{
  "aliases": [
    "dinodas",
    "dinodasrat",
    "linodas",
    "linodasrat"
  ],
  "attack_id": null,
  "attack_name": null,
  "attack_url": null,
  "counts": {
    "domain": 12,
    "ipv4": 7,
    "url": 5
  },
  "first_seen": {
    "domain": {
      "115-126-98-204.hkt.cc": "2023-10-10",
      "118-99-6-202.hkt.cc": "2023-10-10",
      "centos-yum.com": "2023-10-10",
      "microsoft-setting.com": "2023-10-10",
      "microsoft-settings.com": "2024-03-29",
      "security-microsoft.net": "2024-03-18",
      "server-microsoft.com": "2024-03-18",
      "update.centos-yum.com": "2023-10-10",
      "update.microsoft-setting.com": "2023-10-10",
      "update.microsoft-settings.com": "2024-03-29",
      "update.windows.server-microsoft.com": "2024-03-18",
      "windows.server-microsoft.com": "2024-03-18"
    },
    "ipv4": {
      "115.126.98.204:443": "2023-10-10",
      "118.107.221.43:443": "2026-01-02",
      "118.107.221.43:5000": "2026-01-02",
      "118.107.221.43:8080": "2026-01-02",
      "118.99.6.202:443": "2023-10-10",
      "199.231.211.19:30612": "2023-10-11",
      "199.231.211.19:8080": "2023-10-11"
    },
    "url": {
      "http://115.126.98.204": "2023-10-10",
      "http://118.99.6.202": "2023-10-10",
      "http://23.106.122.46": "2023-10-10",
      "http://23.106.122.5": "2023-10-10",
      "http://23.106.123.166": "2023-10-10"
    }
  },
  "first_seen_precision": {
    "domain": {},
    "ipv4": {
      "118.107.221.43:443": "at-or-before",
      "118.107.221.43:5000": "at-or-before",
      "118.107.221.43:8080": "at-or-before"
    },
    "url": {}
  },
  "first_seen_range": {
    "earliest": "2023-10-10",
    "latest": "2026-01-02"
  },
  "generated_at": "2026-08-08T03:26:30+00:00",
  "indicators": {
    "domain": [
      "115-126-98-204.hkt.cc",
      "118-99-6-202.hkt.cc",
      "centos-yum.com",
      "microsoft-setting.com",
      "microsoft-settings.com",
      "security-microsoft.net",
      "server-microsoft.com",
      "update.centos-yum.com",
      "update.microsoft-setting.com",
      "update.microsoft-settings.com",
      "update.windows.server-microsoft.com",
      "windows.server-microsoft.com"
    ],
    "ipv4": [
      "115.126.98.204:443",
      "118.107.221.43:443",
      "118.107.221.43:5000",
      "118.107.221.43:8080",
      "118.99.6.202:443",
      "199.231.211.19:30612",
      "199.231.211.19:8080"
    ],
    "url": [
      "http://115.126.98.204",
      "http://118.99.6.202",
      "http://23.106.122.46",
      "http://23.106.122.5",
      "http://23.106.123.166"
    ]
  },
  "last_modified": "2026-01-02T23:10:15+00:00",
  "maltrail_groups": [
    "EARTHKRAHANG"
  ],
  "references": [
    "https://github.com/eset/malware-ioc/tree/master/operation_jacana",
    "https://securelist.com/dinodasrat-linux-implant/112284/",
    "https://www.trendmicro.com/content/dam/trendmicro/global/en/research/24/c/earth-krahang-exploits-intergovernmental-trust-to-launch-cross-government-attacks/earth_krahang_iocs.txt",
    "https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html",
    "https://www.virustotal.com/gui/file/15412d1a6b7f79fad45bcd32cf82f9d651d9ccca082f98a0cca3ad5335284e45/detection",
    "https://www.virustotal.com/gui/file/18f4f14857e9b7e3aa1f6f21f21396abd5f421342b7f4d00402a4aff5a538fa1/detection",
    "https://www.virustotal.com/gui/file/339479cb5a54424b520ff85f297882d410b8ecf179a45bad2c112b8c14f7575c/detection",
    "https://www.virustotal.com/gui/file/3f0aa01ed70bc2ab29557521a65476ec2ff2c867315067cc8a5937d63bcbe815/detection",
