent evasion practices.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
PATHLOADER FINALDRAFT GUILOADER
Indicators of Compromise (46)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3eba3860c1983d183a1c984957dc4b6a MD5 of f29779049f1fc2d45e43d866a845c45dc9aed6c2d9bbf99a8b1bdacfac2d52f2 2025-02-12
FileHash-MD5 3fd5aae11b1b05480a5d76119dc6ab2b MD5 of cffca467b6ff4dee8391c68650a53f4f3828a0b5a31a9aa501d2272b683205f9 2025-02-12
FileHash-MD5 764a838236f5dceb3d199059ad36311e MD5 of 83406905710e52f6af35b4b3c27549a12c28a628c492429d3a411fdb2d28cc8c 2025-02-12
FileHash-MD5 77cb2b8cd04aa216fd973f303d7a8529 MD5 of f90420847e1f2378ac8c52463038724533a9183f02ce9ad025a6a10fd4327f12 2025-02-12
FileHash-MD5 a9d0f588f1b0f88c5a5036bc5bf2e09e MD5 of f45661ea4959a944ca2917454d1314546cc0c88537479e00550eef05bed5b1b9 2025-02-12
FileHash-SHA1 2fdea656bf50277c8d728e1a005bf1e5157c68d0 SHA1 of 83406905710e52f6af35b4b3c27549a12c28a628c492429d3a411fdb2d28cc8c 2025-02-12
FileHash-SHA1 465f35c8a865b5904474bef9be163e680549f360 SHA1 of cffca467b6ff4dee8391c68650a53f4f3828a0b5a31a9aa501d2272b683205f9 2025-02-12
FileHash-SHA1 549c567cd32a562eaba15fe17ba71ce68cf0228c SHA1 of f29779049f1fc2d45e43d866a845c45dc9aed6c2d9bbf99a8b1bdacfac2d52f2 2025-02-12
FileHash-SHA1 57868094d1ff07648505e212112444677e4ee9dd SHA1 of f90420847e1f2378ac8c52463038724533a9183f02ce9ad025a6a10fd4327f12 2025-02-12
FileHash-SHA1 a1376a0760c0c327c2ff370cecdf755dfa53eca5 SHA1 of f45661ea4959a944ca2917454d1314546cc0c88537479e00550eef05bed5b1b9 2025-02-12
FileHash-SHA256 08331f33d196ced23bb568689c950b39ff7734b7461d9501c404e2b1dc298cc1 2025-02-12
FileHash-SHA256 17b2c6723c11348ab438891bc52d0b29f38fc435c6ba091d4464f9f2a1b926e0 2025-02-12
FileHash-SHA256 20508edac0ca872b7977d1d2b04425aaa999ecf0b8d362c0400abb58bd686f92 2025-02-12
FileHash-SHA256 33f3a8ef2c5fbd45030385b634e40eaa264acbaeb7be851cbf04b62bbe575e75 2025-02-12
FileHash-SHA256 39e85de1b1121dc38a33eca97c41dbd9210124162c6d669d28480c833e059530 2025-02-12
FileHash-SHA256 41141e3bdde2a7aebf329ec546745149144eff584b7fe878da7a2ad8391017b9 2025-02-12
FileHash-SHA256 41a3a518cc8abad677bb2723e05e2f052509a6f33ea75f32bd6603c96b721081 2025-02-12
FileHash-SHA256 49e383ab6d092ba40e12a255e37ba7997f26239f82bebcd28efaa428254d30e1 2025-02-12
FileHash-SHA256 5e3dbfd543909ff09e343339e4e64f78c874641b4fe9d68367c4d1024fe79249 2025-02-12
FileHash-SHA256 6d79dfb00da88bb20770ffad636c884bad515def4f8e97e9a9d61473297617e3 2025-02-12
FileHash-SHA256 7cd14d3e564a68434e3b705db41bddeb51dbb7d5425fd901c5ec904dbb7b6af0 2025-02-12
FileHash-SHA256 83406905710e52f6af35b4b3c27549a12c28a628c492429d3a411fdb2d28cc8c 2025-02-12
FileHash-SHA256 842d6ddb7b26fdb1656235293ebf77c683608f8f312ed917074b30fbd5e8b43d 2025-02-12
FileHash-SHA256 9a11d6fcf76583f7f70ff55297fb550fed774b61f35ee2edd95cf6f959853bcf 2025-02-12
FileHash-SHA256 cffca467b6ff4dee8391c68650a53f4f3828a0b5a31a9aa501d2272b683205f9 2025-02-12
FileHash-SHA256 d9fc1cab72d857b1e4852d414862ed8eab1d42960c1fd643985d352c148a6461 2025-02-12
FileHash-SHA256 f29779049f1fc2d45e43d866a845c45dc9aed6c2d9bbf99a8b1bdacfac2d52f2 2025-02-12
FileHash-SHA256 f45661ea4959a944ca2917454d1314546cc0c88537479e00550eef05bed5b1b9 2025-02-12
FileHash-SHA256 f90420847e1f2378ac8c52463038724533a9183f02ce9ad025a6a10fd4327f12 2025-02-12
URL https://support.vmphere.com 2025-02-12
domain autodiscovar.com 2025-02-12
domain checkponit.com 2025-02-12
domain d-links.net 2025-02-12
domain hobiter.com 2025-02-12
domain ictnsc.com 2025-02-12
domain mrd0x.com 2025-02-12
domain vm-clouds.net 2025-02-12
domain vmphere.com 2025-02-12
hostname cloud.autodiscovar.com 2025-02-12
hostname digert.ictnsc.com 2025-02-12
hostname ict.ictnsc.com 2025-02-12
hostname pol.vm-clouds.net 2025-02-12
hostname poster.checkponit.com 2025-02-12
hostname support.fortineat.com 2025-02-12
hostname support.vmphere.com 2025-02-12
hostname update.hobiter.com 2025-02-12