Overview 271 indicators
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.
| domain | 220 | G0049-domain.txt |
| ipv4 | 42 | G0049.json |
| url | 6 | G0049.json |
| url_path | 3 | G0049.json |
Techniques 76 ATT&CK
Open in ATT&CK Navigator → or download the layer (76 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.004 LSA Secrets
- T1003.005 Cached Domain Credentials
- T1005 Data from Local System
- T1007 System Service Discovery
- T1008 Fallback Channels
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1021.001 Remote Desktop Protocol
- T1021.004 SSH
- T1025 Data from Removable Media
- T1027.005 Indicator Removal from Tools
- T1027.013 Encrypted/Encoded File
- T1033 System Owner/User Discovery
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1068 Exploitation for Privilege Escalation
- T1069.001 Local Groups
- T1069.002 Domain Groups
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1071.004 DNS
- T1078 Valid Accounts
- T1078.002 Domain Accounts
- T1082 System Information Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1105 Ingress Tool Transfer
- T1110 Brute Force
- T1112 Modify Registry
- T1113 Screen Capture
- T1115 Clipboard Data
- T1119 Automated Collection
- T1120 Peripheral Device Discovery
- T1133 External Remote Services
- T1137.004 Outlook Home Page
- T1140 Deobfuscate/Decode Files or Information
- T1195 Supply Chain Compromise
- T1201 Password Policy Discovery
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1218.001 Compiled HTML File
- T1219 Remote Access Tools
- T1497.001 System Checks
- T1505.003 Web Shell
- T1543.003 Windows Service
- T1552.001 Credentials In Files
- T1553.002 Code Signing
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1555.004 Windows Credential Manager
- T1556.002 Password Filter DLL
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1566.003 Spearphishing via Service
- T1572 Protocol Tunneling
- T1573.002 Asymmetric Cryptography
- T1583.001 Domains
- T1586.002 Email Accounts
- T1587.001 Malware
- T1588.002 Tool
- T1588.003 Code Signing Certificates
- T1608.001 Upload Malware
- T1686.003 Windows Host Firewall
Software 30
- Mimikatz
- PsExec
- Net
- Tasklist
- Reg
- ftp
- Systeminfo
- ipconfig
- netstat
- certutil
- Helminth
- POWRUNER
- SEASHARPEE
- ISMInjector
- RGDoor
- OopsIE
- QUADAGENT
- LaZagne
- BONDUPDATER
- RDAT
- ngrok
- SideTwist
- ZeroCleare
- Solar
- SampleCheck5000
- Mango
- ODAgent
- OilCheck
- OilBooster
- PowerExchange
Principal sources 101 reports
Ranked by how many of this actor's indicators each report brought in.
- 42domaintools.com/resources/blog/identifying-critical-inf…
- 42otx.alienvault.com/pulse/5fcfc04c753344dd65c6135d
- 27blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targe…
- 27fortinet.com/blog/threat-research/please-confirm-you…
- 27otx.alienvault.com/pulse/627ce7ceecf262a2aff36f9f
- 27virustotal.com/gui/file/e0872958b8d3824089e5e1cfab03d9…
- 23x.com/Cyber_O51NT/status/1834069690777301121
- 23research.checkpoint.com/2024/iranian-malware-attacks-iraqi-gove…
Related groups 8
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 271 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/ThreatBookLabs/status/18994726308494136… · x.com/ThreatBookLabs/status/19066703111450913… · x.com/ThreatBookLabs/status/19399722432386336… · threatbook.io/blog/id/1101 · app.validin.com/detail?find=b60d5beecd0576e7c59f2195e24… · app.validin.com/detail?find=3981e30d1289ce1be9210c929a6… · virustotal.com/gui/file/b607d60d680f1f1335902a666df843…
domain mytrustiq.com ipv4 151.236.17.231:8989 ipv4 185.76.78.177:8989 ipv4 185.76.78.177:9090 ipv4 192.71.166.24:10443 ipv4 193.36.132.224:8080 ipv4 198.44.140.29:8989 ipv4 38.180.31.225:443 ipv4 38.180.31.225:8080 ipv4 89.46.233.239:10443 ipv4 89.46.233.239:8080 ipv4 91.132.95.117:8080 ipv4 91.132.95.117:8989 ipv4 95.156.204.168:10443 ipv4 95.156.204.168:443 ipv4 95.156.204.168:8080 -
