{
  "aliases": [
    "BlackGuard",
    "cherryspy",
    "hatvibe"
  ],
  "attack_id": null,
  "attack_name": null,
  "attack_url": null,
  "counts": {
    "domain": 10,
    "ipv4": 1,
    "url": 7,
    "url_path": 1
  },
  "first_seen": {
    "domain": {
      "background-services.net": "2025-01-13",
      "diagnostic-resolver.com": "2023-05-22",
      "download-resourses.info": "2025-01-13",
      "energieecoinnov.info": "2025-01-13",
      "energieecotech.info": "2025-01-13",
      "enrollmentdm.com": "2024-07-23",
      "lookup.ink": "2025-01-13",
      "ms-webdav-miniredir.com": "2023-05-22",
      "net-certificate.services": "2023-05-22",
      "trust-certificate.net": "2024-07-23"
    },
    "ipv4": {
      "38.180.207.137:45323": "2025-01-13"
    },
    "url": {
      "http://139.99.126.38": "2023-05-22",
      "http://206.166.251.216": "2023-05-22",
      "http://38.180.206.61": "2025-01-13",
      "http://38.180.207.137": "2025-01-13",
      "http://45.136.198.184": "2024-07-23",
      "http://5.45.70.178": "2024-07-23",
      "http://84.32.188.123": "2023-05-22"
    },
    "url_path": {
      "/hftqlbgtg.php": "2023-05-22"
    }
  },
  "first_seen_precision": {
    "domain": {},
    "ipv4": {},
    "url": {},
    "url_path": {}
  },
  "first_seen_range": {
    "earliest": "2023-05-22",
    "latest": "2025-01-13"
  },
  "generated_at": "2026-08-08T03:26:30+00:00",
  "indicators": {
    "domain": [
      "background-services.net",
      "diagnostic-resolver.com",
      "download-resourses.info",
      "energieecoinnov.info",
      "energieecotech.info",
      "enrollmentdm.com",
      "lookup.ink",
      "ms-webdav-miniredir.com",
      "net-certificate.services",
      "trust-certificate.net"
    ],
    "ipv4": [
      "38.180.207.137:45323"
    ],
    "url": [
      "http://139.99.126.38",
      "http://206.166.251.216",
      "http://38.180.206.61",
      "http://38.180.207.137",
      "http://45.136.198.184",
      "http://5.45.70.178",
      "http://84.32.188.123"
    ],
    "url_path": [
      "/hftqlbgtg.php"
    ]
  },
  "last_modified": "2026-01-02T23:10:15+00:00",
  "maltrail_groups": [
    "DOWNEX"
  ],
  "references": [
    "https://app.validin.com/detail?find=dd9aef0ce3d64a9dd4009357637617fc&type=hash&ref_id=1065472a0a3#tab=host_pairs",
    "https://blog.sekoia.io/double-tap-campaign-russia-nexus-apt-possibly-related-to-apt28-conducts-cyber-espionage-on-central-asia-and-kazakhstan-diplomatic-relations/",
    "https://cert.gov.ua/article/4697016 (Ukrainian)",
    "https://cert.gov.ua/article/6280129",
    "https://search.censys.io/hosts/38.180.206.61",
    "https://search.censys.io/hosts/38.180.207.137",
    "https://www.bitdefender.com/blog/businessinsights/deep-dive-into-downex-espionage-operation-in-central-asia/",
    "https://www.virustotal.com/gui/file/70d8e503fd199de816815b88e82fe70802955437cdc3785cbd0d34e0343ce5f1/detection",
    "https://www.virustotal.com/gui/file/75395359af2d61b2434d68fbee12ebc9947c4d113ca8363dd060caab76077474/detection",
    "https://www.virustotal.com/gui/file/cb9405390b4eb81beebb91ee596f77103e6ee47927c3f27d85474d06e2250e31/detection",
    "https://www.virustotal.com/gui/ip-address/172.104.62.59/relations",
    "https://www.virustotal.com/gui/ip-address/185.158.248.198/relations",
    "https://www.virustotal.com/gui/ip-address/185.203.117.6/relations",
    "https://www.virustotal.com/gui/ip-address/194.31.55.131/relations",
    "https://www.virustotal.com/gui/ip-address/79.124.60.180/relations",
    "https://x.com/lontze7/status/1878800751532896679"
  ],
