Overview 670 indicators
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.
| domain | 466 | G1002-domain.txt |
| url_path | 102 | G1002.json |
| ipv4 | 78 | G1002.json |
| url | 24 | G1002.json |
Techniques 17 ATT&CK
Open in ATT&CK Navigator → or download the layer (17 techniques, layer 4.5)
- T1027.013 Encrypted/Encoded File
- T1036.004 Masquerade Task or Service
- T1053.005 Scheduled Task
- T1068 Exploitation for Privilege Escalation
- T1071.001 Web Protocols
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1559.002 Dynamic Data Exchange
- T1566.001 Spearphishing Attachment
- T1568 Dynamic Resolution
- T1573 Encrypted Channel
- T1583.001 Domains
- T1588.002 Tool
- T1608.001 Upload Malware
- T1660 Phishing
Software 1
Principal sources 586 reports
Ranked by how many of this actor's indicators each report brought in.
- 38github.com/pan-unit42/iocs/blob/master/bitter/iocs…
- 18github.com/blackorbird/APT_REPORT/tree/master/bitt…
- 17about.fb.com/wp-content/uploads/2022/08/Quarterly-Ad…
- 17otx.alienvault.com/pulse/62f2344533e6cfe5e975f573
- 17ti.qianxin.com/blog/articles/%22operation-magichm%22:C…
- 15twitter.com/blackorbird/status/1295265067173163010
- 15twitter.com/ShadowChasing1/status/13036285473663508…
- 15twitter.com/ShadowChasing1/status/13064229119729582…
Related groups 8
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 670 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 670. Complete: G1002.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/nextronresearch/status/2070473326372291… · virustotal.com/gui/file/d0ee008d3c480d5f9f75332851ae94…
ultraflavors.com -
x.com/blackorbird/status/2064727597435752846 · mp.weixin.qq.com/s/jH60_sYtZjJZWtVc5d277g
domain downloadclouddata.com ipv4 163.245.220.108:8442 -
x.com/blackorbird/status/2051892318203175106
fswhardtools.com vpn146318720.softether.net -
x.com/RexorVc0/status/2049740014875967766 · mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508516…
domain domainnamevalidator.com domain domainregistationcheck.com domain getserviceupdates.com ipv4 151.236.4.164:5010 ipv4 89.46.236.152:443 url http://46.30.191.221 -
x.com/RedDrip7/status/2049775100237676647 · virustotal.com/gui/file/359200a112936939f8b324bee7edc9… · virustotal.com/gui/file/c151a8861d4f75c09803efa6773221… · virustotal.com/gui/file/84f2b3cde61895fbe28c3660d5f8d7…
bravojacksonmentor.com -
x.com/RedDrip7/status/2047579562184413587 · virustotal.com/gui/file/563fd6ff3f767d8120731803aeec9e… · virustotal.com/gui/file/85fae6eb3d173274e59293d31d48c1…
domain grandinaspectrum.com url_path /hgdtfjgtyf.php -
x.com/smica83/status/2044417422606655769 · virustotal.com/gui/file/6fd40f0aba5c6bd9dd784abd8f5c0e…
invstampvest.com -
x.com/volrant136/status/2041159217374244990 · virustotal.com/gui/file/0b6d4f7a545e6fc1bfc907f76e9291…
commonlifesupport.com -
x.com/RedDrip7/status/2038827595018727498 · virustotal.com/gui/file/7ea0930a332788c2e88e5822e4908d… · virustotal.com/gui/file/9fb6f4c55e5198739123264f8007cf…
188.214.33.170:443 -
x.com/RedDrip7/status/2037368885876564464 · virustotal.com/gui/file/bbe94912c0dd4b812decf9d4e8a81d…
domain haburyohoteam.com url_path /jvdmhawme.okjhvthfv -
x.com/RedDrip7/status/2037368638605570409 · virustotal.com/gui/file/c967e7d3c8227e209537257bfe21a6…
caravelcruiser.com -
x.com/RedDrip7/status/2031616083569029525 · virustotal.com/gui/file/fb91c7fd342803ae581ea52e78bc61…
99media.com.pk zoemagicbook.com -
x.com/RedDrip7/status/2027209484784017629 · virustotal.com/gui/file/e6b523e77c31b89f8eb3489007bf14…
domain ashersoftlib.com ipv4 107.172.39.100:44908 -
