Overview 42 indicators
Bouncing Golf is a cyberespionage campaign targeting Middle Eastern countries.
| domain | 23 | G0097-domain.txt |
| url_path | 13 | G0097.json |
| url | 5 | G0097.json |
| ipv4 | 1 | G0097.json |
Techniques 1 ATT&CK
Open in ATT&CK Navigator → or download the layer (1 techniques, layer 4.5)
Software 1
Principal sources 21 reports
Ranked by how many of this actor's indicators each report brought in.
- 12twitter.com/felixaime/status/1353622368913133569
- 12twitter.com/malwrhunterteam/status/1753545424508440…
- 12virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed…
- 12virustotal.com/gui/ip-address/62.112.8.199/relations
- 12virustotal.com/gui/ip-address/62.112.8.244/relations
- 12virustotal.com/gui/ip-address/62.112.8.60/relations
- 12virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb…
- 12virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218…
Related groups 5
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 42 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/ThreatBookLabs/status/20032619204390913…
androidsecurityupdate.com androidsystemsupdate.com googleupdateservicese.com -
twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…
arzdigitals.com ns1.googleassisstants.com ns2.googleassisstants.com -
x.com/ThreatBookLabs/status/20032619204390913…
/farahv2.apk /negahdarigiahanv2.apk /ostadshajarianv5.apk -
twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…
/mmh/gt-func.php /mmh/lg-upld.php /mmh/on-answ.php -
twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…
/msd/gt-func.php /msd/lg-upld.php /msd/on-answ.php -
x.com/ThreatBookLabs/status/20032619204390913…
/sarayemaghale.apk -
welivesecurity.com/2022/10/20/domestic-kitten-campaign-spy…
sarayemaghale.hami24.net -
github.com/ti-research-io/ti/blob/main/ioc_extende…
googlextabv.com newportschoolupdateserver.com -
virustotal.com/gui/file/a7edd5586ac6cd64eaa1d3fd19077b…
padre914.com -
twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…
androidsystemswebview.com googleassisstants.com googleservicesforar.com -
research.checkpoint.com/domestic-kitten-an-iranian-surveillance… · twitter.com/malwrhunterteam/status/1340344596698677… · virustotal.com/gui/file/bd7779e6100e07b3eae67bfcdc53f1…
/hass/answer.php /hass/get-function.php /hass/upload-log.php -
blackberry.com/content/dam/blackberry-com/asset/enterp…
systemdriverupdate.com ydownyload.net ynewnow.net -
twitter.com/blackorbird/status/1181868468620017665 … · mp.weixin.qq.com/s/yaLC8gs-U92X6WnYzuuQ7w · otx.alienvault.com/pulse/5d9db01cc5328d4649e0594c
domain appsoftupdate.com domain lohefeshordeh.net domain ychatonline.net ipv4 198.50.220.44:80 url http://46.4.143.130 -
research.checkpoint.com/domestic-kitten-an-iranian-surveillance… · twitter.com/malwrhunterteam/status/1340344596698677… · virustotal.com/gui/file/bd7779e6100e07b3eae67bfcdc53f1…
domain firmwaresystemupdate.com domain georgethompson.space domain ronaldlubbers.site domain stevenwentz.com url http://162.248.247.172 url http://190.2.144.140 url http://190.2.145.145 url http://89.38.98.49
Further reading 23
- attack.mitre.org/groups/G0097
- blog.trendmicro.com/trendlabs-security-intelligence/mobile-…
- otx.alienvault.com/pulse/5d9db01cc5328d4649e0594c
- twitter.com/malwrhunterteam/status/1340344596698677…
- blackberry.com/content/dam/blackberry-com/asset/enterp…
- mp.weixin.qq.com/s/yaLC8gs-U92X6WnYzuuQ7w
- virustotal.com/gui/file/bd7779e6100e07b3eae67bfcdc53f1…
- virustotal.com/gui/ip-address/62.112.8.199/relations
- welivesecurity.com/2022/10/20/domestic-kitten-campaign-spy…
- virustotal.com/gui/ip-address/62.112.8.60/relations
- twitter.com/felixaime/status/1353622368913133569
- virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed…
- virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218…
- twitter.com/blackorbird/status/1181868468620017665 …
- virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f…
- twitter.com/malwrhunterteam/status/1753545424508440…
- virustotal.com/gui/file/a7edd5586ac6cd64eaa1d3fd19077b…
- research.checkpoint.com/domestic-kitten-an-iranian-surveillance…
- github.com/ti-research-io/ti/blob/main/ioc_extende…
- virustotal.com/gui/ip-address/62.112.8.244/relations
- x.com/ThreatBookLabs/status/20032619204390913…
- virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…
- virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb…