Overview 35 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| domain | 27 | BADMAGIC-domain.txt |
| url | 5 | BADMAGIC.json |
| ipv4 | 2 | BADMAGIC.json |
| url_path | 1 | BADMAGIC.json |
Principal sources 32 reports
Ranked by how many of this actor's indicators each report brought in.
- 14bi.zone/eng/expertise/blog/core-werewolf-protiv…
- 6twitter.com/ShadowChasing1/status/13779737641644769…
- 6twitter.com/ShadowChasing1/status/13779737695793602…
- 6malwarebytes.com/blog/threat-intelligence/2023/05/redsti…
- 6virustotal.com/gui/ip-address/45.154.116.147/relations
- 6virustotal.com/gui/file/fb48b9102388620bb02d1a47297ba1…
- 6virustotal.com/gui/file/301e819008e19b9803ad8b75ecede9…
- 3twitter.com/ginkgo_g/status/1730523884649402872
Timeline 35 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
twitter.com/ginkgo_g/status/1730523884649402872 · virustotal.com/gui/ip-address/5.35.100.31/relations · virustotal.com/gui/file/fa89cbcc99939914e8655aac1f62e0… · virustotal.com/gui/file/c1be9aa6f4ee71180d9779ab8ebae5… · virustotal.com/gui/file/b748d7f3083d6868e1e71469dcbc2d… · virustotal.com/gui/file/22eb4239b472a868ca0ab01bda2820…
ivanovee.ru -
x.com/fstenv/status/1828546982467518823 · virustotal.com/gui/file/14037909d704c418a1d97835bcf7cf…
kb6ns.ru -
x.com/StrikeReadyLabs/status/1811797419971039… · virustotal.com/gui/ip-address/80.85.155.64/relations · virustotal.com/gui/file/42eecd06c7aea0a536f653dd1af238…
astita.ru -
x.com/suyog41/status/1800049246462411209 · virustotal.com/gui/file/33e611181d25079cf975c20bce8a59…
asteriskx.ru -
x.com/suyog41/status/1793183460158312914 · virustotal.com/gui/file/f68996c4d0a72a0b3c3f0757a73636…
01yakutsk.ru mail.01yakutsk.ru -
x.com/alex_lanstein/status/1792291521884283058 · virustotal.com/gui/ip-address/5.8.50.153/relations · virustotal.com/gui/file/7d784e925f73946a63491483369427…
mail.russexportlogistics.ru russexportlogistics.ru -
bi.zone/eng/expertise/blog/core-werewolf-protiv…
autotimesvc.com clodmail.ru contileservices.net licensecheckout.net passportyandex.net savebrowsing.net softdownloaderonline.net statusgeotrust.com tapiservicemgr.com uploaderonline.com uploadingonline.com versusmain.com winupdateronline.com winuptodate.com -
twitter.com/ginkgo_g/status/1730523884649402872 · virustotal.com/gui/ip-address/5.35.100.31/relations · virustotal.com/gui/file/fa89cbcc99939914e8655aac1f62e0… · virustotal.com/gui/file/c1be9aa6f4ee71180d9779ab8ebae5… · virustotal.com/gui/file/b748d7f3083d6868e1e71469dcbc2d… · virustotal.com/gui/file/22eb4239b472a868ca0ab01bda2820…
domain kassperskylaw.ru ipv4 5.35.100.31:443 -
twitter.com/ShadowChasing1/status/13779737641644769… · twitter.com/ShadowChasing1/status/13779737695793602… · malwarebytes.com/blog/threat-intelligence/2023/05/redsti… · virustotal.com/gui/ip-address/45.154.116.147/relations · virustotal.com/gui/file/fb48b9102388620bb02d1a47297ba1… · virustotal.com/gui/file/301e819008e19b9803ad8b75ecede9…
domain securitysearch.ddns.net ipv4 185.166.217.184:2380 url http://176.114.9.192 url http://45.154.116.147 url http://91.234.33.185 -
securelist.com/bad-magic-apt/109087/ (# CommonMagic/Po… · virustotal.com/gui/ip-address/31.31.198.109/relations
webservice-srv.online webservice-srv1.online -
twitter.com/h2jazi/status/1636768039273377797 · virustotal.com/gui/ip-address/95.142.39.88/relations · virustotal.com/gui/file/2df66c8258ca164e2138997754c922…
servicehost-update.net -
twitter.com/h2jazi/status/1573309097021444096 · virustotal.com/gui/file/c75d905cd7826182505c15d39ebe95…
url http://185.166.217.184 url_path /CFVJKXIUPHESRHUSE4FHUREHUIFERAY97A4FXA/ -
twitter.com/ShadowChasing1/status/13779737641644769… · twitter.com/ShadowChasing1/status/13779737695793602… · malwarebytes.com/blog/threat-intelligence/2023/05/redsti… · virustotal.com/gui/ip-address/45.154.116.147/relations · virustotal.com/gui/file/fb48b9102388620bb02d1a47297ba1… · virustotal.com/gui/file/301e819008e19b9803ad8b75ecede9…
http://91.234.33.108
Further reading 32
- twitter.com/ShadowChasing1/status/13779737641644769…
- bi.zone/eng/expertise/blog/core-werewolf-protiv…
- virustotal.com/gui/file/f68996c4d0a72a0b3c3f0757a73636…
- x.com/suyog41/status/1793183460158312914
- twitter.com/h2jazi/status/1573309097021444096
- x.com/StrikeReadyLabs/status/1811797419971039…
- virustotal.com/gui/file/33e611181d25079cf975c20bce8a59…
- virustotal.com/gui/file/22eb4239b472a868ca0ab01bda2820…
- virustotal.com/gui/file/7d784e925f73946a63491483369427…
- virustotal.com/gui/ip-address/5.8.50.153/relations
- virustotal.com/gui/file/c75d905cd7826182505c15d39ebe95…
- virustotal.com/gui/ip-address/5.35.100.31/relations
- virustotal.com/gui/file/fb48b9102388620bb02d1a47297ba1…
- virustotal.com/gui/file/b748d7f3083d6868e1e71469dcbc2d…
- twitter.com/h2jazi/status/1636768039273377797
- twitter.com/ShadowChasing1/status/13779737695793602…
- virustotal.com/gui/ip-address/80.85.155.64/relations
- virustotal.com/gui/ip-address/31.31.198.109/relations
- malwarebytes.com/blog/threat-intelligence/2023/05/redsti…
- virustotal.com/gui/ip-address/45.154.116.147/relations
- x.com/alex_lanstein/status/1792291521884283058
- x.com/fstenv/status/1828546982467518823
- virustotal.com/gui/file/14037909d704c418a1d97835bcf7cf…
- virustotal.com/gui/ip-address/95.142.39.88/relations
- virustotal.com/gui/file/fa89cbcc99939914e8655aac1f62e0…
- virustotal.com/gui/file/301e819008e19b9803ad8b75ecede9…
- virustotal.com/gui/file/42eecd06c7aea0a536f653dd1af238…
- virustotal.com/gui/file/2df66c8258ca164e2138997754c922…
- securelist.com/bad-magic-apt/109087/ (# CommonMagic/Po…
- virustotal.com/gui/file/c1be9aa6f4ee71180d9779ab8ebae5…
- x.com/suyog41/status/1800049246462411209
- twitter.com/ginkgo_g/status/1730523884649402872