  "related": [],
  "slug": "DOWNEX",
  "timeline": [
    {
      "counts": {
        "domain": 5,
        "ipv4": 1,
        "url": 2
      },
      "first_seen": "2025-01-13",
      "indicators": {
        "domain": [
          "background-services.net",
          "download-resourses.info",
          "energieecoinnov.info",
          "energieecotech.info",
          "lookup.ink"
        ],
        "ipv4": [
          "38.180.207.137:45323"
        ],
        "url": [
          "http://38.180.206.61",
          "http://38.180.207.137"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/lontze7/status/1878800751532896679",
        "https://blog.sekoia.io/double-tap-campaign-russia-nexus-apt-possibly-related-to-apt28-conducts-cyber-espionage-on-central-asia-and-kazakhstan-diplomatic-relations/",
        "https://search.censys.io/hosts/38.180.206.61",
        "https://search.censys.io/hosts/38.180.207.137",
        "https://app.validin.com/detail?find=dd9aef0ce3d64a9dd4009357637617fc&type=hash&ref_id=1065472a0a3#tab=host_pairs"
      ],
      "total": 8
    },
    {
      "counts": {
        "domain": 2,
        "url": 2
      },
      "first_seen": "2024-07-23",
      "indicators": {
        "domain": [
          "enrollmentdm.com",
          "trust-certificate.net"
        ],
        "url": [
          "http://45.136.198.184",
          "http://5.45.70.178"
        ]
      },
      "precision": "exact",
      "references": [
        "https://cert.gov.ua/article/6280129",
        "https://www.virustotal.com/gui/ip-address/185.158.248.198/relations",
        "https://www.virustotal.com/gui/ip-address/194.31.55.131/relations"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 3,
        "url": 3
      },
      "first_seen": "2023-05-22",
      "indicators": {
        "domain": [
          "diagnostic-resolver.com",
          "ms-webdav-miniredir.com",
          "net-certificate.services"
        ],
        "url": [
          "http://139.99.126.38",
          "http://206.166.251.216",
          "http://84.32.188.123"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.bitdefender.com/blog/businessinsights/deep-dive-into-downex-espionage-operation-in-central-asia/",
        "https://cert.gov.ua/article/4697016 (Ukrainian)",
        "https://www.virustotal.com/gui/ip-address/172.104.62.59/relations",
        "https://www.virustotal.com/gui/ip-address/185.203.117.6/relations",
        "https://www.virustotal.com/gui/ip-address/79.124.60.180/relations",
        "https://www.virustotal.com/gui/file/cb9405390b4eb81beebb91ee596f77103e6ee47927c3f27d85474d06e2250e31/detection",
        "https://www.virustotal.com/gui/file/70d8e503fd199de816815b88e82fe70802955437cdc3785cbd0d34e0343ce5f1/detection",
        "https://www.virustotal.com/gui/file/75395359af2d61b2434d68fbee12ebc9947c4d113ca8363dd060caab76077474/detection"
      ],
      "total": 6
    },
    {
      "counts": {
        "url_path": 1
      },
      "first_seen": "2023-05-22",
      "indicators": {
        "url_path": [
          "/hftqlbgtg.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/lontze7/status/1878800751532896679",
        "https://blog.sekoia.io/double-tap-campaign-russia-nexus-apt-possibly-related-to-apt28-conducts-cyber-espionage-on-central-asia-and-kazakhstan-diplomatic-relations/",
        "https://search.censys.io/hosts/38.180.206.61",
        "https://search.censys.io/hosts/38.180.207.137",
        "https://app.validin.com/detail?find=dd9aef0ce3d64a9dd4009357637617fc&type=hash&ref_id=1065472a0a3#tab=host_pairs"
      ],
      "total": 1
    }
  ]
}
