← All actors Recent activity

BITTER G1002

BITTER · AlmondRAT · BDarkRAT · Hazy Tiger · KugelBlitz · MiyaRAT · MuuyDownloader · ORPCBackdoor · Orange Yali · WSCSPL · apt-c-08 · apt-k-47 · apt-q-37 · apt-q-41 · artradownloader · asyncshell · chmghost · kiwistealer · manlinghua · mysterious elephant · splinter · stomexfiltrator · ta397 · turtlepower · ung0002

Indicators
670
Source reports
586
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-06-26
20182026

Overview 670 indicators

BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.

domain466G1002-domain.txt
url_path102G1002.json
ipv478G1002.json
url24G1002.json

Techniques 17 ATT&CK

Open in ATT&CK Navigator → or download the layer (17 techniques, layer 4.5)

Software 1

Principal sources 586 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 670 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

Showing the 300 most recent of 670. Complete: G1002.json.

  1. 1 domainthis year

    x.com/nextronresearch/status/2070473326372291… · virustotal.com/gui/file/d0ee008d3c480d5f9f75332851ae94…

    ultraflavors.com

  2. 1 domain, 1 ipv4this year

    x.com/blackorbird/status/2064727597435752846 · mp.weixin.qq.com/s/jH60_sYtZjJZWtVc5d277g

    domaindownloadclouddata.com
    ipv4163.245.220.108:8442

  3. 2 domainthis year

    x.com/blackorbird/status/2051892318203175106

    fswhardtools.com
    vpn146318720.softether.net

  4. 3 domain, 2 ipv4, 1 urlthis year

    x.com/RexorVc0/status/2049740014875967766 · mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508516…

    domaindomainnamevalidator.com
    domaindomainregistationcheck.com
    domaingetserviceupdates.com
    ipv4151.236.4.164:5010
    ipv489.46.236.152:443
    urlhttp://46.30.191.221

  5. 1 domainthis year

    x.com/RedDrip7/status/2049775100237676647 · virustotal.com/gui/file/359200a112936939f8b324bee7edc9… · virustotal.com/gui/file/c151a8861d4f75c09803efa6773221… · virustotal.com/gui/file/84f2b3cde61895fbe28c3660d5f8d7…

    bravojacksonmentor.com

  6. 1 domain, 1 url_paththis year

    x.com/RedDrip7/status/2047579562184413587 · virustotal.com/gui/file/563fd6ff3f767d8120731803aeec9e… · virustotal.com/gui/file/85fae6eb3d173274e59293d31d48c1…

    domaingrandinaspectrum.com
    url_path/hgdtfjgtyf.php

  7. 1 domainthis year

    x.com/smica83/status/2044417422606655769 · virustotal.com/gui/file/6fd40f0aba5c6bd9dd784abd8f5c0e…

    invstampvest.com

  8. 1 domainthis year

    x.com/volrant136/status/2041159217374244990 · virustotal.com/gui/file/0b6d4f7a545e6fc1bfc907f76e9291…

    commonlifesupport.com

  9. 1 ipv4this year

    x.com/RedDrip7/status/2038827595018727498 · virustotal.com/gui/file/7ea0930a332788c2e88e5822e4908d… · virustotal.com/gui/file/9fb6f4c55e5198739123264f8007cf…

    188.214.33.170:443

  10. 1 domain, 1 url_paththis year

    x.com/RedDrip7/status/2037368885876564464 · virustotal.com/gui/file/bbe94912c0dd4b812decf9d4e8a81d…

    domainhaburyohoteam.com
    url_path/jvdmhawme.okjhvthfv

  11. 1 domainthis year

    x.com/RedDrip7/status/2037368638605570409 · virustotal.com/gui/file/c967e7d3c8227e209537257bfe21a6…

    caravelcruiser.com

  12. 2 domainthis year

    x.com/RedDrip7/status/2031616083569029525 · virustotal.com/gui/file/fb91c7fd342803ae581ea52e78bc61…

    99media.com.pk
    zoemagicbook.com

  13. 1 domain, 1 ipv4this year

    x.com/RedDrip7/status/2027209484784017629 · virustotal.com/gui/file/e6b523e77c31b89f8eb3489007bf14…

    domainashersoftlib.com
    ipv4107.172.39.100:44908

  14. 1 domainthis year

    x.com/skocherhan/status/2024194564605579358 · virustotal.com/gui/file/4885affbac1695037c5fbfc000ff54… · virustotal.com/gui/file/5a98b05cff064c3884c689e4f4fb99…

    officesignature.info

  15. 1 domainthis year

    strikeready.com/blog/open-sesame · virustotal.com/gui/ip-address/172.86.68.175/relations · virustotal.com/gui/file/15337ad45a65f8f9eae57f76d6cff3… · virustotal.com/gui/file/ba352569428df4618cd57f91bd3479… · virustotal.com/gui/file/ee088e6d8ac0f3dbfbd17f556a58d0… · virustotal.com/gui/file/52a4020392de0d527fe0aaf551fa55…

    nelavohomet.com

  16. 2 domain, 2 url_paththis year

    x.com/RedDrip7/status/2019243120131805198 · virustotal.com/gui/file/941011523ce613d6729e83febc1de7… · virustotal.com/gui/file/28b586cf4f84eeb6ced3e5b40451e0…

    domainpinkrosesandmore.com
    domainprolukemarion.com
    url_path/ceszvd.php
    url_path/vbdfsbad.php

