Overview 2,244 indicators
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.
| domain | 1,441 | G0040-domain.txt |
| url_path | 643 | G0040.json |
| ipv4 | 106 | G0040.json |
| url | 54 | G0040.json |
Techniques 41 ATT&CK
Open in ATT&CK Navigator → or download the layer (41 techniques, layer 4.5)
- T1005 Data from Local System
- T1021.001 Remote Desktop Protocol
- T1027.001 Binary Padding
- T1027.002 Software Packing
- T1027.005 Indicator Removal from Tools
- T1027.010 Command Obfuscation
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1053.005 Scheduled Task
- T1055.012 Process Hollowing
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1070.004 File Deletion
- T1074.001 Local Data Staging
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1102.001 Dead Drop Resolver
- T1105 Ingress Tool Transfer
- T1112 Modify Registry
- T1119 Automated Collection
- T1132.001 Standard Encoding
- T1189 Drive-by Compromise
- T1197 BITS Jobs
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1518.001 Security Software Discovery
- T1547.001 Registry Run Keys / Startup Folder
- T1548.002 Bypass User Account Control
- T1553.002 Code Signing
- T1555.003 Credentials from Web Browsers
- T1559.002 Dynamic Data Exchange
- T1560 Archive Collected Data
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1574.001 DLL
- T1587.002 Code Signing Certificates
- T1588.002 Tool
- T1598.003 Spearphishing Link
- T1680 Local Storage Discovery
Software 9
Principal sources 1,101 reports
Ranked by how many of this actor's indicators each report brought in.
- 84x.com/malwrhunterteam/status/1928036337292132…
- 84virustotal.com/gui/ip-address/185.225.17.36/relations
- 84app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104…
- 84virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c…
- 84virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
- 72twitter.com/blackorbird/status/1111159128775249920
- 72netscout.com/blog/asert/lucky-elephant-campaign-masq…
- 54cymmetria.com/wp-content/uploads/2017/10/Unveiling-Pa…
Related groups 11
What the sources have in common — not a claim that these are the same actor. See the whole graph.
3 more in the relationship graph.
Timeline 2,244 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 2,244. Complete: G0040.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/SinghSoodeep/status/2084220447487381592 · virustotal.com/gui/file/d1ae51e18644263c9fdf618b285c97… · virustotal.com/gui/file/6d142127e10dc9bd88e804d0f71278…
domain cas-edu.com domain cas-edu.org domain china-robot.online domain china-robot.org domain eps-expo.com domain gcl-power-cn.org domain humanoid-robot.online domain ljewmte.org domain tickimmazy.org domain wtechnote.org url_path /a5c5a153b6caddd7.php url_path /c019e2b6b055-48d2/a5c5a153b6caddd7.php -
app.validin.com/detail?type=hash&find=caa62d2795e1d6656… · virustotal.com/gui/ip-address/206.188.197.82/relations · virustotal.com/gui/ip-address/45.61.139.141/relations · virustotal.com/gui/file/41fae8ffc58fab5e1405aa95baec29… · virustotal.com/gui/file/e8dcdbbfaea83f0aa48fc74b7fb960…
juffysolute.info -
x.com/ThreatBookLabs/status/19749881418546094…
alex-ikmz.store alex-olpw.store alex-ujmi.com alex-ujmi.store alex-yhnv.store solutionlogz.info solutionpelle.info vomologs.info -
cyderes.com/howler-cell/tracking-donot-apt-c-35-ban…
logshopperz.info quickly21.com virgology.info -
x.com/ThreatBookLabs/status/19749881418546094…
getslogicx.info -
cyderes.com/howler-cell/tracking-donot-apt-c-35-ban…
