Overview 52 indicators
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.
| domain | 45 | G1001-domain.txt |
| ipv4 | 7 | G1001.json |
Techniques 36 ATT&CK
Open in ATT&CK Navigator → or download the layer (36 techniques, layer 4.5)
- T1010 Application Window Discovery
- T1016 System Network Configuration Discovery
- T1016.001 Internet Connection Discovery
- T1018 Remote System Discovery
- T1021.001 Remote Desktop Protocol
- T1027.010 Command Obfuscation
- T1033 System Owner/User Discovery
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1069.001 Local Groups
- T1082 System Information Discovery
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1110 Brute Force
- T1110.003 Password Spraying
- T1204.002 Malicious File
- T1518 Software Discovery
- T1534 Internal Spearphishing
- T1546.003 Windows Management Instrumentation Event Subscription
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1567.002 Exfiltration to Cloud Storage
- T1583.001 Domains
- T1583.002 DNS Server
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1586.002 Email Accounts
- T1588.002 Tool
- T1589 Gather Victim Identity Information
- T1589.002 Email Addresses
- T1591.004 Identify Roles
- T1608.001 Upload Malware
Software 12
Principal sources 45 reports
Ranked by how many of this actor's indicators each report brought in.
- 22vblocalhost.com/uploads/VB2021-Kayal-etal.pdf
- 10twitter.com/blackorbird/status/1166345000826724352
- 10secureworks.com/blog/lyceum-takes-center-stage-in-middl…
- 10otx.alienvault.com/pulse/5d656065aaa9ac9b19ef75c2
- 10twitter.com/Manu_De_Lucia/status/1208388233731678208
- 10medium.com/@Manu_De_Lucia/exploding-the-danbot-cod…
- 10virustotal.com/gui/file/11c52732d7fde12f5f4c6431f8be87…
- 9virustotal.com/gui/file/b668c7308223885f7875b02de2c924…
Related groups 6
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 52 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
twitter.com/RedDrip7/status/1564090684612952064 · virustotal.com/gui/file/1e6d7fa1c7a17d4bc9fc939132347e…
domain he-express-marketing.com ipv4 185.243.112.136:6501 -
clearskysec.com/wp-content/uploads/2022/06/Lyceum-suici… · otx.alienvault.com/pulse/62b598f4ee9576cd17e3ad87 · virustotal.com/gui/ip-address/89.39.149.19/relations
planet-informer.me -
twitter.com/sS55752750/status/1540353519974334467
89.39.149.18:3444 -
twitter.com/RedDrip7/status/1537389704374431744 · virustotal.com/gui/file/8883bbd14017d0946aefd2c6fbc7b2… · virustotal.com/gui/file/50e643e06c1fd6b334668439c1fb73…
89.39.149.18:6500 89.39.149.18:6501 -
research.checkpoint.com/2022/state-sponsored-attack-groups-capi… · zscaler.com/blogs/security-research/lyceum-net-dns-… · otx.alienvault.com/pulse/624c29baad734a210134b02c · otx.alienvault.com/pulse/6298718ccb0c8c00f0485af3 · virustotal.com/gui/ip-address/85.206.175.201/relations · virustotal.com/gui/file/0e06aa02a69b8efc5c38753849e325… · virustotal.com/gui/file/e8bb67e80203e1996c4098d8366799… · virustotal.com/gui/file/e3d375744e9e03c6248cc1c4770c57… · virustotal.com/gui/file/b668c7308223885f7875b02de2c924… · virustotal.com/gui/file/a9f9e5a30cc858dc135ec428cdd68c… · virustotal.com/gui/file/4d05bef5407ca33b133ff9ca7f1686… · virustotal.com/gui/file/431900772fde6905031b35077072d6… · virustotal.com/gui/file/10ac0884f1b53c3f42d97fd78b17af… · virustotal.com/gui/file/fcd1f79cec4de354b05cac1d606865… · virustotal.com/gui/file/a8829144273332032b5527e41a22cc… · virustotal.com/gui/file/91100c15dbd7ce47fc8598ef621181… · virustotal.com/gui/file/0a43911679e3ad25638d04d1f4b000… · virustotal.com/gui/file/029e41b95553b0d2e6254a52b78630…
85.206.175.199:53 -
research.checkpoint.com/2022/state-sponsored-attack-groups-capi… · zscaler.com/blogs/security-research/lyceum-net-dns-… · otx.alienvault.com/pulse/624c29baad734a210134b02c · otx.alienvault.com/pulse/6298718ccb0c8c00f0485af3 · virustotal.com/gui/ip-address/85.206.175.201/relations · virustotal.com/gui/file/0e06aa02a69b8efc5c38753849e325… · virustotal.com/gui/file/e8bb67e80203e1996c4098d8366799… · virustotal.com/gui/file/e3d375744e9e03c6248cc1c4770c57… · virustotal.com/gui/file/b668c7308223885f7875b02de2c924… · virustotal.com/gui/file/a9f9e5a30cc858dc135ec428cdd68c… · virustotal.com/gui/file/4d05bef5407ca33b133ff9ca7f1686… · virustotal.com/gui/file/431900772fde6905031b35077072d6… · virustotal.com/gui/file/10ac0884f1b53c3f42d97fd78b17af… · virustotal.com/gui/file/fcd1f79cec4de354b05cac1d606865… · virustotal.com/gui/file/a8829144273332032b5527e41a22cc… · virustotal.com/gui/file/91100c15dbd7ce47fc8598ef621181… · virustotal.com/gui/file/0a43911679e3ad25638d04d1f4b000… · virustotal.com/gui/file/029e41b95553b0d2e6254a52b78630…
main.download -
research.checkpoint.com/2022/state-sponsored-attack-groups-capi… · zscaler.com/blogs/security-research/lyceum-net-dns-… · otx.alienvault.com/pulse/624c29baad734a210134b02c · otx.alienvault.com/pulse/6298718ccb0c8c00f0485af3 · virustotal.com/gui/ip-address/85.206.175.201/relations · virustotal.com/gui/file/0e06aa02a69b8efc5c38753849e325… · virustotal.com/gui/file/e8bb67e80203e1996c4098d8366799… · virustotal.com/gui/file/e3d375744e9e03c6248cc1c4770c57… · virustotal.com/gui/file/b668c7308223885f7875b02de2c924… · virustotal.com/gui/file/a9f9e5a30cc858dc135ec428cdd68c… · virustotal.com/gui/file/4d05bef5407ca33b133ff9ca7f1686… · virustotal.com/gui/file/431900772fde6905031b35077072d6… · virustotal.com/gui/file/10ac0884f1b53c3f42d97fd78b17af… · virustotal.com/gui/file/fcd1f79cec4de354b05cac1d606865… · virustotal.com/gui/file/a8829144273332032b5527e41a22cc… · virustotal.com/gui/file/91100c15dbd7ce47fc8598ef621181… · virustotal.com/gui/file/0a43911679e3ad25638d04d1f4b000… · virustotal.com/gui/file/029e41b95553b0d2e6254a52b78630…
domain news-reporter.xyz domain news-spot.live domain news-spot.xyz ipv4 185.243.112.136:5512 -