x.com/skocherhan/status/2024194564605579358 · virustotal.com/gui/file/4885affbac1695037c5fbfc000ff54… · virustotal.com/gui/file/5a98b05cff064c3884c689e4f4fb99…
officesignature.info -
strikeready.com/blog/open-sesame · virustotal.com/gui/ip-address/172.86.68.175/relations · virustotal.com/gui/file/15337ad45a65f8f9eae57f76d6cff3… · virustotal.com/gui/file/ba352569428df4618cd57f91bd3479… · virustotal.com/gui/file/ee088e6d8ac0f3dbfbd17f556a58d0… · virustotal.com/gui/file/52a4020392de0d527fe0aaf551fa55…
nelavohomet.com -
x.com/RedDrip7/status/2019243120131805198 · virustotal.com/gui/file/941011523ce613d6729e83febc1de7… · virustotal.com/gui/file/28b586cf4f84eeb6ced3e5b40451e0…
domain pinkrosesandmore.com domain prolukemarion.com url_path /ceszvd.php url_path /vbdfsbad.php -
x.com/RedDrip7/status/2016415763633242298 · virustotal.com/gui/file/836c8fb1ff998d3b94b4800aca7b17…
134.255.210.127:443 -
x.com/RedDrip7/status/2014542257488306575 · virustotal.com/gui/file/6d92924ff3a1de18fe715c2e7432ee… · virustotal.com/gui/file/d597c488b73cde0938b464f93ed9ee…
crudestopics.com -
x.com/RedDrip7/status/2011023732341686629 · virustotal.com/gui/file/8753006b62b74c6805e6cb22e149a4…
domain broadsforthestate.com url_path /jdfgwe.php -
x.com/RedDrip7/status/2009443295127326763 · virustotal.com/gui/file/deb241a46da181c8c1f68a43745fcb… · virustotal.com/gui/file/dfedb0033337aaa8570ef682a93119…
185.193.50.233:443 83.243.121.87:443 -
x.com/ThreatrayLabs/status/1986432637762732515 · virustotal.com/gui/ip-address/103.57.251.154/relations · virustotal.com/gui/file/090b1691a623cc6e8d956ed41ab3ef… · virustotal.com/gui/file/0ca1ce61d917771ed344f8345a8161…
domain jmxdnqr8.mediumblog.online domain manage.mediumblog.online domain mediumblog.online domain qdey4uvj.mediumblog.online domain rgevzuir.mediumblog.online domain services.windowmediaplayer.media domain unr0wddj.mediumblog.online domain vzgmbwva.mediumblog.online domain windowmediaplayer.media domain yorkstar.mediumblog.online ipv4 103.57.251.154:4443 ipv4 192.71.213.128:4431 -
x.com/volrant136/status/1923686317252075887
alvesbarcelona.com app.chabaka.com balkanclan.com chabaka.com com-ae.net drogbachelsea.com mail.alvesbarcelona.com mail.com-ae.net mail.drogbachelsea.com mail.youtubepremiumapp.com opfor.balkanclan.com -
x.com/RedDrip7/status/1976924908736405560 · x.com/RedDrip7/status/1976923481377063382 · virustotal.com/gui/ip-address/78.110.166.82/relations · virustotal.com/gui/file/bb67a4de756336d45ebaa7657a7586… · virustotal.com/gui/file/f7e25e5601fdf038aa0840be508cf1…
domain 365cloudz.esanojinjasvc.com domain eliteteam.esanojinjasvc.com domain esanojinjasvc.com domain msoffice.365cloudz.esanojinjasvc.com domain supportteaminterface.esanojinjasvc.com domain teamlogin.esanojinjasvc.com url_path /cloudzx/msweb/drdxcsv34.php url_path /cloudzx/msweb/drxbds23.php url_path /cloudzx/msweb/drxcvg45.php url_path /teamesano/drivers/teamzid.php -
x.com/malwrhunterteam/status/1929906003258048… · x.com/BaoshengbinCumt/status/1946009959831126… · seqrite.com/blog/ung0002-espionage-campaigns-south-… · virustotal.com/gui/file/4ca4f673e4389a352854f5feb0793d…
domain ecoglide.site domain marine-research.space domain pentree.online domain skyfare.site ipv4 162.0.216.229:21443 ipv4 162.0.216.229:8888 ipv4 209.74.80.194:7699 -
x.com/frdfzi/status/1930495401456533564 · proofpoint.com/us/blog/threat-insight/bitter-end-unrav… · threatray.com/blog/the-bitter-end-unraveling-eight-ye…
domain blucollinsoutien.com domain headntale.com domain trkswqsservice.com domain utizviewstation.com domain warsanservices.com domain woodstocktutors.com url http://46.229.55.63 -
