{
  "aliases": [
    "lodeinfo",
    "mirrorstealer"
  ],
  "attack_id": "G1054",
  "attack_name": "MirrorFace",
  "attack_url": "https://attack.mitre.org/groups/G1054/",
  "counts": {
    "domain": 2,
    "ipv4": 17,
    "url": 3
  },
  "first_seen": {
    "domain": {
      "aesorunwe.com": "2022-12-15",
      "ninesmn.com": "2022-12-15"
    },
    "ipv4": {
      "104.238.149.37:3389": "2024-12-01",
      "108.160.138.20:3389": "2024-12-01",
      "139.180.197.13:3389": "2024-12-01",
      "149.28.31.17:3389": "2024-12-01",
      "167.179.105.29:3389": "2024-12-01",
      "198.13.51.211:3389": "2024-12-01",
      "198.13.55.8:3389": "2024-12-01",
      "207.148.104.176:3389": "2024-12-01",
      "43.224.34.61:3389": "2024-12-01",
      "45.32.14.107:3389": "2024-12-01",
      "45.32.18.42:3389": "2024-12-01",
      "45.76.193.104:3389": "2024-12-01",
      "45.76.202.254:3389": "2024-12-01",
      "45.76.202.98:3389": "2024-12-01",
      "45.76.97.113:3389": "2024-12-01",
      "45.77.28.195:3389": "2024-12-01",
      "45.77.29.108:3389": "2024-12-01"
    },
    "url": {
      "http://167.179.116.56": "2022-12-15",
      "http://172.105.217.233": "2022-12-15",
      "http://45.32.13.180": "2022-12-15"
    }
  },
  "first_seen_precision": {
    "domain": {},
    "ipv4": {},
    "url": {}
  },
  "first_seen_range": {
    "earliest": "2022-12-15",
    "latest": "2024-12-01"
  },
  "generated_at": "2026-08-08T03:26:30+00:00",
  "indicators": {
    "domain": [
      "aesorunwe.com",
      "ninesmn.com"
    ],
    "ipv4": [
      "104.238.149.37:3389",
      "108.160.138.20:3389",
      "139.180.197.13:3389",
      "149.28.31.17:3389",
      "167.179.105.29:3389",
      "198.13.51.211:3389",
      "198.13.55.8:3389",
      "207.148.104.176:3389",
      "43.224.34.61:3389",
      "45.32.14.107:3389",
      "45.32.18.42:3389",
      "45.76.193.104:3389",
      "45.76.202.254:3389",
      "45.76.202.98:3389",
      "45.76.97.113:3389",
      "45.77.28.195:3389",
      "45.77.29.108:3389"
    ],
    "url": [
      "http://167.179.116.56",
      "http://172.105.217.233",
      "http://45.32.13.180"
    ]
  },
  "last_modified": "2026-01-02T23:10:15+00:00",
  "maltrail_groups": [
    "MIRRORFACE"
  ],
  "references": [
    "https://otx.alienvault.com/pulse/639b01a88df8698311dc2b43",
    "https://search.censys.io/search?q=services.tls.certificates.leaf_data.subject_dn%3D%22CN%3DDESKTOP-QKVE59Z%22&resource=hosts",
    "https://therecord.media/china-linked-hackers-tasked-with-japanese-targets-pursue-through-europe",
    "https://www.virustotal.com/gui/file/a8ec766eee6cc3c6416519f8407ac534f088637ed1a6bc05ed0596d8a0237548/detection",
    "https://www.virustotal.com/gui/file/f53c5fd78000755ccfff11d2f1b7d659f4a71c887083697d54b8fe8cf905ef6a/detection",
    "https://www.virustotal.com/gui/ip-address/167.179.116.56/relations",
    "https://www.virustotal.com/gui/ip-address/172.105.217.233/relations",
    "https://www.welivesecurity.com/2022/12/14/unmasking-mirrorface-operation-liberalface-targeting-japanese-political-entities/",
    "https://x.com/780thC/status/1856027964112044127",
    "https://x.com/pancak3lullz/status/1862959850180804935",
    "https://x.com/pancak3lullz/status/1863005095375319345"
  ],
  "related": [
    {
      "evidence": [
        {
          "detail": "shares nbtstat",
          "kind": "software",
          "weight": 0.5
        }
      ],
      "slug": "G0010"
    },
    {
      "evidence": [
        {
          "detail": "shares UPPERCUT",
          "kind": "software",
          "weight": 0.5
        }
      ],
      "slug": "G0045"
    },
    {
      "evidence": [
        {
          "detail": "shares Nltest",
          "kind": "software",
          "weight": 0.5
        }
      ],
      "slug": "G1006"
    },
    {
      "evidence": [
        {
          "detail": "shares Wevtutil",
          "kind": "software",
          "weight": 0.333
        }
      ],
      "slug": "G0007"
    },
    {
      "evidence": [
        {
          "detail": "shares Wevtutil",
          "kind": "software",
          "weight": 0.333
        }
      ],
      "slug": "G0129"
    }
  ],
  "slug": "G1054",
  "timeline": [
    {
      "counts": {
        "ipv4": 17
      },
      "first_seen": "2024-12-01",
      "indicators": {
        "ipv4": [
          "104.238.149.37:3389",
          "108.160.138.20:3389",
          "139.180.197.13:3389",
          "149.28.31.17:3389",
          "167.179.105.29:3389",
          "198.13.51.211:3389",
          "198.13.55.8:3389",
          "207.148.104.176:3389",
          "43.224.34.61:3389",
          "45.32.14.107:3389",
          "45.32.18.42:3389",
          "45.76.193.104:3389",
          "45.76.202.254:3389",
          "45.76.202.98:3389",
          "45.76.97.113:3389",
          "45.77.28.195:3389",
          "45.77.29.108:3389"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/780thC/status/1856027964112044127",
        "https://x.com/pancak3lullz/status/1862959850180804935",
        "https://x.com/pancak3lullz/status/1863005095375319345",
        "https://therecord.media/china-linked-hackers-tasked-with-japanese-targets-pursue-through-europe",
        "https://search.censys.io/search?q=services.tls.certificates.leaf_data.subject_dn%3D%22CN%3DDESKTOP-QKVE59Z%22&resource=hosts"
      ],
      "total": 17
    },
    {
      "counts": {
        "domain": 2,
        "url": 3
      },
      "first_seen": "2022-12-15",
      "indicators": {
        "domain": [
          "aesorunwe.com",
          "ninesmn.com"
        ],
        "url": [
          "http://167.179.116.56",
          "http://172.105.217.233",
          "http://45.32.13.180"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.welivesecurity.com/2022/12/14/unmasking-mirrorface-operation-liberalface-targeting-japanese-political-entities/",
        "https://otx.alienvault.com/pulse/639b01a88df8698311dc2b43",
        "https://www.virustotal.com/gui/ip-address/167.179.116.56/relations",
        "https://www.virustotal.com/gui/ip-address/172.105.217.233/relations",
        "https://www.virustotal.com/gui/file/f53c5fd78000755ccfff11d2f1b7d659f4a71c887083697d54b8fe8cf905ef6a/detection",
        "https://www.virustotal.com/gui/file/a8ec766eee6cc3c6416519f8407ac534f088637ed1a6bc05ed0596d8a0237548/detection"
      ],
      "total": 5
    }
  ]
}
