Overview 32 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| domain | 27 | SOBAKEN-domain.txt |
| url | 5 | SOBAKEN.json |
Principal sources 13 reports
Ranked by how many of this actor's indicators each report brought in.
- 12welivesecurity.com/wp-content/uploads/2018/07/ESET_Quasar_…
- 9malpedia.caad.fkie.fraunhofer.de/details/win.vermin
- 9cert.gov.ua/article/37815 (Ukrainian)
- 9virustotal.com/gui/file/621b0d5a0c91b1d90588b78bc04fa9…
- 7cert.gov.ua/article/6280422
- 7virustotal.com/gui/ip-address/171.22.120.50/relations
- 7virustotal.com/gui/ip-address/91.225.219.185/relations
- 7virustotal.com/gui/ip-address/94.232.249.88/relations
Timeline 32 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/smica83/status/1950515843110154388 · x.com/JAMESWT_WT/status/1950522465068720460 · virustotal.com/gui/file/076edddf05a35a150d4e973eca9e7a…
aeroua.online gw.telegrarn.fun telegrarn.fun ukr.somee.com -
cert.gov.ua/article/6280422 · virustotal.com/gui/ip-address/171.22.120.50/relations · virustotal.com/gui/ip-address/91.225.219.185/relations · virustotal.com/gui/ip-address/94.232.249.88/relations · virustotal.com/gui/file/b474e4db82023d913a00b6c127e1ba… · virustotal.com/gui/file/250f49264ff06c39f2222d4d7e7368…
aviasys.somee.com code.ukraero.space firma.ukraero.space mail.ukraero.space -
cert.gov.ua/article/6280422 · virustotal.com/gui/ip-address/171.22.120.50/relations · virustotal.com/gui/ip-address/91.225.219.185/relations · virustotal.com/gui/ip-address/94.232.249.88/relations · virustotal.com/gui/file/b474e4db82023d913a00b6c127e1ba… · virustotal.com/gui/file/250f49264ff06c39f2222d4d7e7368…
domain prozorro.online domain ukraero.space url http://171.22.120.50 -
malpedia.caad.fkie.fraunhofer.de/details/win.vermin · cert.gov.ua/article/37815 (Ukrainian) · virustotal.com/gui/file/621b0d5a0c91b1d90588b78bc04fa9…
domain getmod.host domain meteolink.host domain netbin.host domain stormpredictor.host domain syncapp.host url http://176.119.2.194 url http://176.119.2.195 url http://176.119.2.212 url http://176.119.2.214 -
welivesecurity.com/wp-content/uploads/2018/07/ESET_Quasar_…
akamaicdn.ru akamainet021.info akamainet022.info akamainet023.info akamainet024.info akamainet066.info akamainet067.info cdnakamai.ru mailukr.net notifymail.ru tech-adobe.dyndns.biz windowsupdate.kiev.ua
Further reading 13
- virustotal.com/gui/ip-address/94.232.249.88/relations
- virustotal.com/gui/ip-address/91.225.219.185/relations
- virustotal.com/gui/ip-address/171.22.120.50/relations
- malpedia.caad.fkie.fraunhofer.de/details/win.vermin
- virustotal.com/gui/file/076edddf05a35a150d4e973eca9e7a…
- virustotal.com/gui/file/621b0d5a0c91b1d90588b78bc04fa9…
- virustotal.com/gui/file/250f49264ff06c39f2222d4d7e7368…
- x.com/smica83/status/1950515843110154388
- x.com/JAMESWT_WT/status/1950522465068720460
- virustotal.com/gui/file/b474e4db82023d913a00b6c127e1ba…
- cert.gov.ua/article/6280422
- cert.gov.ua/article/37815 (Ukrainian)
- welivesecurity.com/wp-content/uploads/2018/07/ESET_Quasar_…