x.com/WhichbufferArda/status/1921506670343061… · tria.ge/250511-kptycahm6s/behavioral1 · virustotal.com/gui/file/15db9daa175d506c3e1eaee339eecd… · virustotal.com/gui/file/edb68223db3e583f9a4dd52fd91867…
domain fogomyart.com domain greenadelhouse.com domain maximasigns.greenadelhouse.com domain tradesmarkets.greenadelhouse.com url_path /crvtyfgvwicidnex.php url_path /excerorderslistoncbook.php -
x.com/RedDrip7/status/1978366720432562372 · virustotal.com/gui/file/9b21e4b32e3e125bad638df76f25ca… · virustotal.com/gui/file/d6a533102f801066ddd6069e20f3a5…
domain bootcampquest.com domain mail.bootcampquest.com domain tools.bootcampquest.com ipv4 194.110.246.254:443 ipv4 83.172.134.186:443 -
x.com/RedDrip7/status/1962415190051573781 · x.com/blackorbird/status/1981958007958524023 · virustotal.com/gui/file/1e7ce7c530a1cf4d74a356592f99bd… · virustotal.com/gui/file/66eff3058760b478aa70b44b929ca5… · virustotal.com/gui/file/b6bd48fa94fa15cdcbd6b24198472f… · virustotal.com/gui/file/7b801221a024507ff948261bf5b635… · virustotal.com/gui/file/08674b806c13a1dab0964548302170…
carlminiclub.com keeferbeautytrends.com microsoft365.sangellobrighthouse.com sangellobrighthouse.com -
x.com/volrant136/status/1956393083949502767 · virustotal.com/gui/file/6f0bc10f8326b462e02cf97f4aac1e…
domain nsipsvc.com url_path /edgevrisinze.php url_path /imacnags/edgevrisinze.php -
x.com/liqingjia1989/status/1930584300224676024 · virustotal.com/gui/file/a76f00ea65cf7fb9327e9b6d2d4aca…
domain inspurcloudservice.com ipv4 89.46.234.221:443 ipv4 89.46.234.221:9672 -
x.com/RedDrip7/status/2004026276294938903 · virustotal.com/gui/file/974abd4dc03bd9dc1a5d7ae56d2882… · virustotal.com/gui/file/8c95b0d740df0f91444d5ddb9107f3… · virustotal.com/gui/file/c93e0f954cfcfafbb07cc248fab316…
florabrocuisine.com joelgardens.com oscarskatingcoach.com -
x.com/suyog41/status/1924329354504634767 · virustotal.com/gui/file/d02fd3472adb0d7a502b08656c5001…
domain jgmfducservice.net url_path /jmv/jmd.php?st= -
x.com/smica83/status/1983935993209069584 · tria.ge/251030-t3ev1s1khn/behavioral1 · virustotal.com/gui/ip-address/146.70.118.226/relations · virustotal.com/gui/file/8b57d6b676afdd84786655eb5fc876…
large-file-download-in-progress-page-loading-iuwt6sk34bs6543df.tartaakademi.com tartaakademi.com -
x.com/malwrhunterteam/status/1925086462120165… · virustotal.com/gui/file/ea73818d5c96294381ea56af0bdda9…
url http://196.251.84.150 url_path /v10.066/egrf.php -
x.com/ginkgo_g/status/1897192606196703668 · virustotal.com/gui/file/8958b215f30f9d48010fb93363125d… · virustotal.com/gui/file/7847a287472f7e2b688bd5d000f435…
url http://149.154.153.184 url_path /loccs.php?cn= -
x.com/blackorbird/status/1958836180587307479 · mp.weixin.qq.com/s/ItcbKuoH0KjJjzSTG7YSrA · virustotal.com/gui/file/a850a903b74c1d3d21c41e03761e8e…
domain pololiberty.com ipv4 185.237.166.24:56218 -
x.com/__0XYC__/status/1930552371530129610 · x.com/__0XYC__/status/1930552424353202399 · virustotal.com/gui/file/5bdbec839592af17a725c5705201d3… · virustotal.com/gui/file/fbab7758765265a6988e78779cae2e…
domain diginurworld.com ipv4 151.236.21.48:8080 -
x.com/StrikeReadyLabs/status/1846000315566375… · x.com/ginkgo_g/status/1933364194998694198 · virustotal.com/gui/file/ae8d252986c616884c10ab5082088c… · virustotal.com/gui/file/939f509a8edc6b9da103fbcebe8563… · virustotal.com/gui/file/8af2d392181c359ce04e38ab113e22…
/cndrll.php /cndrll.php?er= -
x.com/RedDrip7/status/1998638735358128307 · virustotal.com/gui/file/1f262d5838e29f56eb190100f0753f… · virustotal.com/gui/file/1854e0e0a59a82e4d9629dd54a506e… · virustotal.com/gui/file/ffea43ead04d4bda567b1fd32ec68c…