  17. 1 ipv4this year

    x.com/RedDrip7/status/2016415763633242298 · virustotal.com/gui/file/836c8fb1ff998d3b94b4800aca7b17…

    134.255.210.127:443

  18. 1 domainthis year

    x.com/RedDrip7/status/2014542257488306575 · virustotal.com/gui/file/6d92924ff3a1de18fe715c2e7432ee… · virustotal.com/gui/file/d597c488b73cde0938b464f93ed9ee…

    crudestopics.com

  19. 1 domain, 1 url_paththis year

    x.com/RedDrip7/status/2011023732341686629 · virustotal.com/gui/file/8753006b62b74c6805e6cb22e149a4…

    domainbroadsforthestate.com
    url_path/jdfgwe.php

  20. 2 ipv4this year

    x.com/RedDrip7/status/2009443295127326763 · virustotal.com/gui/file/deb241a46da181c8c1f68a43745fcb… · virustotal.com/gui/file/dfedb0033337aaa8570ef682a93119…

    185.193.50.233:443
    83.243.121.87:443

  21. or earlier 10 domain, 2 ipv4this year

    x.com/ThreatrayLabs/status/1986432637762732515 · virustotal.com/gui/ip-address/103.57.251.154/relations · virustotal.com/gui/file/090b1691a623cc6e8d956ed41ab3ef… · virustotal.com/gui/file/0ca1ce61d917771ed344f8345a8161…

    domainjmxdnqr8.mediumblog.online
    domainmanage.mediumblog.online
    domainmediumblog.online
    domainqdey4uvj.mediumblog.online
    domainrgevzuir.mediumblog.online
    domainservices.windowmediaplayer.media
    domainunr0wddj.mediumblog.online
    domainvzgmbwva.mediumblog.online
    domainwindowmediaplayer.media
    domainyorkstar.mediumblog.online
    ipv4103.57.251.154:4443
    ipv4192.71.213.128:4431

  22. or earlier 11 domainthis year

    x.com/volrant136/status/1923686317252075887

    alvesbarcelona.com
    app.chabaka.com
    balkanclan.com
    chabaka.com
    com-ae.net
    drogbachelsea.com
    mail.alvesbarcelona.com
    mail.com-ae.net
    mail.drogbachelsea.com
    mail.youtubepremiumapp.com
    opfor.balkanclan.com

  23. or earlier 6 domain, 4 url_paththis year

    x.com/RedDrip7/status/1976924908736405560 · x.com/RedDrip7/status/1976923481377063382 · virustotal.com/gui/ip-address/78.110.166.82/relations · virustotal.com/gui/file/bb67a4de756336d45ebaa7657a7586… · virustotal.com/gui/file/f7e25e5601fdf038aa0840be508cf1…

    domain365cloudz.esanojinjasvc.com
    domaineliteteam.esanojinjasvc.com
    domainesanojinjasvc.com
    domainmsoffice.365cloudz.esanojinjasvc.com
    domainsupportteaminterface.esanojinjasvc.com
    domainteamlogin.esanojinjasvc.com
    url_path/cloudzx/msweb/drdxcsv34.php
    url_path/cloudzx/msweb/drxbds23.php
    url_path/cloudzx/msweb/drxcvg45.php
    url_path/teamesano/drivers/teamzid.php

  24. or earlier 4 domain, 3 ipv4this year

    x.com/malwrhunterteam/status/1929906003258048… · x.com/BaoshengbinCumt/status/1946009959831126… · seqrite.com/blog/ung0002-espionage-campaigns-south-… · virustotal.com/gui/file/4ca4f673e4389a352854f5feb0793d…

    domainecoglide.site
    domainmarine-research.space
    domainpentree.online
    domainskyfare.site
    ipv4162.0.216.229:21443
    ipv4162.0.216.229:8888
    ipv4209.74.80.194:7699

  25. or earlier 6 domain, 1 urlthis year

    x.com/frdfzi/status/1930495401456533564 · proofpoint.com/us/blog/threat-insight/bitter-end-unrav… · threatray.com/blog/the-bitter-end-unraveling-eight-ye…

    domainblucollinsoutien.com
    domainheadntale.com
    domaintrkswqsservice.com
    domainutizviewstation.com
    domainwarsanservices.com
    domainwoodstocktutors.com
    urlhttp://46.229.55.63

  26. or earlier 4 domain, 2 url_paththis year

    x.com/WhichbufferArda/status/1921506670343061… · tria.ge/250511-kptycahm6s/behavioral1 · virustotal.com/gui/file/15db9daa175d506c3e1eaee339eecd… · virustotal.com/gui/file/edb68223db3e583f9a4dd52fd91867…

    domainfogomyart.com
    domaingreenadelhouse.com
    domainmaximasigns.greenadelhouse.com
    domaintradesmarkets.greenadelhouse.com
    url_path/crvtyfgvwicidnex.php
    url_path/excerorderslistoncbook.php