hunt.io/blog/track-apt34-like-infrastructure-be…
domain axoryvexity.eu domain biam-iraq.org domain iraqmailservice.com domain plenoryvantyx.eu domain valtorynexon.eu domain valtryventyx.eu domain westagnews.com domain zyverantova.eu ipv4 38.180.140.30:8080 ipv4 38.180.18.189:8080 -
x.com/ThreatBookLabs/status/19244705993944227…
91.184.249.198:443 -
x.com/Cyberteam008/status/1834415607825277069 · x.com/Aarn63373424/status/1834496842580505035 · en.fofa.info/result?qbase64=IHRpdGxlPT0iZ29vZF9uZXdz… · zoomeye.hk/searchResult?q=title%3A%22good_news_sit…
151.236.17.231:8080 185.76.78.177:8080 198.44.140.29:8080 91.132.95.117:8081 -
x.com/Cyber_O51NT/status/1834069690777301121 · research.checkpoint.com/2024/iranian-malware-attacks-iraqi-gove… · app.validin.com/detail?find=151.236.17.231&type=ip4&ref… · app.validin.com/detail?find=185.76.78.177&type=ip4&ref_… · virustotal.com/gui/ip-address/194.68.32.114/relations · virustotal.com/gui/ip-address/206.206.123.176/relations · virustotal.com/gui/ip-address/37.1.213.152/relations · virustotal.com/gui/file/1388f124c6af24eefe5483a5a50ab1… · virustotal.com/gui/file/413cef6cf83ff649c15c60fff88819… · virustotal.com/gui/file/81e3e31ffd8aa0a96f48eeb638eed9… · virustotal.com/gui/file/b85ffc8af90d4312aca9a81e0da00a… · virustotal.com/gui/file/dcdaa9da5ee4750b1084f7dd99faee…
domain admin.mofaiq.com domain apps.iqwebservice.com domain asiacall.net domain base32.iqwebservice.com domain iqwebservice.com domain mofaiq.com domain ns1.asiacall.net domain ns1.iqwebservice.com domain ns1.mofaiq.com domain ns1.spacenet.fun domain ns2.iqwebservice.com domain ns2.mofaiq.com domain ns2.spacenet.fun domain spacenet.fun domain truetone.cfd ipv4 151.236.17.231:53 ipv4 185.76.78.177:53 ipv4 194.68.32.114:53 ipv4 206.206.123.176:443 ipv4 206.206.123.176:8080 ipv4 37.1.213.152:39654 ipv4 37.1.213.152:8999 ipv4 91.132.95.117:53 -
x.com/k3yp0d/status/1834192780605710659 · app.validin.com/detail?find=helllllllllllllllllllllllll…
fastasia.shop ns1.fastasia.shop ns2.fastasia.shop -
welivesecurity.com/en/eset-research/oilrig-persistent-atta… · otx.alienvault.com/pulse/657b11ab57c4b75f5004b236
host1.com/rt.ovf -
trendmicro.com/en_us/research/23/i/apt34-deploys-phish… · virustotal.com/gui/file/8a8a7a506fd57bde314ce6154f2484… · virustotal.com/gui/file/64156f9ca51951a9bf91b5b74073d3…
tecforsc-001-site1.gtempurl.com -
twitter.com/t3ft3lb/status/1605487437995597826 · virustotal.com/gui/file/d33da74a263c03bb9473ac6db7ef1a…
262t3my0gt.cardioteacher.com 7a7n4j60g4.cardioteacher.com cardioteacher.com egef74rfrf.cardioteacher.com mxmbwci0gs.cardioteacher.com pkpqzvgb3t.cardioteacher.com shsz3eub38.cardioteacher.com u3u6gm4b34.cardioteacher.com zgz4sjvb33.cardioteacher.com -
virustotal.com/gui/file/b69812221cd9328a70c90f771c58be…
2zcf.uber-asia.com efezhyrzc9.joexpediagroup.com -
blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targe… · fortinet.com/blog/threat-research/please-confirm-you… · otx.alienvault.com/pulse/627ce7ceecf262a2aff36f9f · virustotal.com/gui/file/e0872958b8d3824089e5e1cfab03d9…
astrazencea.com astrazeneeca.com cisco0.com coinbasedeutschland.com hsbcbkcn.com ntu-sg-edu.com theworldbank.uk valtronics-ae.com -
blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targe… · fortinet.com/blog/threat-research/please-confirm-you… · otx.alienvault.com/pulse/627ce7ceecf262a2aff36f9f · virustotal.com/gui/file/e0872958b8d3824089e5e1cfab03d9…