andrewswebstorage.com sanolegazy.com -
x.com/RedDrip7/status/1993874904710828150 · virustotal.com/gui/file/258918e48a7aaf393af89858f95af6…
domain hannahsgpsapp.com ipv4 185.117.72.87:10923 -
x.com/RedDrip7/status/1964874030869332252
151.236.14.173:443 185.76.79.30:443 -
x.com/AndreGironda/status/1955692280825962846 · blog.pulsedive.com/unpacking-kiwistealer-diving-into-bitte… · app.any.run/tasks/a755b624-d146-4a49-acd5-c25e6b07a…
domain ebeninstallsvc.com url_path /uplh4ppy.php -
x.com/wa1Ile/status/1925447893743542391 · virustotal.com/gui/file/64fd1e641731e48ea8c3df7b9caa5f…
inizdesignstudio.com -
x.com/volrant136/status/1941557096933359638
oakcreekbakers.com -
x.com/volrant136/status/1930659807440039970 · virustotal.com/gui/ip-address/69.61.36.186/relations
goldenaturalinc.com -
x.com/volrant136/status/1924126261514833963
parcaredrive.com -
x.com/suyog41/status/1963171056044109898 · virustotal.com/gui/file/624decbc0445e51873436e42699323…
seragoonupdates.com -
x.com/suyog41/status/1952990924210094369 · virustotal.com/gui/file/121c3917e7b2e00d7c6e15f09370d2…
koliwooclients.com -
x.com/suyog41/status/1952709606297227414 · virustotal.com/gui/file/891ffe498debc7accfbdf9146adb6d…
ccltdcn.org -
x.com/suyog41/status/1929855753206083762 · virustotal.com/gui/file/6763fadbfbcf125a73cc6388aba075…
plymouthvibes.com -
x.com/suyog41/status/1922608403454583215 · virustotal.com/gui/file/31214e97722f99666dde6b09f386e7…
princecleanit.com -
x.com/malwrhunterteam/status/2002470001924813… · virustotal.com/gui/file/f692ba8fbe76ee5488fd81ad3ae668…
stellacustomscreens.com -
x.com/malwrhunterteam/status/1994001214795862… · virustotal.com/gui/file/09647fabb086acf09fdc72f3e8703c…
pawsandtailcare.com -
x.com/malwrhunterteam/status/1923660512920744… · virustotal.com/gui/file/243e4d1e53a805f61d2c4e8cabdd02…
ntplugnplay.com -
x.com/blackorbird/status/1986747686050287997 · mp.weixin.qq.com/s/CI1g4iaYxHhO925V15LvIQ · virustotal.com/gui/file/93a905048ca8cdf7162ade1720d508…
tapeqcqoptions.com -
x.com/RedDrip7/status/2001489642072482032 · virustotal.com/gui/file/1fd8ba64a687247466fa6e8b7d1941… · virustotal.com/gui/file/71fa6a00314701fef5c6f32c17e143… · virustotal.com/gui/file/974626cf14864f0a3185233bbce417…
46.30.191.221:443 -
x.com/RedDrip7/status/1952922656220823798 · virustotal.com/gui/file/389883cfa666855750974c540299de… · virustotal.com/gui/file/886c36f4625f98537e8f2df5975aab…
glamormusicwave.com -
twitter.com/binlmmhc/status/1610969202722242561 · x.com/ShanHolo/status/1971249000985788673
/cmpn/xing.php -
x.com/SethKingHi/status/1876845124488941942 · virustotal.com/gui/file/d94ff0edb28f7b90b9e4ab9ee94e8d… · virustotal.com/gui/file/b1efa4e3abadfab14aba6e36ed9f41… · virustotal.com/gui/file/1126916c98b7801175375827fb5e8b…
ipv4 158.255.215.45:8899 ipv4 185.193.48.135:8676 ipv4 194.71.227.222:8855 ipv4 91.103.66.202:46882 url_path /anotherLife?credPart= url_path /nina/anotherLife?credPart= -
x.com/banthisguy9349/status/18671791048998546… · x.com/banthisguy9349/status/18674586255325064… · virustotal.com/gui/file/acfb3223d5bcbcf96ee1265fdd510c… · virustotal.com/gui/file/a152fa2e7368ed357a91214fdd91e1…
http://72.18.215.1 -
x.com/StrikeReadyLabs/status/1865140931953070… · x.com/mal_analysis136/status/1865323680344969… · virustotal.com/gui/file/14ce282ffeaa5cc3d214acae337857…
url http://37.1.214.196 url_path /zserr.php url_path /zserr.php?li= -
x.com/StrikeReadyLabs/status/1864408026658041… · virustotal.com/gui/file/65419a704f252f8c3574d90cf016b6…
grounpackcluepik.com -