  27. or earlier 3 domain, 2 ipv4this year

    x.com/RedDrip7/status/1978366720432562372 · virustotal.com/gui/file/9b21e4b32e3e125bad638df76f25ca… · virustotal.com/gui/file/d6a533102f801066ddd6069e20f3a5…

    domainbootcampquest.com
    domainmail.bootcampquest.com
    domaintools.bootcampquest.com
    ipv4194.110.246.254:443
    ipv483.172.134.186:443

  28. or earlier 4 domainthis year

    x.com/RedDrip7/status/1962415190051573781 · x.com/blackorbird/status/1981958007958524023 · virustotal.com/gui/file/1e7ce7c530a1cf4d74a356592f99bd… · virustotal.com/gui/file/66eff3058760b478aa70b44b929ca5… · virustotal.com/gui/file/b6bd48fa94fa15cdcbd6b24198472f… · virustotal.com/gui/file/7b801221a024507ff948261bf5b635… · virustotal.com/gui/file/08674b806c13a1dab0964548302170…

    carlminiclub.com
    keeferbeautytrends.com
    microsoft365.sangellobrighthouse.com
    sangellobrighthouse.com

  29. or earlier 1 domain, 2 url_paththis year

    x.com/volrant136/status/1956393083949502767 · virustotal.com/gui/file/6f0bc10f8326b462e02cf97f4aac1e…

    domainnsipsvc.com
    url_path/edgevrisinze.php
    url_path/imacnags/edgevrisinze.php

  30. or earlier 1 domain, 2 ipv4this year

    x.com/liqingjia1989/status/1930584300224676024 · virustotal.com/gui/file/a76f00ea65cf7fb9327e9b6d2d4aca…

    domaininspurcloudservice.com
    ipv489.46.234.221:443
    ipv489.46.234.221:9672

  31. or earlier 3 domainthis year

    x.com/RedDrip7/status/2004026276294938903 · virustotal.com/gui/file/974abd4dc03bd9dc1a5d7ae56d2882… · virustotal.com/gui/file/8c95b0d740df0f91444d5ddb9107f3… · virustotal.com/gui/file/c93e0f954cfcfafbb07cc248fab316…

    florabrocuisine.com
    joelgardens.com
    oscarskatingcoach.com

  32. or earlier 1 domain, 1 url_paththis year

    x.com/suyog41/status/1924329354504634767 · virustotal.com/gui/file/d02fd3472adb0d7a502b08656c5001…

    domainjgmfducservice.net
    url_path/jmv/jmd.php?st=

  33. or earlier 2 domainthis year

    x.com/smica83/status/1983935993209069584 · tria.ge/251030-t3ev1s1khn/behavioral1 · virustotal.com/gui/ip-address/146.70.118.226/relations · virustotal.com/gui/file/8b57d6b676afdd84786655eb5fc876…

    large-file-download-in-progress-page-loading-iuwt6sk34bs6543df.tartaakademi.com
    tartaakademi.com

  34. or earlier 1 url, 1 url_paththis year

    x.com/malwrhunterteam/status/1925086462120165… · virustotal.com/gui/file/ea73818d5c96294381ea56af0bdda9…

    urlhttp://196.251.84.150
    url_path/v10.066/egrf.php

  35. or earlier 1 url, 1 url_paththis year

    x.com/ginkgo_g/status/1897192606196703668 · virustotal.com/gui/file/8958b215f30f9d48010fb93363125d… · virustotal.com/gui/file/7847a287472f7e2b688bd5d000f435…

    urlhttp://149.154.153.184
    url_path/loccs.php?cn=

  36. or earlier 1 domain, 1 ipv4this year

    x.com/blackorbird/status/1958836180587307479 · mp.weixin.qq.com/s/ItcbKuoH0KjJjzSTG7YSrA · virustotal.com/gui/file/a850a903b74c1d3d21c41e03761e8e…

    domainpololiberty.com
    ipv4185.237.166.24:56218

  37. or earlier 1 domain, 1 ipv4this year

    x.com/__0XYC__/status/1930552371530129610 · x.com/__0XYC__/status/1930552424353202399 · virustotal.com/gui/file/5bdbec839592af17a725c5705201d3… · virustotal.com/gui/file/fbab7758765265a6988e78779cae2e…

    domaindiginurworld.com
    ipv4151.236.21.48:8080

  38. or earlier 2 url_paththis year

    x.com/StrikeReadyLabs/status/1846000315566375… · x.com/ginkgo_g/status/1933364194998694198 · virustotal.com/gui/file/ae8d252986c616884c10ab5082088c… · virustotal.com/gui/file/939f509a8edc6b9da103fbcebe8563… · virustotal.com/gui/file/8af2d392181c359ce04e38ab113e22…

