Overview 34 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| domain | 23 | Q27-domain.txt |
| ipv4 | 5 | Q27.json |
| url_path | 5 | Q27.json |
| url | 1 | Q27.json |
Principal sources 14 reports
Ranked by how many of this actor's indicators each report brought in.
- 16news.sophos.com/en-us/2023/05/03/doubled-dll-sideloadin…
- 16github.com/sophoslabs/IoCs/blob/master/double-drag…
- 7x.com/askardyuss/status/2066859258130665974
- 7virustotal.com/gui/file/0010762b4b1361aa9bc66892021869…
- 4x.com/malwrhunterteam/status/1995568662284022…
- 4virustotal.com/gui/file/873ea83b3507d8391b1b66f0f3d57c…
- 4virustotal.com/gui/file/b941c271b016f482137022b3da58e5…
- 3x.com/malwrhunterteam/status/2002322293091901…
Timeline 34 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/askardyuss/status/2066859258130665974 · virustotal.com/gui/file/0010762b4b1361aa9bc66892021869…
domain api.keensie.com ipv4 35.78.126.246:5198 url_path /snapshothelper/Helper.dat url_path /snapshothelper/SnapshotHelper.exe url_path /snapshothelper/VideoNativeForViews.dll url_path /snapshothelper/he.txt url_path /snapshothelper/image.jpg -
x.com/malwrhunterteam/status/2002322293091901… · cyberpress.org/apt-q-27-evades-corporate-defenses · virustotal.com/gui/file/14d374ea0604f70e6f39306efd948e…
domain yy-service.s3.ap-northeast-2.amazonaws.com domain yyupdats.s3.ap-southeast-1.amazonaws.com ipv4 143.92.57.46:15628 -
x.com/smica83/status/2012523844196544813 · tria.ge/260117-sjqyhafw7g/behavioral1
links3s.s3.ap-east-1.amazonaws.com s3work08.s3.ap-east-1.amazonaws.com -
x.com/malwrhunterteam/status/1995568662284022… · virustotal.com/gui/file/873ea83b3507d8391b1b66f0f3d57c… · virustotal.com/gui/file/b941c271b016f482137022b3da58e5…
domain datareportnew.s3.ap-northeast-2.amazonaws.com domain goldeyeuu.io domain uu.goldeyeuu.io ipv4 185.135.79.196:5188 -
x.com/WabiSabi777_/status/2009238999190392969 · virustotal.com/gui/file/01268d68f1726a31e881515bd70139…
domain wk.goldeyeuu.io ipv4 185.135.79.200:5188 -
news.sophos.com/en-us/2023/05/03/doubled-dll-sideloadin… · github.com/sophoslabs/IoCs/blob/master/double-drag…
domain 123.nsjdhmdjs.com domain 2.nsjdhmdjs.com domain 2.potatouu.com domain a.pic447.com domain ac2.nsjdhmdjs.com domain d.pic447.com domain l.pic447.com domain l2.pic447.com domain nsjdhmdjs.com domain potatouu.com domain t.pic447.com domain v.pic447.com domain v2.pic447.com domain w.pic447.com ipv4 206.233.128.103:443 url http://206.233.128.103
Further reading 14
- tria.ge/260117-sjqyhafw7g/behavioral1
- x.com/smica83/status/2012523844196544813
- x.com/WabiSabi777_/status/2009238999190392969
- x.com/malwrhunterteam/status/2002322293091901…
- virustotal.com/gui/file/14d374ea0604f70e6f39306efd948e…
- x.com/malwrhunterteam/status/1995568662284022…
- virustotal.com/gui/file/0010762b4b1361aa9bc66892021869…
- virustotal.com/gui/file/01268d68f1726a31e881515bd70139…
- x.com/askardyuss/status/2066859258130665974
- virustotal.com/gui/file/873ea83b3507d8391b1b66f0f3d57c…
- cyberpress.org/apt-q-27-evades-corporate-defenses
- news.sophos.com/en-us/2023/05/03/doubled-dll-sideloadin…
- github.com/sophoslabs/IoCs/blob/master/double-drag…
- virustotal.com/gui/file/b941c271b016f482137022b3da58e5…