x.com/suyog41/status/1864199979369447473 · x.com/mal_analysis136/status/1864285903058809… · virustotal.com/gui/ip-address/185.244.151.84/relations · virustotal.com/gui/file/cb4a280f54c56d250c98124a88e80c…
jacknwoods.com premierinvestmentfund.com -
x.com/blackorbird/status/1862131045883408582 · virustotal.com/gui/file/e44d034ceb135990452fce74d358bd…
http://159.100.30.103 http://173.254.204.72 -
x.com/StrikeReadyLabs/status/1861383328521207… · x.com/mal_analysis136/status/1863537157119299… · virustotal.com/gui/file/b3b2d915f47aa631cc4900ec56f9b8…
domain siasat.top url_path /xyzxyzhanoiwhb3237gb2wahabjiki/ -
x.com/blackorbird/status/1859161598469836806 · blogs.blackberry.com/en/2024/11/suspected-nation-state-adver… · virustotal.com/gui/collection/f6f862c588961ae94c5c23d9… · virustotal.com/gui/file/fc39ec35d767a2c0a178ca9874be8a… · virustotal.com/gui/file/a0a18e76d8af39b9b198d9ea7c67dc…
updateschedulers.com -
x.com/blackorbird/status/1858873110625243398
dappscryp.com ghayoorfilmstudio.com haileemecacademy.com zensparkagent.com -
x.com/wa1Ile/status/1858421539286168058 · virustotal.com/gui/file/c00570eb0b47614b7286cf945b2127…
abelewebconnect.com -
x.com/StrikeReadyLabs/status/1856371787145130… · medium.com/@knownsec404team/unveiling-the-past-and… · virustotal.com/gui/file/52362a3bf05d0f65c49d527bfecec7… · virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41… · virustotal.com/gui/file/cb7e6640ab5c1dad5083e5790d6009…
domain federalrevenueboard.com ipv4 162.252.175.131:6969 ipv4 91.132.92.231:9314 -
x.com/blackorbird/status/1856340219328639441 · virustotal.com/gui/file/08d12b65525d05e6c4e2d308a1e1ed…
laboratoreventsvc.com procarcaresvc.com -
x.com/blackorbird/status/1854529596156182765 · virustotal.com/gui/file/fd2f4f23bb4d42a0d758d56ccb04a1…
ipv4 95.169.180.122:443 url http://95.169.180.122 -
x.com/RedDrip7/status/1852178923695804654 · virustotal.com/gui/file/2544d79e47c01c9714264550b9e311…
domain wusvcpsvc.com ipv4 45.56.165.121:46346 -
x.com/StrikeReadyLabs/status/1851227466259443… · virustotal.com/gui/file/2b0f8c6261b4e9e97732efadad14fc…
domain iboxencentrum.com url_path /lux.php?cv= -
x.com/ginkgo_g/status/1850821079260094731 · virustotal.com/gui/file/d28df7a8a275f628660e2f2744bfa3…
192.71.249.194:443 -
x.com/blackorbird/status/1850060334079610936 · mp.weixin.qq.com/s/kkl0jh14M9DtDGtSGQ4gag
domain fizzillacottages.com domain ottawadesignlab.com url http://47.245.111.83 -
x.com/blackorbird/status/1846487125249970293 · mp.weixin.qq.com/s/tkOMIHY36TujPKjWKVa6kA · virustotal.com/gui/ip-address/192.71.249.194/relations
domain ns2.easyiplookup.com ipv4 151.236.9.75:6396 ipv4 162.252.172.67:443 ipv4 162.252.175.131:8246 ipv4 46.183.187.42:443 ipv4 91.132.92.231:5959 -
x.com/blackorbird/status/1846487125249970293 · mp.weixin.qq.com/s/tkOMIHY36TujPKjWKVa6kA · virustotal.com/gui/ip-address/192.71.249.194/relations · x.com/StrikeReadyLabs/status/1856371787145130… · medium.com/@knownsec404team/unveiling-the-past-and… · virustotal.com/gui/file/52362a3bf05d0f65c49d527bfecec7… · virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41… · virustotal.com/gui/file/cb7e6640ab5c1dad5083e5790d6009…
46.183.186.208:6060 -
x.com/StrikeReadyLabs/status/1846000315566375… · x.com/ginkgo_g/status/1933364194998694198 · virustotal.com/gui/file/ae8d252986c616884c10ab5082088c… · virustotal.com/gui/file/939f509a8edc6b9da103fbcebe8563… · virustotal.com/gui/file/8af2d392181c359ce04e38ab113e22…
domain inhostnetservice.com url_path /mscu/lokc.php url_path /mscu/lokc.php?wl= -
x.com/mal_analysis136/status/1846049340328198…
miyamassagenklinik.com narinesonlinelibrary.com -