    /cndrll.php
    /cndrll.php?er=

  39. or earlier 2 domainthis year

    x.com/RedDrip7/status/1998638735358128307 · virustotal.com/gui/file/1f262d5838e29f56eb190100f0753f… · virustotal.com/gui/file/1854e0e0a59a82e4d9629dd54a506e… · virustotal.com/gui/file/ffea43ead04d4bda567b1fd32ec68c…

    andrewswebstorage.com
    sanolegazy.com

  40. or earlier 1 domain, 1 ipv4this year

    x.com/RedDrip7/status/1993874904710828150 · virustotal.com/gui/file/258918e48a7aaf393af89858f95af6…

    domainhannahsgpsapp.com
    ipv4185.117.72.87:10923

  41. or earlier 2 ipv4this year

    x.com/RedDrip7/status/1964874030869332252

    151.236.14.173:443
    185.76.79.30:443

  42. or earlier 1 domain, 1 url_paththis year

    x.com/AndreGironda/status/1955692280825962846 · blog.pulsedive.com/unpacking-kiwistealer-diving-into-bitte… · app.any.run/tasks/a755b624-d146-4a49-acd5-c25e6b07a…

    domainebeninstallsvc.com
    url_path/uplh4ppy.php

  43. or earlier 1 domainthis year

    x.com/wa1Ile/status/1925447893743542391 · virustotal.com/gui/file/64fd1e641731e48ea8c3df7b9caa5f…

    inizdesignstudio.com

  44. or earlier 1 domainthis year

    x.com/volrant136/status/1941557096933359638

    oakcreekbakers.com

  45. or earlier 1 domainthis year

    x.com/volrant136/status/1930659807440039970 · virustotal.com/gui/ip-address/69.61.36.186/relations

    goldenaturalinc.com

  46. or earlier 1 domainthis year

    x.com/volrant136/status/1924126261514833963

    parcaredrive.com

  47. or earlier 1 domainthis year

    x.com/suyog41/status/1963171056044109898 · virustotal.com/gui/file/624decbc0445e51873436e42699323…

    seragoonupdates.com

  48. or earlier 1 domainthis year

    x.com/suyog41/status/1952990924210094369 · virustotal.com/gui/file/121c3917e7b2e00d7c6e15f09370d2…

    koliwooclients.com

  49. or earlier 1 domainthis year

    x.com/suyog41/status/1952709606297227414 · virustotal.com/gui/file/891ffe498debc7accfbdf9146adb6d…

    ccltdcn.org

  50. or earlier 1 domainthis year

    x.com/suyog41/status/1929855753206083762 · virustotal.com/gui/file/6763fadbfbcf125a73cc6388aba075…

    plymouthvibes.com

  51. or earlier 1 domainthis year

    x.com/suyog41/status/1922608403454583215 · virustotal.com/gui/file/31214e97722f99666dde6b09f386e7…

    princecleanit.com

  52. or earlier 1 domainthis year

    x.com/malwrhunterteam/status/2002470001924813… · virustotal.com/gui/file/f692ba8fbe76ee5488fd81ad3ae668…

    stellacustomscreens.com

  53. or earlier 1 domainthis year

    x.com/malwrhunterteam/status/1994001214795862… · virustotal.com/gui/file/09647fabb086acf09fdc72f3e8703c…

    pawsandtailcare.com

  54. or earlier 1 domainthis year

    x.com/malwrhunterteam/status/1923660512920744… · virustotal.com/gui/file/243e4d1e53a805f61d2c4e8cabdd02…

    ntplugnplay.com

  55. or earlier 1 domainthis year

    x.com/blackorbird/status/1986747686050287997 · mp.weixin.qq.com/s/CI1g4iaYxHhO925V15LvIQ · virustotal.com/gui/file/93a905048ca8cdf7162ade1720d508…

    tapeqcqoptions.com

  56. or earlier 1 ipv4this year

    x.com/RedDrip7/status/2001489642072482032 · virustotal.com/gui/file/1fd8ba64a687247466fa6e8b7d1941… · virustotal.com/gui/file/71fa6a00314701fef5c6f32c17e143… · virustotal.com/gui/file/974626cf14864f0a3185233bbce417…

    46.30.191.221:443

  57. or earlier 1 domainthis year

    x.com/RedDrip7/status/1952922656220823798 · virustotal.com/gui/file/389883cfa666855750974c540299de… · virustotal.com/gui/file/886c36f4625f98537e8f2df5975aab…

    glamormusicwave.com

  58. or earlier 1 url_paththis year

    twitter.com/binlmmhc/status/1610969202722242561 · x.com/ShanHolo/status/1971249000985788673

    /cmpn/xing.php

  59. 4 ipv4, 2 url_path1 yr ago

    x.com/SethKingHi/status/1876845124488941942 · virustotal.com/gui/file/d94ff0edb28f7b90b9e4ab9ee94e8d… · virustotal.com/gui/file/b1efa4e3abadfab14aba6e36ed9f41… · virustotal.com/gui/file/1126916c98b7801175375827fb5e8b…

    ipv4158.255.215.45:8899
    ipv4185.193.48.135:8676
    ipv4194.71.227.222:8855
    ipv491.103.66.202:46882
    url_path/anotherLife?credPart=
    url_path/nina/anotherLife?credPart=

  60. 1 url2 yrs ago

    x.com/banthisguy9349/status/18671791048998546… · x.com/banthisguy9349/status/18674586255325064… · virustotal.com/gui/file/acfb3223d5bcbcf96ee1265fdd510c… · virustotal.com/gui/file/a152fa2e7368ed357a91214fdd91e1…

    http://72.18.215.1

  61. 1 url, 2 url_path2 yrs ago

    x.com/StrikeReadyLabs/status/1865140931953070… · x.com/mal_analysis136/status/1865323680344969… · virustotal.com/gui/file/14ce282ffeaa5cc3d214acae337857…

    urlhttp://37.1.214.196
    url_path/zserr.php
    url_path/zserr.php?li=

  62. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1864408026658041… · virustotal.com/gui/file/65419a704f252f8c3574d90cf016b6…

    grounpackcluepik.com

  63. 2 domain2 yrs ago

    x.com/suyog41/status/1864199979369447473 · x.com/mal_analysis136/status/1864285903058809… · virustotal.com/gui/ip-address/185.244.151.84/relations · virustotal.com/gui/file/cb4a280f54c56d250c98124a88e80c…

    jacknwoods.com
    premierinvestmentfund.com

  64. 2 url2 yrs ago

    x.com/blackorbird/status/1862131045883408582 · virustotal.com/gui/file/e44d034ceb135990452fce74d358bd…

    http://159.100.30.103
    http://173.254.204.72

  65. 1 domain, 1 url_path2 yrs ago

    x.com/StrikeReadyLabs/status/1861383328521207… · x.com/mal_analysis136/status/1863537157119299… · virustotal.com/gui/file/b3b2d915f47aa631cc4900ec56f9b8…

    domainsiasat.top
    url_path/xyzxyzhanoiwhb3237gb2wahabjiki/

  66. 1 domain2 yrs ago

    x.com/blackorbird/status/1859161598469836806 · blogs.blackberry.com/en/2024/11/suspected-nation-state-adver… · virustotal.com/gui/collection/f6f862c588961ae94c5c23d9… · virustotal.com/gui/file/fc39ec35d767a2c0a178ca9874be8a… · virustotal.com/gui/file/a0a18e76d8af39b9b198d9ea7c67dc…

    updateschedulers.com

  67. 4 domain2 yrs ago

    x.com/blackorbird/status/1858873110625243398

    dappscryp.com
    ghayoorfilmstudio.com
    haileemecacademy.com
    zensparkagent.com

  68. 1 domain2 yrs ago

    x.com/wa1Ile/status/1858421539286168058 · virustotal.com/gui/file/c00570eb0b47614b7286cf945b2127…

    abelewebconnect.com

  69. 1 domain, 2 ipv42 yrs ago

    x.com/StrikeReadyLabs/status/1856371787145130… · medium.com/@knownsec404team/unveiling-the-past-and… · virustotal.com/gui/file/52362a3bf05d0f65c49d527bfecec7… · virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41… · virustotal.com/gui/file/cb7e6640ab5c1dad5083e5790d6009…

    domainfederalrevenueboard.com
    ipv4162.252.175.131:6969
    ipv491.132.92.231:9314

  70. 2 domain2 yrs ago

    x.com/blackorbird/status/1856340219328639441 · virustotal.com/gui/file/08d12b65525d05e6c4e2d308a1e1ed…

    laboratoreventsvc.com
    procarcaresvc.com

  71. 1 ipv4, 1 url2 yrs ago

    x.com/blackorbird/status/1854529596156182765 · virustotal.com/gui/file/fd2f4f23bb4d42a0d758d56ccb04a1…

    ipv495.169.180.122:443
    urlhttp://95.169.180.122

  72. 1 domain, 1 ipv42 yrs ago

    x.com/RedDrip7/status/1852178923695804654 · virustotal.com/gui/file/2544d79e47c01c9714264550b9e311…

    domainwusvcpsvc.com
    ipv445.56.165.121:46346

  73. 1 domain, 1 url_path2 yrs ago

    x.com/StrikeReadyLabs/status/1851227466259443… · virustotal.com/gui/file/2b0f8c6261b4e9e97732efadad14fc…

    domainiboxencentrum.com
    url_path/lux.php?cv=

  74. 1 ipv42 yrs ago

    x.com/ginkgo_g/status/1850821079260094731 · virustotal.com/gui/file/d28df7a8a275f628660e2f2744bfa3…

    192.71.249.194:443

  75. 2 domain, 1 url2 yrs ago

    x.com/blackorbird/status/1850060334079610936 · mp.weixin.qq.com/s/kkl0jh14M9DtDGtSGQ4gag

    domainfizzillacottages.com
    domainottawadesignlab.com
    urlhttp://47.245.111.83

  76. 1 domain, 5 ipv42 yrs ago

    x.com/blackorbird/status/1846487125249970293 · mp.weixin.qq.com/s/tkOMIHY36TujPKjWKVa6kA · virustotal.com/gui/ip-address/192.71.249.194/relations

    domainns2.easyiplookup.com
    ipv4151.236.9.75:6396
    ipv4162.252.172.67:443
    ipv4162.252.175.131:8246
    ipv446.183.187.42:443
    ipv491.132.92.231:5959