    "https://www.virustotal.com/gui/file/6fd7697efc137faf2d3ad5d63ffe4743db70f905a71dbed76207beeeb04732f2/detection",
    "https://www.virustotal.com/gui/file/98b5b4f96d4e1a9a6e170a4b2740ce1a1dfc411ada238e42a5954e66559a5541/detection",
    "https://www.virustotal.com/gui/file/9edf5313596432b4bad03bb7b16537c44652289b113430de7e3ed1cb5cf0760f/detection",
    "https://www.virustotal.com/gui/file/a2c3073fa5587f8a70d7def7fd8355e1f6d20eb906c3cd4df8c744826cb81d91/detection",
    "https://www.virustotal.com/gui/file/d17fe5bc3042baf219e81cbbf991749dfcd8b6d73cf6506a8228e19910da3578/detection",
    "https://www.virustotal.com/gui/file/d2a832f8430636b3c53e7fe75c1df20e07850f68024a39708a2491005470e674/detection",
    "https://www.virustotal.com/gui/file/e0f109836a025d4531ea895cebecc9bdefb84a0cc747861986c4bc231e1d4213/detection",
    "https://www.virustotal.com/gui/ip-address/115.126.98.204/relations",
    "https://www.virustotal.com/gui/ip-address/118.99.6.202/relations",
    "https://www.virustotal.com/gui/ip-address/199.231.211.19/relations",
    "https://www.welivesecurity.com/en/eset-research/operation-jacana-spying-guyana-entity/",
    "https://x.com/Cyberteam008/status/1907257221118881893",
    "https://x.com/Cyberteam008/status/1927207900033802624"
  ],
  "related": [],
  "slug": "EARTHKRAHANG",
  "timeline": [
    {
      "counts": {
        "ipv4": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "ipv4": [
          "118.107.221.43:443",
          "118.107.221.43:8080"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/Cyberteam008/status/1907257221118881893",
        "https://www.virustotal.com/gui/file/9edf5313596432b4bad03bb7b16537c44652289b113430de7e3ed1cb5cf0760f/detection",
        "https://www.virustotal.com/gui/file/d2a832f8430636b3c53e7fe75c1df20e07850f68024a39708a2491005470e674/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "ipv4": [
          "118.107.221.43:5000"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/Cyberteam008/status/1927207900033802624",
        "https://www.virustotal.com/gui/file/339479cb5a54424b520ff85f297882d410b8ecf179a45bad2c112b8c14f7575c/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-03-29",
      "indicators": {
        "domain": [
          "microsoft-settings.com",
          "update.microsoft-settings.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://securelist.com/dinodasrat-linux-implant/112284/",
        "https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html",
        "https://www.trendmicro.com/content/dam/trendmicro/global/en/research/24/c/earth-krahang-exploits-intergovernmental-trust-to-launch-cross-government-attacks/earth_krahang_iocs.txt"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 4
      },
      "first_seen": "2024-03-18",
      "indicators": {
        "domain": [
          "security-microsoft.net",
          "server-microsoft.com",
          "update.windows.server-microsoft.com",
          "windows.server-microsoft.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://securelist.com/dinodasrat-linux-implant/112284/",
        "https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html",
        "https://www.trendmicro.com/content/dam/trendmicro/global/en/research/24/c/earth-krahang-exploits-intergovernmental-trust-to-launch-cross-government-attacks/earth_krahang_iocs.txt"
      ],
      "total": 4
    },
    {
      "counts": {
        "ipv4": 2
      },
      "first_seen": "2023-10-11",
      "indicators": {
        "ipv4": [
          "199.231.211.19:30612",