twitter.com/k3yp0d/status/1503756002738515969 · virustotal.com/gui/file/b668c7308223885f7875b02de2c924… · research.checkpoint.com/2022/state-sponsored-attack-groups-capi… · zscaler.com/blogs/security-research/lyceum-net-dns-… · otx.alienvault.com/pulse/624c29baad734a210134b02c · otx.alienvault.com/pulse/6298718ccb0c8c00f0485af3 · virustotal.com/gui/ip-address/85.206.175.201/relations · virustotal.com/gui/file/0e06aa02a69b8efc5c38753849e325… · virustotal.com/gui/file/e8bb67e80203e1996c4098d8366799… · virustotal.com/gui/file/e3d375744e9e03c6248cc1c4770c57… · virustotal.com/gui/file/a9f9e5a30cc858dc135ec428cdd68c… · virustotal.com/gui/file/4d05bef5407ca33b133ff9ca7f1686… · virustotal.com/gui/file/431900772fde6905031b35077072d6… · virustotal.com/gui/file/10ac0884f1b53c3f42d97fd78b17af… · virustotal.com/gui/file/fcd1f79cec4de354b05cac1d606865… · virustotal.com/gui/file/a8829144273332032b5527e41a22cc… · virustotal.com/gui/file/91100c15dbd7ce47fc8598ef621181… · virustotal.com/gui/file/0a43911679e3ad25638d04d1f4b000… · virustotal.com/gui/file/029e41b95553b0d2e6254a52b78630…
104.249.26.60:5512 -
twitter.com/k3yp0d/status/1503756002738515969 · virustotal.com/gui/file/b668c7308223885f7875b02de2c924…
science-news.live -
twitter.com/fr0s7_/status/1503678175284449288 · virustotal.com/gui/file/5f0e0f0abc28ccc1911533fd035e98… · research.checkpoint.com/2022/state-sponsored-attack-groups-capi… · zscaler.com/blogs/security-research/lyceum-net-dns-… · otx.alienvault.com/pulse/624c29baad734a210134b02c · otx.alienvault.com/pulse/6298718ccb0c8c00f0485af3 · virustotal.com/gui/ip-address/85.206.175.201/relations · virustotal.com/gui/file/0e06aa02a69b8efc5c38753849e325… · virustotal.com/gui/file/e8bb67e80203e1996c4098d8366799… · virustotal.com/gui/file/e3d375744e9e03c6248cc1c4770c57… · virustotal.com/gui/file/b668c7308223885f7875b02de2c924… · virustotal.com/gui/file/a9f9e5a30cc858dc135ec428cdd68c… · virustotal.com/gui/file/4d05bef5407ca33b133ff9ca7f1686… · virustotal.com/gui/file/431900772fde6905031b35077072d6… · virustotal.com/gui/file/10ac0884f1b53c3f42d97fd78b17af… · virustotal.com/gui/file/fcd1f79cec4de354b05cac1d606865… · virustotal.com/gui/file/a8829144273332032b5527e41a22cc… · virustotal.com/gui/file/91100c15dbd7ce47fc8598ef621181… · virustotal.com/gui/file/0a43911679e3ad25638d04d1f4b000… · virustotal.com/gui/file/029e41b95553b0d2e6254a52b78630…
cyberclub.one -
clearskysec.com/wp-content/uploads/2021/08/Siamesekitte… · otx.alienvault.com/pulse/611cebb137fe5c6475b044f5
defenderstatus.com jobschippc.com softwareagjobs.com zonestatistic.com -
vblocalhost.com/uploads/VB2021-Kayal-etal.pdf
centosupdatecdn.com cloudmsn.net defenderlive.com digitalmarketingnews.net dmgagency.net dnscatalog.net dnscdn.org dnsstatus.org hpesystem.com livecdn.com mastertape.org microsftonline.net msnnews.org onlineoutlook.net securednsservice.net sysadminnews.info uctpostgraduate.com updatecdn.net webmaster-team.com windowsupdatecdn.com wsuslink.com -
vblocalhost.com/uploads/VB2021-Kayal-etal.pdf
akastatus.com -