  77. 1 ipv42 yrs ago

    x.com/blackorbird/status/1846487125249970293 · mp.weixin.qq.com/s/tkOMIHY36TujPKjWKVa6kA · virustotal.com/gui/ip-address/192.71.249.194/relations · x.com/StrikeReadyLabs/status/1856371787145130… · medium.com/@knownsec404team/unveiling-the-past-and… · virustotal.com/gui/file/52362a3bf05d0f65c49d527bfecec7… · virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41… · virustotal.com/gui/file/cb7e6640ab5c1dad5083e5790d6009…

    46.183.186.208:6060

  78. 1 domain, 2 url_path2 yrs ago

    x.com/StrikeReadyLabs/status/1846000315566375… · x.com/ginkgo_g/status/1933364194998694198 · virustotal.com/gui/file/ae8d252986c616884c10ab5082088c… · virustotal.com/gui/file/939f509a8edc6b9da103fbcebe8563… · virustotal.com/gui/file/8af2d392181c359ce04e38ab113e22…

    domaininhostnetservice.com
    url_path/mscu/lokc.php
    url_path/mscu/lokc.php?wl=

  79. 2 domain2 yrs ago

    x.com/mal_analysis136/status/1846049340328198…

    miyamassagenklinik.com
    narinesonlinelibrary.com

  80. 6 domain, 2 ipv42 yrs ago

    x.com/blackorbird/status/1845000997665755151 · mp.weixin.qq.com/s/eseliIVHqiWI-Q1CoCA81g · virustotal.com/gui/file/8b7f36b3af85639ea0fcdd35eda43e… · virustotal.com/gui/file/df5c0d787de9cc7dceeec3e3457522…

    domainlocklearhealthapp.com
    domainmail.wmiapcservice.com
    domainmaxnursesolutions.com
    domainnurekleindesign.com
    domainsamsnewlooker.com
    domainwmiapcservice.com
    ipv4185.106.123.198:40269
    ipv496.9.215.155:56172

  81. 3 domain, 1 ipv42 yrs ago

    virustotal.com/gui/file/ba2853547fe79f52461323295f9bc5… · virustotal.com/gui/file/afaaa7d065ad7267dfbd2b69cd0d0e…

    domainlsamapkitlaunch.com
    domainnashmediawave.com
    domainns1.nashmediawave.com
    ipv45.135.43.181:35598

  82. 1 domain2 yrs ago

    virustotal.com/gui/file/c44d142a4cf541afcc4b5fc6612c7d… · virustotal.com/gui/file/3d529596440dfc64a7db106ddb77ec…

    microworldus.com

  83. 2 domain, 2 ipv4, 1 url2 yrs ago

    x.com/StrikeReadyLabs/status/1839037780644471… · x.com/silentpush_labs/status/1839077173141094… · virustotal.com/gui/file/294323c2611edeb7bae0ff3993ac48… · virustotal.com/gui/file/303bc4bce9555b02d9b1c0b96eb573…

    domaineasyiplookup.com
    domaingewistaplaner.gewista.at
    ipv4151.236.9.75:5080
    ipv491.132.92.231:6060
    urlhttp://151.236.9.75

  84. 2 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1839037780644471… · x.com/silentpush_labs/status/1839077173141094… · virustotal.com/gui/file/294323c2611edeb7bae0ff3993ac48… · virustotal.com/gui/file/303bc4bce9555b02d9b1c0b96eb573…

    apifilestore.net
    winfreecloud.net

  85. 1 domain2 yrs ago

    x.com/suyog41/status/1837073539121434966 · x.com/StrikeReadyLabs/status/1837317218943525… · virustotal.com/gui/file/507aa944d77806b3f24a3337729b52… · virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d…

    elevateecom.com

  86. 1 domain2 yrs ago

    x.com/suyog41/status/1837073539121434966 · x.com/StrikeReadyLabs/status/1837317218943525… · virustotal.com/gui/file/507aa944d77806b3f24a3337729b52… · virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d…

    vanessalove.com

  87. 1 domain2 yrs ago

    x.com/k3yp0d/status/1836001049976422810 · virustotal.com/gui/ip-address/104.200.73.57/relations

    healthtipsart.com

  88. 2 domain, 1 ipv42 yrs ago

    x.com/StrikeReadyLabs/status/1835445587149562… · virustotal.com/gui/file/81afc6d8e369ba8f08753541c78db4…

    domainjetmains.com
    domainsharesmydrive.com
    ipv465.20.105.88:8082

  89. 1 ipv42 yrs ago

    x.com/StrikeReadyLabs/status/1834599289391108… · virustotal.com/gui/file/67c0ad5ab6be8efec70a53cc56a03b… · virustotal.com/gui/file/5de9131252e6bc5a336516b9de4d7e…