          "199.231.211.19:8080"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.welivesecurity.com/en/eset-research/operation-jacana-spying-guyana-entity/",
        "https://github.com/eset/malware-ioc/tree/master/operation_jacana",
        "https://www.virustotal.com/gui/ip-address/115.126.98.204/relations",
        "https://www.virustotal.com/gui/ip-address/118.99.6.202/relations",
        "https://www.virustotal.com/gui/ip-address/199.231.211.19/relations",
        "https://www.virustotal.com/gui/file/15412d1a6b7f79fad45bcd32cf82f9d651d9ccca082f98a0cca3ad5335284e45/detection",
        "https://www.virustotal.com/gui/file/e0f109836a025d4531ea895cebecc9bdefb84a0cc747861986c4bc231e1d4213/detection",
        "https://www.virustotal.com/gui/file/d17fe5bc3042baf219e81cbbf991749dfcd8b6d73cf6506a8228e19910da3578/detection",
        "https://www.virustotal.com/gui/file/18f4f14857e9b7e3aa1f6f21f21396abd5f421342b7f4d00402a4aff5a538fa1/detection",
        "https://www.virustotal.com/gui/file/6fd7697efc137faf2d3ad5d63ffe4743db70f905a71dbed76207beeeb04732f2/detection",
        "https://www.virustotal.com/gui/file/3f0aa01ed70bc2ab29557521a65476ec2ff2c867315067cc8a5937d63bcbe815/detection",
        "https://www.virustotal.com/gui/file/a2c3073fa5587f8a70d7def7fd8355e1f6d20eb906c3cd4df8c744826cb81d91/detection",
        "https://www.virustotal.com/gui/file/98b5b4f96d4e1a9a6e170a4b2740ce1a1dfc411ada238e42a5954e66559a5541/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 6,
        "ipv4": 2,
        "url": 5
      },
      "first_seen": "2023-10-10",
      "indicators": {
        "domain": [
          "115-126-98-204.hkt.cc",
          "118-99-6-202.hkt.cc",
          "centos-yum.com",
          "microsoft-setting.com",
          "update.centos-yum.com",
          "update.microsoft-setting.com"
        ],
        "ipv4": [
          "115.126.98.204:443",
          "118.99.6.202:443"
        ],
        "url": [
          "http://115.126.98.204",
          "http://118.99.6.202",
          "http://23.106.122.46",
          "http://23.106.122.5",
          "http://23.106.123.166"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.welivesecurity.com/en/eset-research/operation-jacana-spying-guyana-entity/",
        "https://github.com/eset/malware-ioc/tree/master/operation_jacana",
        "https://www.virustotal.com/gui/ip-address/115.126.98.204/relations",
        "https://www.virustotal.com/gui/ip-address/118.99.6.202/relations",
        "https://www.virustotal.com/gui/ip-address/199.231.211.19/relations",
        "https://www.virustotal.com/gui/file/15412d1a6b7f79fad45bcd32cf82f9d651d9ccca082f98a0cca3ad5335284e45/detection",
        "https://www.virustotal.com/gui/file/e0f109836a025d4531ea895cebecc9bdefb84a0cc747861986c4bc231e1d4213/detection",
        "https://www.virustotal.com/gui/file/d17fe5bc3042baf219e81cbbf991749dfcd8b6d73cf6506a8228e19910da3578/detection",
        "https://www.virustotal.com/gui/file/18f4f14857e9b7e3aa1f6f21f21396abd5f421342b7f4d00402a4aff5a538fa1/detection",
        "https://www.virustotal.com/gui/file/6fd7697efc137faf2d3ad5d63ffe4743db70f905a71dbed76207beeeb04732f2/detection",
        "https://www.virustotal.com/gui/file/3f0aa01ed70bc2ab29557521a65476ec2ff2c867315067cc8a5937d63bcbe815/detection",
        "https://www.virustotal.com/gui/file/a2c3073fa5587f8a70d7def7fd8355e1f6d20eb906c3cd4df8c744826cb81d91/detection",
        "https://www.virustotal.com/gui/file/98b5b4f96d4e1a9a6e170a4b2740ce1a1dfc411ada238e42a5954e66559a5541/detection"
      ],
      "total": 13
    }
  ]
}