x.com/blackorbird/status/1845000997665755151 · mp.weixin.qq.com/s/eseliIVHqiWI-Q1CoCA81g · virustotal.com/gui/file/8b7f36b3af85639ea0fcdd35eda43e… · virustotal.com/gui/file/df5c0d787de9cc7dceeec3e3457522…
domain locklearhealthapp.com domain mail.wmiapcservice.com domain maxnursesolutions.com domain nurekleindesign.com domain samsnewlooker.com domain wmiapcservice.com ipv4 185.106.123.198:40269 ipv4 96.9.215.155:56172 -
virustotal.com/gui/file/ba2853547fe79f52461323295f9bc5… · virustotal.com/gui/file/afaaa7d065ad7267dfbd2b69cd0d0e…
domain lsamapkitlaunch.com domain nashmediawave.com domain ns1.nashmediawave.com ipv4 5.135.43.181:35598 -
virustotal.com/gui/file/c44d142a4cf541afcc4b5fc6612c7d… · virustotal.com/gui/file/3d529596440dfc64a7db106ddb77ec…
microworldus.com -
x.com/StrikeReadyLabs/status/1839037780644471… · x.com/silentpush_labs/status/1839077173141094… · virustotal.com/gui/file/294323c2611edeb7bae0ff3993ac48… · virustotal.com/gui/file/303bc4bce9555b02d9b1c0b96eb573…
domain easyiplookup.com domain gewistaplaner.gewista.at ipv4 151.236.9.75:5080 ipv4 91.132.92.231:6060 url http://151.236.9.75 -
x.com/StrikeReadyLabs/status/1839037780644471… · x.com/silentpush_labs/status/1839077173141094… · virustotal.com/gui/file/294323c2611edeb7bae0ff3993ac48… · virustotal.com/gui/file/303bc4bce9555b02d9b1c0b96eb573…
apifilestore.net winfreecloud.net -
x.com/suyog41/status/1837073539121434966 · x.com/StrikeReadyLabs/status/1837317218943525… · virustotal.com/gui/file/507aa944d77806b3f24a3337729b52… · virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d…
elevateecom.com -
x.com/suyog41/status/1837073539121434966 · x.com/StrikeReadyLabs/status/1837317218943525… · virustotal.com/gui/file/507aa944d77806b3f24a3337729b52… · virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d…
vanessalove.com -
x.com/k3yp0d/status/1836001049976422810 · virustotal.com/gui/ip-address/104.200.73.57/relations
healthtipsart.com -
x.com/StrikeReadyLabs/status/1835445587149562… · virustotal.com/gui/file/81afc6d8e369ba8f08753541c78db4…
domain jetmains.com domain sharesmydrive.com ipv4 65.20.105.88:8082 -
x.com/StrikeReadyLabs/status/1834599289391108… · virustotal.com/gui/file/67c0ad5ab6be8efec70a53cc56a03b… · virustotal.com/gui/file/5de9131252e6bc5a336516b9de4d7e…
95.156.206.105:443 -
x.com/StrikeReadyLabs/status/1834609928285110… · virustotal.com/gui/ip-address/69.61.36.170/relations
affinitycapitalgp.com affinitycapitalgr.com gdatesystems.com idbcxnetmac.com jmsatozplanning.com mcxntoolsservice.com sporcketngearforu.com surininfiniumclub.com -
x.com/liqingjia1989/status/1834427464837464131 · virustotal.com/gui/file/575b783b3bd38271450a2c2cc8fb3a…
domain benclickstudio.com url_path /shrd.php?vo= -
x.com/liqingjia1989/status/1833410135005483214 · virustotal.com/gui/file/0db680ad035e30a4d17716538ab56a…
andbouncersclub.com -
x.com/liqingjia1989/status/1831906877841797172 · virustotal.com/gui/file/dea912dce66c32598ec2d0a24b9e0b…
aadresourcing.com -
x.com/mal_analysis136/status/1831562638104703…
mnemautoregsvc.com -
x.com/StrikeReadyLabs/status/1831506911839080… · virustotal.com/gui/file/8f5f92e4d901eccf63e76223cacce4…
glamorcliniques.com -
x.com/suyog41/status/1831196846615633926 · virustotal.com/gui/file/83e64fc374eff67e66b476d32bfd34…
onlinewebdebugsvc.com -
x.com/mal_analysis136/status/1826491897910886…
devflowservice.com -
x.com/StrikeReadyLabs/status/1824790667765190… · virustotal.com/gui/file/2c5a14edacc03a57458d8260706720…
domain mcdavezonepanel.com url_path /mloknj.php url_path /mloknj.php?cv= -
x.com/ShadowChasing1/status/18246304068236782… · virustotal.com/gui/file/11dff82741190cdb7934fd996796ad…