    95.156.206.105:443

  90. 8 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1834609928285110… · virustotal.com/gui/ip-address/69.61.36.170/relations

    affinitycapitalgp.com
    affinitycapitalgr.com
    gdatesystems.com
    idbcxnetmac.com
    jmsatozplanning.com
    mcxntoolsservice.com
    sporcketngearforu.com
    surininfiniumclub.com

  91. 1 domain, 1 url_path2 yrs ago

    x.com/liqingjia1989/status/1834427464837464131 · virustotal.com/gui/file/575b783b3bd38271450a2c2cc8fb3a…

    domainbenclickstudio.com
    url_path/shrd.php?vo=

  92. 1 domain2 yrs ago

    x.com/liqingjia1989/status/1833410135005483214 · virustotal.com/gui/file/0db680ad035e30a4d17716538ab56a…

    andbouncersclub.com

  93. 1 domain2 yrs ago

    x.com/liqingjia1989/status/1831906877841797172 · virustotal.com/gui/file/dea912dce66c32598ec2d0a24b9e0b…

    aadresourcing.com

  94. 1 domain2 yrs ago

    x.com/mal_analysis136/status/1831562638104703…

    mnemautoregsvc.com

  95. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1831506911839080… · virustotal.com/gui/file/8f5f92e4d901eccf63e76223cacce4…

    glamorcliniques.com

  96. 1 domain2 yrs ago

    x.com/suyog41/status/1831196846615633926 · virustotal.com/gui/file/83e64fc374eff67e66b476d32bfd34…

    onlinewebdebugsvc.com

  97. 1 domain2 yrs ago

    x.com/mal_analysis136/status/1826491897910886…

    devflowservice.com

  98. 1 domain, 2 url_path2 yrs ago

    x.com/StrikeReadyLabs/status/1824790667765190… · virustotal.com/gui/file/2c5a14edacc03a57458d8260706720…

    domainmcdavezonepanel.com
    url_path/mloknj.php
    url_path/mloknj.php?cv=

  99. 1 domain2 yrs ago

    x.com/ShadowChasing1/status/18246304068236782… · virustotal.com/gui/file/11dff82741190cdb7934fd996796ad…

    mxuconlinegame.com

  100. 2 domain2 yrs ago

    strikeready.com/blog/open-sesame · virustotal.com/gui/ip-address/172.86.68.175/relations · virustotal.com/gui/file/15337ad45a65f8f9eae57f76d6cff3… · virustotal.com/gui/file/ba352569428df4618cd57f91bd3479… · virustotal.com/gui/file/ee088e6d8ac0f3dbfbd17f556a58d0… · virustotal.com/gui/file/52a4020392de0d527fe0aaf551fa55…

    kimfilippovision.com
    windowphotoviewer.com

  101. 1 domain2 yrs ago

    x.com/wa1Ile/status/1823643124562022487 · virustotal.com/gui/file/4c556d9e902c8cc0096bb564470758…

    vizylstatpro.com

  102. 1 url2 yrs ago

    x.com/k3yp0d/status/1823652687029698699 · virustotal.com/gui/file/42ab740ff15988b4f919b31a6203fb…

    http://94.156.175.95

  103. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1822458511940264… · virustotal.com/gui/file/e1aff2618bad2418023730bab3e2e1…

    gocartwillium.com

  104. 2 domain2 yrs ago

    x.com/suyog41/status/1820766059814953246 · x.com/StrikeReadyLabs/status/1820787452174368… · virustotal.com/gui/file/a1bb8ce0cf7290524326442be9b8ec…

    bickrickneoservice.com
    pdcunaco.com

  105. 2 domain, 1 ipv4, 1 url2 yrs ago

    x.com/karol_paciorek/status/18182048125649387… · virustotal.com/gui/file/28cb51c171d591b2bb35bc9a437901… · virustotal.com/gui/file/833501101c1af641e9910389596e79…

    domaincloudaff.net
    domainturkeyapi.bio
    ipv465.20.103.184:8080
    urlhttp://45.61.139.69

  106. 1 domain, 1 ipv42 yrs ago

    x.com/wa1Ile/status/1814284608269353136 · virustotal.com/gui/file/96f74896774ad4877740378d216afd…

    domainmindgamecenter.com
    ipv4193.29.58.210:15192

  107. 1 domain2 yrs ago

    x.com/wa1Ile/status/1795747139601195042 · virustotal.com/gui/file/ffee624870767c528c9d7578833483…

    lezziezgrillcorner.com

  108. 1 domain2 yrs ago

    x.com/suyog41/status/1813453691019571279 · virustotal.com/gui/file/8f03eb3fe7363bb7ab291c86680a71…

    littlehipsononline.com

  109. 1 domain, 1 ipv42 yrs ago

    x.com/liqingjia1989/status/1811658282366271537 · virustotal.com/gui/file/c2e492da957ef5c76b3cc8890007c4…

    domaingorgxwebset.com
    ipv446.30.190.137:51620

  110. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1811034367856161… · virustotal.com/gui/file/1dd50966db005e30f7a69b6d16dfe8…

    mxmediasolutions.com

  111. 1 domain2 yrs ago

    x.com/suyog41/status/1808379399953146053 · virustotal.com/gui/file/8c4416b735826bd35707b9caad3562…

