Overview 68 indicators
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.
| domain | 68 | G0079-domain.txt |
Techniques 7 ATT&CK
Open in ATT&CK Navigator → or download the layer (7 techniques, layer 4.5)
- T1059.001 PowerShell
- T1187 Forced Authentication
- T1204.002 Malicious File
- T1221 Template Injection
- T1564.003 Hidden Window
- T1566.001 Spearphishing Attachment
- T1588.002 Tool
Software 3
Principal sources 6 reports
Ranked by how many of this actor's indicators each report brought in.
- 64docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
- 42unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can…
- 22researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-d…
- 2virustotal.com/gui/file/f81a5f0f97eb9782e425f1fde19a40…
- 2virustotal.com/gui/file/270ec2945fb976823e46d6fbb346fa…
- 2virustotal.com/gui/ip-address/108.177.235.92/relations
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 68 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
virustotal.com/gui/file/f81a5f0f97eb9782e425f1fde19a40… · virustotal.com/gui/file/270ec2945fb976823e46d6fbb346fa…
asisdns.space asismdnu.asisdns.space -
unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can… · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
akadns.services cloudfronts.services trafficmanager.live -
virustotal.com/gui/ip-address/108.177.235.92/relations
microsoftonline.host microsoftonline.services -
unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can… · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
ns1.microsoftlab.ir ns102.kaspersky.host ns103.kaspersky.host ns2.microsoftlab.ir -
researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-d… · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
0utlook.accountant citriix.net microsoftlab.ir msdnscripts.com -
unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can… · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
0ffice365.agency 0ffice365.life 0ffice365.services 0nedrive.agency akamai.agency akamaiedge.live akamaiedge.services akamaized.live akdns.live asimov-win-microsoft.services azureedge.today brit.ns.cloudfronts.services britns.akadns.live britns.akadns.services corewindows.agency data-microsoft.services dns.cloudfronts.services edgekey.live gogle.co iecvlist-microsoft.live microsoftonline.agency ns2.akadns.live ns2.akadns.services nsatc.agency onecs-live.services onedrive.agency phicdn.world sharepoint.agency skydrive.agency skydrive.services t-msedge.world tbs1.microsoftonline.services tbs2.microsoftonline.services tvs1.trafficmanager.live tvs2.trafficmanager.live -
researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-d… · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
0ffice.com 0ffiice.com 0utl00k.net 0utlook.bid allexa.net anyconnect.stream bigip.stream cisc0.net fortiweb.download kaspersky.host kaspersky.science maccaffe.com microtik.stream micrrosoft.net msdncss.com owa365.bid symanteclive.download windowsdefender.win
Further reading 8
- attack.mitre.org/groups/G0079
- pan-unit42.github.io/playbook_viewer
- researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-d…
- virustotal.com/gui/file/f81a5f0f97eb9782e425f1fde19a40…
- docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
- virustotal.com/gui/ip-address/108.177.235.92/relations
- unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can…
- virustotal.com/gui/file/270ec2945fb976823e46d6fbb346fa…