2fhj.asiaworldremit.com 2u21hipg70.uber-asia.com 3j3oyvsf8i.joexpediagroup.com 5s5gp24f8x.asiaworldremit.com 7w7rbgt13f.uber-asia.com asiaworldremit.com j9jnkf7asv.joexpediagroup.com joexpediagroup.com jqj6po1g71.uber-asia.com ozo26hwfhl.uber-asia.com p5p98ljg7e.asiaworldremit.com qcqrpjgasn.joexpediagroup.com r2rcdvnasg.asiaworldremit.com t3tadulf8d.joexpediagroup.com uber-asia.com ucu4dsvf8m.joexpediagroup.com vhvn201135.joexpediagroup.com w0wiq48g7w.uber-asia.com zlz5ow818r.joexpediagroup.com -
twitter.com/__0XYC__/status/1468909913976025100 · virustotal.com/gui/file/5b5b1608e6736c7759b1ecf61e7567…
domain bgre.kozow.com url karachidha.org/docs/EOIForm.rtf url_path /Gfg786v6fcd6v8j09jg67f6/ url_path /Gfg786v6fcd6v8j09jg67f6/addentry2.php url_path /Gfg786v6fcd6v8j09jg67f6/dolist.php -
blog.morphisec.com/microsoft-equation-editor-backdoor · virustotal.com/gui/file/5b307600b1ceb84f29315c95e5b217… · virustotal.com/gui/file/17f9db18327a29777b01d741f7631d…
ipv4 185.198.59.121:137 ipv4 185.198.59.121:139 ipv4 185.198.59.121:445 url http://138.68.234.128 url http://185.198.59.121 -
twitter.com/AnonySecAgency/status/14054519683744440… · virustotal.com/gui/file/1f47770cc42ac8805060004f203a5f… · virustotal.com/gui/file/cb00ee3f246a3d3af6ba4f97546a39… · virustotal.com/gui/file/f91c5250b33fc5f95495c5e3d63b5f…
mail.army.gov.lb -
virustotal.com/gui/file/08261ed40e21140eb438f16af02332…
akastatus.com yciwcgakeqowsbrieq1sqtahecq96qca.dnsstatus.org yciwfgpmeq5wstpke6psqtahecnue5we.defenderlive.com yciwfgroetpwetaletomqtahecq96qca.defenderlive.com yciwftaie66jstpmds5sqtahecnue5we.dnsstatus.org yciwftaketowstrmehpsqtahecnuetwb.dnsstatus.org yciwstrnecpwebaletpmqtahecnuec5d.dnsstatus.org yciwzbrue66jsbaoespsqtahecnuetwb.defenderlive.com yciwztanet1kcpnjds1wepwacqmz6frgxqlzutrxsmuux.defenderlive.com -
research.checkpoint.com/2021/irans-apt34-returns-with-an-update… · otx.alienvault.com/pulse/606f347aadebd8f4dd043ac9
sarmsoftware.com -
twitter.com/kyleehmke/status/1359828105804869634
pluginmain.com -
twitter.com/kyleehmke/status/1349041310704029701
severalfissures.com -
twitter.com/kyleehmke/status/1340304704589492225
crucialanswer.com endlesspromises.com forecasterman.com hopeisstamina.com unsecuredstorage.com -
twitter.com/kyleehmke/status/1339410533410369537
acceptplan.com confusedtown.com importantgate.com -
twitter.com/kyleehmke/status/1338907878455963648
donotfollowmeass.com -
domaintools.com/resources/blog/identifying-critical-inf… · otx.alienvault.com/pulse/5fcfc04c753344dd65c6135d
domain ababab.biz domain alcirineos.com domain amazon-loveyou.com domain anhuisiafu.com domain bargertextiles.com domain berqertextiles.com domain boardexecutivemanagement.com domain boardsexecutives.com domain cererock.com domain chinaconstructioncorp.com domain clearinghouseinternational.com domain connect-roofing.com domain cornerstoneconect.com domain exmngt.com domain groupsexecutive.com domain hoganlouells.com domain hscminkjet.com domain huopay.top domain indeptheva.com domain jiabolianjie0.com domain jinkangpu.co domain jlrootfile.com domain kent-lawfirm.net domain lavalingroup.com domain mngtboard.com domain oculus-au.info domain pet188.biz domain petrochinas.com domain renrenbaowang.com domain renrenbaowang.net domain stagmein.pl domain superrnax.com domain svn-stone.com domain us-customs.org domain virtual-slots.com domain virtualcaresadvisor.com domain wilsonconts.com domain wiqzi.com domain zj-tunq.com url iafflocal290.org/sapm/Poland/china.php -
twitter.com/kyleehmke/status/1332716197188661248 · domaintools.com/resources/blog/identifying-critical-inf… · otx.alienvault.com/pulse/5fcfc04c753344dd65c6135d
klwebsrv.com -
twitter.com/kyleehmke/status/1332141973403291648 · domaintools.com/resources/blog/identifying-critical-inf… · otx.alienvault.com/pulse/5fcfc04c753344dd65c6135d
careers-ntiva.com -
twitter.com/ShadowChasing1/status/13067802163842580… · virustotal.com/gui/file/0ee32e3ea3d83da9df6317d7c8c539…