    shioyuilubiz.com

  112. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1808457407632224… · virustotal.com/gui/file/86c4e9a4615836c6fc7c44f458a3fa…

    bakuackermannfashions.com

  113. 1 domain2 yrs ago

    virustotal.com/gui/file/309740ee31eff70c8510340293cc45…

    fusionjunction.link

  114. 1 domain2 yrs ago

    x.com/liqingjia1989/status/1798160822134546655 · virustotal.com/gui/file/7ca837a4e410b57e0c54bb6fb3a7ef…

    viyoappmapper.com

  115. 1 domain2 yrs ago

    x.com/liqingjia1989/status/1795276257627877723 · virustotal.com/gui/file/c8b93075675b6b90cc5a2f58bdd1c5…

    giov.officeweb.live

  116. 1 domain, 1 ipv42 yrs ago

    x.com/liqingjia1989/status/1795058403540173275 · virustotal.com/gui/file/bc764b4af4edeaf94920c75c7956b8…

    domainmanderikgamezilla.com
    ipv446.183.25.24:52546

  117. 1 domain2 yrs ago

    x.com/RedDrip7/status/1794979757559599555 · virustotal.com/gui/file/0b230b83c0b4af6e13ad837c35121d…

    mariasunistyle.com

  118. 13 domain2 yrs ago

    x.com/mal_analysis136/status/1793123437680210… · app.validin.com/detail?type=dom&find=aduhoki88.com#tab=…

    55five.lol
    888toto.com
    8toto.co
    918slot.top
    99togel.org
    99toto.shop
    aduhoki88.com
    bulltrader.vip
    efgchartered.co.uk
    kertasiusaus.com
    maxcavelli.com
    plugins-support.com
    test.bulltrader.vip

  119. 1 domain2 yrs ago

    x.com/alex_lanstein/status/1792638726931161109 · virustotal.com/gui/file/482e4f64e1aa9096bed00dbe0cc645…

    goalvaidclub.com

  120. 1 domain2 yrs ago

    twitter.com/liqingjia1989/status/1788123283931717847 · virustotal.com/gui/file/f95167754f162097b83495baa070d3…

    yalinasculetips.com

  121. 1 domain, 1 ipv42 yrs ago

    twitter.com/liqingjia1989/status/1787752297461846466 · virustotal.com/gui/file/667e411ec65acc61eea0be0dbae8a4…

    domainsmartclouddirect.com
    ipv4167.88.15.93:61920

  122. 1 ipv42 yrs ago

    twitter.com/suyog41/status/1785925227337375766 · virustotal.com/gui/file/30f9676fb31a2ee5c4d5ec9e380942…

    47.94.19.69:8080

  123. 1 domain2 yrs ago

    twitter.com/liqingjia1989/status/1784846105416708314 · virustotal.com/gui/file/53e9d201163cd5fc1adf3974afb41c…

    johnfashionaccess.com

  124. 1 domain2 yrs ago

    twitter.com/alex_lanstein/status/1785026144246325630 · virustotal.com/gui/ip-address/93.123.73.160/relations

    colorsofnether.com

  125. 4 domain2 yrs ago

    twitter.com/ginkgo_g/status/1784505204391739493 · virustotal.com/gui/file/ba2e21641a1238a5b30e535bd0940f… · virustotal.com/gui/file/6cdc79edba95c6a9ec1d50457dc16f…

    libraofficeonline.com
    officeweb.live
    outlook-web.ddns.net
    outlook.officeweb.live

  126. 1 domain, 1 ipv42 yrs ago

    virustotal.com/gui/file/85a6ac13510983b3a29ccb2527679d…

    domainmicrosoft.officeweb.live
    ipv4141.94.68.169:443

  127. 1 domain2 yrs ago

    twitter.com/ginkgo_g/status/1783386949765718155 · virustotal.com/gui/file/dcdae583da8a1b01a8ad0caef6a7f6…

    oraclewebonline.com

  128. 1 domain2 yrs ago

    twitter.com/liqingjia1989/status/1777622247936491681 · virustotal.com/gui/file/9fcae6572e9d474e131e64b639becf…

    evtessentials.com

  129. 1 domain2 yrs ago

    twitter.com/liqingjia1989/status/1776779248524755435 · virustotal.com/gui/file/4dfe81aeb881c9e7cf0a469542d390…

    bsdqcaptureman.com

  130. 1 domain2 yrs ago

    twitter.com/__0XYC__/status/1770689612031164671 · virustotal.com/gui/file/7525cecb3d45097db48ee08410ba2b…

    libraofficeweb.com

  131. 1 domain2 yrs ago

    twitter.com/JVPv5sIM3eFmGyi/status/1765651279093612…

    bartelemarks.com

  132. 1 domain2 yrs ago

    twitter.com/suyog41/status/1765296640028774450 · virustotal.com/gui/file/8b79f6b2061e3231da4ef75799ad97…

    whitelilyshop.com

Further reading 588

548 more, and the report behind every indicator, in G1002.json.