domain exessupdate.info url_path /5IrzalAfHEUM9Tg6/ url_path /5IrzalAfHEUM9Tg6/5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.ico url_path /5IrzalAfHEUM9Tg6/5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.mp3 url_path /5IrzalAfHEUM9Tg6/5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.mp4 url_path /5IrzalAfHEUM9Tg6/5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.png url_path /5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.ico url_path /5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.mp3 url_path /5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.mp4 url_path /5zbnrP5Dj2BLtwQmZ0pksh86sDDpVlY1WWOk8oExh1o7bh1g.png -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
pineappleworld.best -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
greenpop.online hreatlittleheaven.shop -
x.com/RedDrip7/status/2041718076509712703 · virustotal.com/gui/file/90df3151c6ee487fc2e8a9606e6f45… · rapid7.com/blog/post/tr-malware-tracking-dropping-… · github.com/rapid7/Rapid7-Labs/blob/main/IOCs/Dropp…
/gedhagammgjvvva/ /prjozifvkpkfhkr/ /prjozifvkpkfhkr/gedhagammgjvvva/ /prjozifvkpkfhkr/spxbjdhxtapivrk/ /spxbjdhxtapivrk/ -
rapid7.com/blog/post/tr-malware-tracking-dropping-… · github.com/rapid7/Rapid7-Labs/blob/main/IOCs/Dropp…
chinagreenenergy.org gcl-cn.org gcl-power.org -
x.com/suyog41/status/2060337183874302019 · virustotal.com/gui/file/4e6add88feff408b96f01d15917540…
certific-activation.info ftp.videoinnovationsdaily.com greezupdto.info mail.videoinnovationsdaily.com nikkimstudiosllc.info videoinnovationsdaily.com -
x.com/RedDrip7/status/2052313849278394621 · virustotal.com/gui/file/b793c39e3c9e06a310968ba18e73f0… · virustotal.com/gui/file/fdd0b4f6550dd7be13cb46ec0e0909…
domain mtsspk.net url_path /TrDGjfgtxkdl3Pl47enr/ -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
hubbuchpfada.com -
x.com/phatomcandle/status/2050998845082063322 · virustotal.com/gui/ip-address/45.61.136.27/relations
reggyupdated.info -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
balschsteuerix.com upklarbericht.com -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
liststernia.com -
x.com/ThreatBookLabs/status/19749881418546094…
shadoworkz.info -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
proberichtsweg.com -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
greifbrunnex.com startfinanzio.com wissenbalora.com wisssteuerhub.com -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
klarinkonten.com meiszahlenup.com ulmenbilora.com -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
gotthardsteirw.com steirgothara.com thurraferro.com wegezukunfta.com -
x.com/malwrhunterteam/status/2047237436065894… · virustotal.com/gui/file/9b2637b8fefeedf8dca8a0ace491de… · virustotal.com/gui/file/9d7e12eae6b593e582d8b2c3af3154…
domain paksecurity.org domain techoption.org url_path /H7OG7pFMzFh5.php url_path /tHjFCiMNw5Bs/ url_path /tHjFCiMNw5Bs/H7OG7pFMzFh5.php -
x.com/RedDrip7/status/2046417026835714239 · virustotal.com/gui/file/0c69637c2f54822a2f6c796a780019…
cloudwindowapps.com -
x.com/smica83/status/2044416468469555212 · tria.ge/260415-rc7r1agt7l/behavioral1 · virustotal.com/gui/file/045d995dee9b3fba080415be55c932…
domain arrayhouse.org domain energy.pakpower.org domain ismemcs.org domain moma-cdn.org domain pakistanpower.org domain pakpower.org domain pakserver.live domain pkenergy.org domain pkfileserver.org domain pkserver.live domain psca-gop.org url_path /SqX55Z32TtCh/ url_path /SqX55Z32TtCh/oA3gW185qmtI.php url_path /oA3gW185qmtI.php -
x.com/RedDrip7/status/2041718076509712703 · virustotal.com/gui/file/90df3151c6ee487fc2e8a9606e6f45…
domain sandtribes.org url_path /nhmkifhejdkdmnghdgebc/ url_path /prjozifvkpkfhkr/nhmkifhejdkdmnghdgebc/ url_path /prjozifvkpkfhkr/snedhjnfilmjensbhe/ url_path /snedhjnfilmjensbhe/ -
x.com/ThreatBookLabs/status/19749881418546094…
programgreedz.info -
x.com/malwrhunterteam/status/2032576992596390… · virustotal.com/gui/ip-address/206.71.149.126/relations · virustotal.com/gui/file/caa66675f6574ba2295aff502850a0…