mxuconlinegame.com -
strikeready.com/blog/open-sesame · virustotal.com/gui/ip-address/172.86.68.175/relations · virustotal.com/gui/file/15337ad45a65f8f9eae57f76d6cff3… · virustotal.com/gui/file/ba352569428df4618cd57f91bd3479… · virustotal.com/gui/file/ee088e6d8ac0f3dbfbd17f556a58d0… · virustotal.com/gui/file/52a4020392de0d527fe0aaf551fa55…
kimfilippovision.com windowphotoviewer.com -
x.com/wa1Ile/status/1823643124562022487 · virustotal.com/gui/file/4c556d9e902c8cc0096bb564470758…
vizylstatpro.com -
x.com/k3yp0d/status/1823652687029698699 · virustotal.com/gui/file/42ab740ff15988b4f919b31a6203fb…
http://94.156.175.95 -
x.com/StrikeReadyLabs/status/1822458511940264… · virustotal.com/gui/file/e1aff2618bad2418023730bab3e2e1…
gocartwillium.com -
x.com/suyog41/status/1820766059814953246 · x.com/StrikeReadyLabs/status/1820787452174368… · virustotal.com/gui/file/a1bb8ce0cf7290524326442be9b8ec…
bickrickneoservice.com pdcunaco.com -
x.com/karol_paciorek/status/18182048125649387… · virustotal.com/gui/file/28cb51c171d591b2bb35bc9a437901… · virustotal.com/gui/file/833501101c1af641e9910389596e79…
domain cloudaff.net domain turkeyapi.bio ipv4 65.20.103.184:8080 url http://45.61.139.69 -
x.com/wa1Ile/status/1814284608269353136 · virustotal.com/gui/file/96f74896774ad4877740378d216afd…
domain mindgamecenter.com ipv4 193.29.58.210:15192 -
x.com/wa1Ile/status/1795747139601195042 · virustotal.com/gui/file/ffee624870767c528c9d7578833483…
lezziezgrillcorner.com -
x.com/suyog41/status/1813453691019571279 · virustotal.com/gui/file/8f03eb3fe7363bb7ab291c86680a71…
littlehipsononline.com -
x.com/liqingjia1989/status/1811658282366271537 · virustotal.com/gui/file/c2e492da957ef5c76b3cc8890007c4…
domain gorgxwebset.com ipv4 46.30.190.137:51620 -
x.com/StrikeReadyLabs/status/1811034367856161… · virustotal.com/gui/file/1dd50966db005e30f7a69b6d16dfe8…
mxmediasolutions.com -
x.com/suyog41/status/1808379399953146053 · virustotal.com/gui/file/8c4416b735826bd35707b9caad3562…
shioyuilubiz.com -
x.com/StrikeReadyLabs/status/1808457407632224… · virustotal.com/gui/file/86c4e9a4615836c6fc7c44f458a3fa…
bakuackermannfashions.com -
virustotal.com/gui/file/309740ee31eff70c8510340293cc45…
fusionjunction.link -
x.com/liqingjia1989/status/1798160822134546655 · virustotal.com/gui/file/7ca837a4e410b57e0c54bb6fb3a7ef…
viyoappmapper.com -
x.com/liqingjia1989/status/1795276257627877723 · virustotal.com/gui/file/c8b93075675b6b90cc5a2f58bdd1c5…
giov.officeweb.live -
x.com/liqingjia1989/status/1795058403540173275 · virustotal.com/gui/file/bc764b4af4edeaf94920c75c7956b8…
domain manderikgamezilla.com ipv4 46.183.25.24:52546 -
x.com/RedDrip7/status/1794979757559599555 · virustotal.com/gui/file/0b230b83c0b4af6e13ad837c35121d…
mariasunistyle.com -
x.com/mal_analysis136/status/1793123437680210… · app.validin.com/detail?type=dom&find=aduhoki88.com#tab=…
55five.lol 888toto.com 8toto.co 918slot.top 99togel.org 99toto.shop aduhoki88.com bulltrader.vip efgchartered.co.uk kertasiusaus.com maxcavelli.com plugins-support.com test.bulltrader.vip -
x.com/alex_lanstein/status/1792638726931161109 · virustotal.com/gui/file/482e4f64e1aa9096bed00dbe0cc645…
goalvaidclub.com -
twitter.com/liqingjia1989/status/1788123283931717847 · virustotal.com/gui/file/f95167754f162097b83495baa070d3…
yalinasculetips.com -
twitter.com/liqingjia1989/status/1787752297461846466 · virustotal.com/gui/file/667e411ec65acc61eea0be0dbae8a4…
domain smartclouddirect.com ipv4 167.88.15.93:61920 -
twitter.com/suyog41/status/1785925227337375766 · virustotal.com/gui/file/30f9676fb31a2ee5c4d5ec9e380942…
47.94.19.69:8080 -