windowscredcity.com -
twitter.com/kyleehmke/status/1305342438479933442
greenkeyllc-projects.com infopulsejobs.com -
unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/ … · otx.alienvault.com/pulse/5f18618ca64fbccf241e8746
digi.shanx.icu -
unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/ … · otx.alienvault.com/pulse/5f18618ca64fbccf241e8746
acrlee.com allsecpackupdater.com intelligent-finance.site kizlarsoroyur.com kopilkaorukov.com oudax.com rdmsi.com sharjatv.com tprs-servers.eu wwmal.com -
clearskysec.com/wp-content/uploads/2020/02/ClearSky-Fox… · otx.alienvault.com/pulse/5e498b13d1107f3801d4b0b0 · kc.mcafee.com/corporate/index?page=content&id=KB92581… · virustotal.com/gui/file/c6e71d457779d2802f78c7526a6526… · virustotal.com/gui/file/40ba95b54dc4cf0754efcfaeef3bbd…
95.211.104.253:2255 95.211.104.253:443 -
unit42.paloaltonetworks.com/unit42-oilrig-malware-campaign-updates-…
go0gIe.com googleupdate.download shalaghlagh.tk update-kernal.net upgradesystems.info yahoooooomail.com -
clearskysec.com/wp-content/uploads/2020/02/ClearSky-Fox… · otx.alienvault.com/pulse/5e498b13d1107f3801d4b0b0 · kc.mcafee.com/corporate/index?page=content&id=KB92581… · virustotal.com/gui/file/c6e71d457779d2802f78c7526a6526… · virustotal.com/gui/file/40ba95b54dc4cf0754efcfaeef3bbd…
185.32.178.176:80 93.177.75.180:80 95.211.104.253:80 95.211.210.55:80 95.211.213.168:80 95.211.213.177:80 95.211.215.225:80 -
twitter.com/kyleehmke/status/1227993245025738753
rimaga.com -
twitter.com/kyleehmke/status/1224546670576390145
scoorpion.com -
twitter.com/kyleehmke/status/1224193166393344002
lebanonbuilder.com -
twitter.com/GoCyberYourself/status/1224020878146654…
godoycrus.com wastedsituation.com -
twitter.com/kyleehmke/status/1222970186162155523
hr-westat.com westat-hr.com -
intezer.com/blog-new-iranian-campaign-tailored-to-u…
manygoodnews.com -
unit42.paloaltonetworks.com/xhunt-campaign-new-watering-hole-identi… · otx.alienvault.com/pulse/5e305bb0fdf782ede5a5405b
ffconnectivitycheck.com flowconnectivity.com -
twitter.com/ClearskySec/status/1209055280090288131
lcepos.com -
unit42.paloaltonetworks.com/xhunt-campaign-new-watering-hole-identi… · otx.alienvault.com/pulse/5e305bb0fdf782ede5a5405b
6google.com alforatsystem.com antivirus-update.top firewallsupports.com microsofte-update.com sakabota.com -
unit42.paloaltonetworks.com/xhunt-campaign-attacks-on-kuwait-shippi…
whatzapps.net -
docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD… · sec0wn.blogspot.com/2018/05/prb-backdoor-fully-loaded-power…
akamai-global.com linledin.net outl00k.net -
twitter.com/kyleehmke/status/1151944337598668801
fuktheme.com goosegoosecome.com hugebricks.com offturn.com -
fireeye.com/blog/threat-research/2019/07/hard-pass-… · otx.alienvault.com/pulse/5d3092fc4cd930e8cd6b1f76
domain cam-research-ac.com domain cdn-edge-akamai.com domain offlineearthquake.com url http://185.15.247.154 -
unit42.paloaltonetworks.com/xhunt-campaign-new-watering-hole-identi… · otx.alienvault.com/pulse/5e305bb0fdf782ede5a5405b
cloudipnameserver.com googie.email lowconnectivity.com -
unit42.paloaltonetworks.com/behind-the-scenes-with-oilrig · otx.alienvault.com/pulse/5cc8494e1a6c9c572567ba7f
msoffice-cdn.com office365-management.com -
otx.alienvault.com/pulse/5cb74e5ce1f7e4097ff06255 · misterch0c.blogspot.com/2019/04/apt34-oilrig-leak.html
myleftheart.com -
docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD… · fireeye.com/blog/threat-research/2017/12/targeted-a…
applicationframehost.in chrome-dns.com dnsupdateservers.net fireeyeupdate.com level3-resolvers.net microsoft-publisher.com miedafire.com mslicensecheck.com msoffice365update.com ntpupdateserver.com opendns-server.com outlookteam.live poison-frog.club ressume.site tatavpnservices.com -
docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
window5.win -
docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD… · unit42.paloaltonetworks.com/unit42-oilrig-malware-campaign-updates-…
winodwsupdates.me -
docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
nsn1.winodwsupdates.me -
docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
prosalar.com -
area1security.com/resources/operation-doos
barsupport.org forskys.com shoterup.com -
area1security.com/resources/operation-doos · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
coldflys.com -
researchcenter.paloaltonetworks.com/2018/09/unit42-oilrig-uses-updated-bond… · twitter.com/silv0123/status/1166399156853846017
withyourface.com -
researchcenter.paloaltonetworks.com/2018/07/unit42-oilrig-targets-technolog…
acrobatverify.com cpuproc.com rdppath.com -
docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD… · fireeye.com/blog/threat-research/2017/12/targeted-a…
anyportals.com dns-update.club hpserver.online mumbai-m.site proxycheker.pro -
twitter.com/ClearskySec/status/1026297541581664257
defender-update.com herkhabar.com windowspatch.com -
unit42.paloaltonetworks.com/xhunt-campaign-new-watering-hole-identi… · otx.alienvault.com/pulse/5e305bb0fdf782ede5a5405b
google-update.com
Further reading 115
- researchcenter.paloaltonetworks.com/2016/05/the-oilrig-campaign-attacks-on-…
- researchcenter.paloaltonetworks.com/2016/10/unit42-oilrig-malware-campaign-…
- researchcenter.paloaltonetworks.com/2017/04/unit42-oilrig-actors-provide-gl…
- clearskysec.com/oilrig
- attack.mitre.org/groups/G0049
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- pan-unit42.github.io/playbook_viewer
- pan-unit42.github.io/playbook_viewer/?pb=evasive-serpens
- research.checkpoint.com/2021/irans-apt34-returns-with-an-update…
- researchcenter.paloaltonetworks.com/2018/07/unit42-oilrig-targets-technolog…
- securityintelligence.com/posts/new-destructive-wiper-zerocleare-…
- crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the…
- fireeye.com/blog/threat-research/2017/12/targeted-a…
- proofpoint.com/us/corporate-blog/post/iranian-state-sp…
- secureworks.com/research/threat-profiles/cobalt-gypsy
- security.com/threat-intelligence/crambus-middle-east…
- trendmicro.com/en_us/research/24/j/earth-simnavaz-cybe…
- twitter.com/kyleehmke/status/1338907878455963648
- x.com/Cyber_O51NT/status/1834069690777301121
- virustotal.com/gui/file/0ee32e3ea3d83da9df6317d7c8c539…
- virustotal.com/gui/ip-address/37.1.213.152/relations
- virustotal.com/gui/file/dcdaa9da5ee4750b1084f7dd99faee…
- unit42.paloaltonetworks.com/xhunt-campaign-attacks-on-kuwait-shippi…
- blog.morphisec.com/microsoft-equation-editor-backdoor
- twitter.com/GoCyberYourself/status/1224020878146654…
- virustotal.com/gui/file/b69812221cd9328a70c90f771c58be…
- virustotal.com/gui/file/e0872958b8d3824089e5e1cfab03d9…
- virustotal.com/gui/file/40ba95b54dc4cf0754efcfaeef3bbd…
- twitter.com/kyleehmke/status/1305342438479933442
- docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
- research.checkpoint.com/2024/iranian-malware-attacks-iraqi-gove…
- twitter.com/kyleehmke/status/1339410533410369537
- virustotal.com/gui/file/c6e71d457779d2802f78c7526a6526…
- virustotal.com/gui/file/413cef6cf83ff649c15c60fff88819…
- otx.alienvault.com/pulse/5d3092fc4cd930e8cd6b1f76
- docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
- twitter.com/kyleehmke/status/1224546670576390145
- x.com/ThreatBookLabs/status/19066703111450913…
- virustotal.com/gui/file/cb00ee3f246a3d3af6ba4f97546a39…
- virustotal.com/gui/file/1388f124c6af24eefe5483a5a50ab1…
75 more, and the report behind every indicator, in G0049.json.