domain flikupdates.info domain locaplayz.info domain regupdates.info url_path /tihRiVEewMOgm6UN/ url_path /tihRiVEewMOgm6UN/fDPlz6QNjof30IVTzyMlLW261LZtf2kN3fFVrEmIP9byeiQX.ico url_path /tihRiVEewMOgm6UN/fDPlz6QNjof30IVTzyMlLW261LZtf2kN3fFVrEmIP9byeiQX.mp3 url_path /tihRiVEewMOgm6UN/fDPlz6QNjof30IVTzyMlLW261LZtf2kN3fFVrEmIP9byeiQX.pptm -
x.com/SinghSoodeep/status/2032443001658540322 · virustotal.com/gui/file/3a2338e1f8bba1c6914545fd24bed1…
muddtech.org -
x.com/ThreatBookLabs/status/19749881418546094…
hillisolutions.info -
x.com/blackorbird/status/2029212305725198559 · mp.weixin.qq.com/s/4Fb6P0ArHeYbKbBHhs4vUQ
upxvion.info -
virustotal.com/gui/file/14f3e99e09adb06a5cd54a62741cd2… · virustotal.com/gui/file/d1232106b929ebb37c482add852af2…
domain blogs.pakdw.live domain pakdw.live url_path /Imbdwexite/ url_path /Imbdwexite/kdtejkli url_path /Mksiwt3df/ url_path /Mksiwt3df/tvfgheurrej url_path /kdtejkli url_path /tvfgheurrej -
x.com/RedDrip7/status/2028721108850225506 · virustotal.com/gui/file/ea649c47cf44498eab67bf6e208586…
domain mnjkuilhgftrew.baiduwebhost.com url_path /gtxkdl3Pl47enr/ -
x.com/RedDrip7/status/2028721108850225506 · virustotal.com/gui/file/246323bc7e5993f89f900e099718a1… · virustotal.com/gui/file/c997638d68430e808fe1cd9f4fedb5…
domain officesite.onrender.com url_path /f80dsnTfr8Dghr58kL/ -
x.com/RedDrip7/status/2028720851491950998 · virustotal.com/gui/file/df51fc728e0ff8c2ed01ee8b3dae29… · virustotal.com/gui/file/807e94b1d69df0b511f3ba0460bb54… · virustotal.com/gui/file/f3a78d41518850fcf368490496c702…
gladiolus.live shop.gladiolus.live -
x.com/500mk500/status/2028854877552587246
daffodil.blog shop.daffodil.blog -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
yumtolo.info -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
domain rnicrosoftcuredrive.org url http://103.172.26.96 -
app.validin.com/detail?type=hash&find=caa62d2795e1d6656… · virustotal.com/gui/ip-address/206.188.197.82/relations · virustotal.com/gui/ip-address/45.61.139.141/relations · virustotal.com/gui/file/41fae8ffc58fab5e1405aa95baec29… · virustotal.com/gui/file/e8dcdbbfaea83f0aa48fc74b7fb960…
soygcp.easypanel.host -
x.com/suyog41/status/2021136856356987347 · virustotal.com/gui/file/24e16b13be82a21d4ebd38715decca…
cppa-pk.org -
app.validin.com/detail?type=hash&find=caa62d2795e1d6656… · virustotal.com/gui/ip-address/206.188.197.82/relations · virustotal.com/gui/ip-address/45.61.139.141/relations · virustotal.com/gui/file/41fae8ffc58fab5e1405aa95baec29… · virustotal.com/gui/file/e8dcdbbfaea83f0aa48fc74b7fb960…
vpn731932925.softether.net -
x.com/mal_analysis136/status/1883446768345718… · virustotal.com/gui/ip-address/38.180.106.242/relations · virustotal.com/gui/ip-address/5.61.48.183/relations · virustotal.com/gui/ip-address/64.176.178.106/relations · virustotal.com/gui/ip-address/72.5.43.148/relations
logsdope.info -
x.com/RedDrip7/status/2017053456037806359 · virustotal.com/gui/file/660ad610b7ab9d090274cea9cc5f14… · virustotal.com/gui/file/1d534cc1f1bf100c5e551613029213… · virustotal.com/gui/file/1cad2c004c9cabaaaf52bfa7ca76bb…
peeca.site webmajic.org -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
boxmaildrive.info compaaat.store mailexcite.store -
app.validin.com/detail?type=hash&find=caa62d2795e1d6656… · virustotal.com/gui/ip-address/206.188.197.82/relations · virustotal.com/gui/ip-address/45.61.139.141/relations · virustotal.com/gui/file/41fae8ffc58fab5e1405aa95baec29… · virustotal.com/gui/file/e8dcdbbfaea83f0aa48fc74b7fb960…
blufflogz.info -
x.com/malwrhunterteam/status/1928036337292132… · virustotal.com/gui/ip-address/185.225.17.36/relations · app.validin.com/detail?find=b0a0f886d1efaa5802076ac2104… · virustotal.com/gui/file/2b24fe48628fe0405db4fa3534d31c… · virustotal.com/gui/file/abefd29c85d69f35f3cf8f5e6a2be7…