twitter.com/h2jazi/status/1372543666909220873 · virustotal.com/gui/file/8bd23bbab513e03ea1eb2adae09f56… · virustotal.com/gui/file/4e70df688e8d824008cc08e1d05f84… · virustotal.com/gui/file/9ed939f56eb04fb40c9a0ce6f3a4fe… · virustotal.com/gui/file/9eca74b1fef65ac41d28f7ada626ee… · virustotal.com/gui/file/a02db59312f14aa8208c462e0e5b3d…
stgeorgebankers.com -
twitter.com/blackorbird/status/1166345000826724352 · secureworks.com/blog/lyceum-takes-center-stage-in-middl… · otx.alienvault.com/pulse/5d656065aaa9ac9b19ef75c2 · twitter.com/Manu_De_Lucia/status/1208388233731678208 · medium.com/@Manu_De_Lucia/exploding-the-danbot-cod… · virustotal.com/gui/file/11c52732d7fde12f5f4c6431f8be87…
bsolutions-cloude.com cybersecnet.co.za cybersecnet.org dnscachecloud.com dnscloudservice.com excsrvcdn.com online-analytic.com opendnscloud.com web-statistics.info web-traffic.info
Further reading 49
- attack.mitre.org/groups/G1001
- dragos.com/resource/hexane
- vblocalhost.com/uploads/VB2021-Kayal-etal.pdf
- accenture.com/us-en/blogs/cyber-defense/iran-based-ly…
- clearskysec.com/siamesekitten
- secureworks.com/blog/lyceum-takes-center-stage-in-middl…
- virustotal.com/gui/file/a02db59312f14aa8208c462e0e5b3d…
- otx.alienvault.com/pulse/5d656065aaa9ac9b19ef75c2
- zscaler.com/blogs/security-research/lyceum-net-dns-…
- virustotal.com/gui/file/029e41b95553b0d2e6254a52b78630…
- virustotal.com/gui/file/5f0e0f0abc28ccc1911533fd035e98…
- virustotal.com/gui/file/8bd23bbab513e03ea1eb2adae09f56…
- research.checkpoint.com/2022/state-sponsored-attack-groups-capi…
- clearskysec.com/wp-content/uploads/2021/08/Siamesekitte…
- virustotal.com/gui/file/9ed939f56eb04fb40c9a0ce6f3a4fe…
- virustotal.com/gui/file/b668c7308223885f7875b02de2c924…
- virustotal.com/gui/file/0e06aa02a69b8efc5c38753849e325…
- virustotal.com/gui/file/50e643e06c1fd6b334668439c1fb73…
- virustotal.com/gui/file/e3d375744e9e03c6248cc1c4770c57…
- medium.com/@Manu_De_Lucia/exploding-the-danbot-cod…
- otx.alienvault.com/pulse/624c29baad734a210134b02c
- virustotal.com/gui/file/431900772fde6905031b35077072d6…
- virustotal.com/gui/file/1e6d7fa1c7a17d4bc9fc939132347e…
- twitter.com/fr0s7_/status/1503678175284449288
- virustotal.com/gui/ip-address/85.206.175.201/relations
- twitter.com/sS55752750/status/1540353519974334467
- virustotal.com/gui/file/a8829144273332032b5527e41a22cc…
- otx.alienvault.com/pulse/62b598f4ee9576cd17e3ad87
- virustotal.com/gui/file/10ac0884f1b53c3f42d97fd78b17af…
- virustotal.com/gui/file/4d05bef5407ca33b133ff9ca7f1686…
- otx.alienvault.com/pulse/611cebb137fe5c6475b044f5
- twitter.com/blackorbird/status/1166345000826724352
- clearskysec.com/wp-content/uploads/2022/06/Lyceum-suici…
- virustotal.com/gui/file/4e70df688e8d824008cc08e1d05f84…
- virustotal.com/gui/file/fcd1f79cec4de354b05cac1d606865…
- virustotal.com/gui/file/8883bbd14017d0946aefd2c6fbc7b2…
- twitter.com/RedDrip7/status/1537389704374431744
- virustotal.com/gui/file/a9f9e5a30cc858dc135ec428cdd68c…
- twitter.com/RedDrip7/status/1564090684612952064
- twitter.com/Manu_De_Lucia/status/1208388233731678208
9 more, and the report behind every indicator, in G1001.json.