twitter.com/liqingjia1989/status/1784846105416708314 · virustotal.com/gui/file/53e9d201163cd5fc1adf3974afb41c…
johnfashionaccess.com -
twitter.com/alex_lanstein/status/1785026144246325630 · virustotal.com/gui/ip-address/93.123.73.160/relations
colorsofnether.com -
twitter.com/ginkgo_g/status/1784505204391739493 · virustotal.com/gui/file/ba2e21641a1238a5b30e535bd0940f… · virustotal.com/gui/file/6cdc79edba95c6a9ec1d50457dc16f…
libraofficeonline.com officeweb.live outlook-web.ddns.net outlook.officeweb.live -
virustotal.com/gui/file/85a6ac13510983b3a29ccb2527679d…
domain microsoft.officeweb.live ipv4 141.94.68.169:443 -
twitter.com/ginkgo_g/status/1783386949765718155 · virustotal.com/gui/file/dcdae583da8a1b01a8ad0caef6a7f6…
oraclewebonline.com -
twitter.com/liqingjia1989/status/1777622247936491681 · virustotal.com/gui/file/9fcae6572e9d474e131e64b639becf…
evtessentials.com -
twitter.com/liqingjia1989/status/1776779248524755435 · virustotal.com/gui/file/4dfe81aeb881c9e7cf0a469542d390…
bsdqcaptureman.com -
twitter.com/__0XYC__/status/1770689612031164671 · virustotal.com/gui/file/7525cecb3d45097db48ee08410ba2b…
libraofficeweb.com -
twitter.com/JVPv5sIM3eFmGyi/status/1765651279093612…
bartelemarks.com -
twitter.com/suyog41/status/1765296640028774450 · virustotal.com/gui/file/8b79f6b2061e3231da4ef75799ad97…
whitelilyshop.com
Further reading 588
- attack.mitre.org/groups/G1002
- blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-t…
- forcepoint.com/blog/x-labs/bitter-targeted-attack-agai…
- x.com/wa1Ile/status/1823643124562022487
- virustotal.com/gui/file/cc1c7e53ea567509a4bcfda2df95cb…
- virustotal.com/gui/file/14986da600df26fdb4e435cf01b6be…
- twitter.com/liqingjia1989/status/1742010387481121156
- x.com/StrikeReadyLabs/status/1808457407632224…
- virustotal.com/gui/file/575b783b3bd38271450a2c2cc8fb3a…
- virustotal.com/gui/file/d0ee008d3c480d5f9f75332851ae94…
- x.com/RedDrip7/status/1976923481377063382
- virustotal.com/gui/file/6cdc79edba95c6a9ec1d50457dc16f…
- virustotal.com/gui/ip-address/82.221.129.39/relations
- x.com/StrikeReadyLabs/status/1835445587149562…
- x.com/StrikeReadyLabs/status/1861383328521207…
- virustotal.com/gui/file/195682cc8a6318d3eb2af83faaff76…
- virustotal.com/gui/file/4e0824b6c9c4e53a7caeda78c8b60b…
- virustotal.com/gui/file/b3b2d915f47aa631cc4900ec56f9b8…
- virustotal.com/gui/file/7ea0930a332788c2e88e5822e4908d…
- twitter.com/JVPv5sIM3eFmGyi/status/1729760374960927…
- virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d…
- twitter.com/HONKONE_K/status/1297829657568407554
- twitter.com/binlmmhc/status/1555002494593679361
- virustotal.com/gui/file/528c6bf7c0c32be26bc1e32df73fed…
- twitter.com/liqingjia1989/status/1672792060007714816
- twitter.com/ginkgo_g/status/1598138502017085440
- virustotal.com/gui/file/ba352569428df4618cd57f91bd3479…
- virustotal.com/gui/file/dfedb0033337aaa8570ef682a93119…
- virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41…
- twitter.com/ginkgo_g/status/1746827915306909954
- twitter.com/RexorVc0/status/1727230322855833657
- x.com/RedDrip7/status/1964874030869332252
- virustotal.com/gui/file/09647fabb086acf09fdc72f3e8703c…
- twitter.com/malwrhunterteam/status/1408491293207154…
- twitter.com/lightC07379408/status/17069659360983904…
- twitter.com/liqingjia1989/status/1724011550825136526
- twitter.com/binlmmhc/status/1377080167881924608
- virustotal.com/gui/file/e6b523e77c31b89f8eb3489007bf14…
- x.com/ShadowChasing1/status/18246304068236782…
- virustotal.com/gui/file/8b57d6b676afdd84786655eb5fc876…
548 more, and the report behind every indicator, in G1002.json.