domain applepicker.info domain asftbngh.top domain blackmoo.info domain bloomwpp.info domain blueberrytree.info domain bluriq.info domain brightpathos.eu domain buzzstack.org domain cmitx.site domain co2divo.info domain crownmedicals.com domain dearbear.info domain elephantglass.info domain evendarkness.info domain fideline.info domain flyinfishwater.info domain flyingcow.info domain flytree.info domain fusionnook.info domain goooglecloud.site domain govpak.info domain greenhippo.info domain greenpop.info domain hreatlittleheaven.info domain ksecure.bio domain louqhwood.net domain mail.asftbngh.top domain mail.messagenote.org domain martkartout.info domain messagenote.ink domain messagenote.org domain nexnxky.info domain ns1.buzzstack.org domain ns1.wdanasiali.store domain ns2.buzzstack.org domain ns2.wdanasiali.store domain pineappleworld.info domain pinkoceanbees.info domain plumpinr.info domain popcornstudy.info domain purpleyh.info domain redcardboard.info domain setappleclin.info domain smoolideronline.info domain sohbettr.info domain soptr.info domain sunmelonontheway.info domain vibrantforest.info domain wdanasiali.store url_path /Cljfdghdjhndklh_ommjhfdgj/ url_path /Cljfdghdjhndklh_ommjhfdgj/cfnbgjfghom_mun_jkghdfjkghdjklgfk_ication.php url_path /cfnbgjfghom_mun_jkghdfjkghdjklgfk_ication.php url_path /ljhgs563ERWHY3fkdhynkykntn_auto.php url_path /modjghdjkhnlkdnhkdhn/ url_path /reckjfhgjkRETldfhger/ url_path /reckjfhgjkRETldfhger/ljhgs563ERWHY3fkdhynkykntn_auto.php url_path /reckjfhgjkRETldfhger/rkgjdfDRRdfYklhjdlghecived.php url_path /rkgjdfDRRdfYklhjdlghecived.php -
x.com/ThreatBookLabs/status/19525673100883398… · app.validin.com/detail?find=38.180.71.241&type=ip4&ref_… · virustotal.com/gui/file/5a4880a243d191f37c88340940d202…
domain altzserberin.info domain aplcompin.site domain aplinvest.site domain appservices.info domain appshare.buzz domain appshares.buzz domain appsharing.buzz domain appsharinggo.buzz domain appshazing.buzz domain appsservicess.buzz domain appsservicess.info domain appsshares.buzz domain appsupports.info domain appzserv.info domain chartsbezorgd.info domain companive.online domain companive.site domain companivee.site domain fininwesde.com domain globexlogic.info domain inveonapl.site domain linkageread.info domain makerolleds.info domain newivesino.site domain newpolinwess.online domain newpolinwess.site domain newpoolinwes.site domain oneinvcomp.online domain oneinvcomp.site domain playserzapp.info domain playsupport.info domain programseeget.info domain rollededpack.info domain rooflaze.info domain savingnames.info domain servicseskep.info domain shareingsevices.info domain sharereliable.buzz domain sharetosharing.info domain tiffyservics.info domain trendhardoensun.buzz domain visionglobale.site url http://149.248.78.7 url_path /chopseybikametcolkders/ url_path /chopseybikametcolkders/makopetrabispokoletrastyzika url_path /makopetrabispokoletrastyzika -
x.com/ginkgo_g/status/1915332815308403152 · virustotal.com/gui/file/4a626d128f00ed616e9eb3ba098920…
bonfo.breatlee.org breatlee.org feng.breatlee.org fimong.breatlee.org giamon.breatlee.org gioamo.breatlee.org gomong.breatlee.org hiaki.breatlee.org hibnao.breatlee.org jiamjo.breatlee.org jiamo.breatlee.org jiamon.breatlee.org jianom.breatlee.org kiamo.breatlee.org kiamon.breatlee.org kiamoz.breatlee.org kimaho.breatlee.org kmong.breatlee.org komonnv.breatlee.org loma.breatlee.org lomong.breatlee.org mianyo.breatlee.org mingo.breatlee.org mingom.breatlee.org minsaz.breatlee.org miqasn.breatlee.org mkiang.breatlee.org nimon.breatlee.org nomon.breatlee.org olama.breatlee.org viamo.breatlee.org xiamo.breatlee.org xuang.breatlee.org -
mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247514233…
domain bijoyshare.buzz domain diffgrinder.info domain sharetobijoy.buzz url_path /2024/filez/uploadz/invite25.php url_path /4us2rZQSxKVHgbyW/ url_path /4us2rZQSxKVHgbyW/iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.ico url_path /4us2rZQSxKVHgbyW/iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.mp3 url_path /4us2rZQSxKVHgbyW/iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.mp4 url_path /4us2rZQSxKVHgbyW/iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.png url_path /PNubW5l8DVqKlNbo/ url_path /PNubW5l8DVqKlNbo/zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.ico url_path /PNubW5l8DVqKlNbo/zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.mp3 url_path /PNubW5l8DVqKlNbo/zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.mp4 url_path /PNubW5l8DVqKlNbo/zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.png url_path /WxporesjaTexopManor/vrptpvabkokamekastra/ url_path /filez/uploadz/invite25.php url_path /iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.ico url_path /iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.mp3 url_path /iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.mp4 url_path /iAILc6MjCh4QEXTJWmKyY8r4DaoKRwkQ3yjlf0evOOO9vIdh.png url_path /vrptpvabkokamekastra/ url_path /zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.ico url_path /zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.mp3 url_path /zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.mp4 url_path /zFsDitREUBbsbeB815VkWnKpuXN4bhXUg3MFC7txkrV5beqf.png -
x.com/RedDrip7/status/1966329373927288941 · app.validin.com/detail?find=7d70e351fecf88c99b1db4c14b2… · virustotal.com/gui/file/b7c1a2f05b74613f8ff47d40c0a856… · virustotal.com/gui/file/d20d4e90de355c90f4d9a0b7b80cf1… · virustotal.com/gui/file/2f329a1171d2c6b1471604bf76157b…
abcvip.us.org · 21 more in this batch, in the JSON
Further reading 1,110
- symantec.com/connect/blogs/patchwork-cyberespionage-…
- attack.mitre.org/groups/G0040
- documents.trendmicro.com/assets/tech-brief-untangling-the-patchw…
- researchcenter.paloaltonetworks.com/2018/03/unit42-patchwork-continues-deli…
- securelist.com/the-dropping-elephant-actor/75328
- unit42.paloaltonetworks.com/updated-backconfig-malware-targeting-go…
- web.archive.org/web/20140424084220/http://enterprise-ma…
- web.archive.org/web/20180825085952/https:/s3-us-west-2.…
- forcepoint.com/sites/default/files/resources/files/for…
- volexity.com/blog/2018/06/07/patchwork-apt-group-tar…
- twitter.com/Jirehlov/status/1535110745649983488
- twitter.com/ShadowChasing1/status/14214811473898127…
- virustotal.com/gui/file/9ef7031c21675175d39c99e0afa32d…
- twitter.com/h2jazi/status/1415347869318537220
- x.com/suyog41/status/1814230027560501248
- mp.weixin.qq.com/s/Nk2zml2d0HtK0hszyKW2Dw (Chinese)
- twitter.com/ShadowChasing1/status/15725330062373314…
- twitter.com/k3yp0d/status/1780929459689758926
- virustotal.com/gui/file/83fe4fb0c944aa210ab2af579155cc…
- twitter.com/_re_fox/status/1517173649568149504
- twitter.com/suyog41/status/1765725837041824121
- virustotal.com/gui/file/6ddf7b13312987ed7d85ff6795f279…
- virustotal.com/gui/file/d1a9ad4186abdb66340dcad87833d3…
- virustotal.com/gui/file/3ddbd2f9d4194aaebaffda1417b34a…
- twitter.com/ShadowChasing1/status/13848252470613319…
- mp.weixin.qq.com/s/pJTPeK1Cam5n4RUElWzb2Q
- virustotal.com/gui/file/3a7e30efd0a283ef764dfa5762fcb1…
- twitter.com/Des00464472/status/1593132541472837638
- twitter.com/ShadowChasing1/status/15267838344105984…
- twitter.com/GGGGh0st/status/1439120967612002309
- app.validin.com/axon?type=ip&find=5.199.168.207
- virustotal.com/gui/file/61eeb6f444bfc11b718646ba4283fb…
- twitter.com/malwrhunterteam/status/1753536383249985…
- twitter.com/ShadowChasing1/status/15769702093277388…
- virustotal.com/gui/file/d1232106b929ebb37c482add852af2…
- twitter.com/souiten/status/1597944825340305408
- twitter.com/RedDrip7/status/1145539943323717632
- virustotal.com/gui/file/01ea7197094b9acd50605bda611111…
- twitter.com/StopMalvertisin/status/1656583924880146…
- x.com/PrakkiSathwik/status/1822328733610430860
1,070 more, and the report behind every indicator, in G0040.json.