← All actors Recent activity

UNC2596

UNC2596 · CVE-2023-36884 · dustyhammock · meltingclaw · romcom · rustyclaw · shadyhammock · singlecamper · snipbot · uat-5647

Indicators
111
Source reports
42
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20222026

Overview 111 indicators

No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.

domain76UNC2596-domain.txt
ipv416UNC2596.json
url_path16UNC2596.json
url3UNC2596.json

Principal sources 42 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 111 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. or earlier 4 domainthis year

    welivesecurity.com/en/eset-research/update-winrar-tools-no…

    campanole.com
    gohazeldale.com
    melamorri.com
    srlaptop.com

  2. 1 domain2 yrs ago

    community.emergingthreats.net/t/ruleset-update-summary-2024-11-26-v10…

    1drv.us.com

  3. 8 domain2 yrs ago

    welivesecurity.com/en/eset-research/romcom-exploits-firefo…

    correctiv.sbs
    cwise.store
    devolredir.com
    economistjournal.cloud
    journalctd.live
    redirconnectwise.cloud
    redircorrectiv.com
    redjournal.cloud

  4. 10 domain, 2 url_path2 yrs ago

    blog.talosintelligence.com/uat-5647-romcom

    domainadbefnts.dev
    domainadcreative.pictures
    domainapisolving.com
    domaincopdaemi.top
    domaincreativeadb.com
    domaindevhubs.dev
    domaindnsresolver.online
    domainpos-st.top
    domainstore-images.org
    domainwirelesszone.top
    url_path/ipns/k51qzi5uqu5dgn9wgsaxb7cfvinmk27eusoufaxrp8qd1ri5kamf41bg7gpydm
    url_path/k51qzi5uqu5dgn9wgsaxb7cfvinmk27eusoufaxrp8qd1ri5kamf41bg7gpydm

  5. 19 domain2 yrs ago

    unit42.paloaltonetworks.com/snipbot-romcom-malware-variant · app.validin.com/detail?find=185.225.74.94&type=ip4&ref_…

    1drv.fileshare.direct
    adobe.cloudcreative.digital
    certifysop.com
    cethernet.com
    cloudcreative.digital
    dns-msn.com
    docstorage.link
    drv2ms.com
    drvmcprotect.com
    fastshare.click
    fileshare.direct
    ilogicflow.com
    linedrv.com
    mcprotect.cloud
    olminx.com
    publicshare.link
    sitepanel.top
    webtimeapi.com
    xeontime.com

  6. 3 ipv4, 1 url, 2 url_path3 yrs ago

    twitter.com/DmitriyMelikov/status/17219919584642051… · virustotal.com/gui/ip-address/201.174.21.202/relations · virustotal.com/gui/file/b9ea82bd961210c69cf1141321be73… · virustotal.com/gui/file/b595ed2252d82bbfea276d40615c4a…

    ipv4201.174.21.202:137
    ipv4201.174.21.202:139
    ipv4201.174.21.202:445
    urlhttp://201.174.21.202
    url_path/abc/filename111111111111.url
    url_path/filename111111111111.url

  7. 7 domain3 yrs ago

    twitter.com/TLP_R3D/status/1705917480844120192 · trendmicro.com/en_us/research/23/j/void-rabisu-targets… · trendmicro.com/content/dam/trendmicro/global/en/resear… · virustotal.com/gui/ip-address/185.250.150.204/relations · virustotal.com/gui/ip-address/45.137.155.163/relations

    budgetnews.org
    kayakahead.net
    mctelemetryzone.com
    pap-cut.com
    redditanalytics.pm
    speedymarker.com
    wplsummit.com

  8. 3 domain3 yrs ago

    twitter.com/TLP_R3D/status/1705917480844120192 · trendmicro.com/en_us/research/23/j/void-rabisu-targets… · trendmicro.com/content/dam/trendmicro/global/en/resear… · virustotal.com/gui/ip-address/185.250.150.204/relations · virustotal.com/gui/ip-address/45.137.155.163/relations

    digitalsolutionstime.com
    netstaticsinformation.com
    wirelessvezion.com

  9. 4 domain3 yrs ago

    twitter.com/Joseliyo_Jstnk/status/16758035904626851… · twitter.com/suyog41/status/1692424324874211646 · twitter.com/blackorbird/status/1694622415006105954 · blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-… · explore.avertium.com/resource/two-microsoft-zero-day-vulnera… · cert.gov.ua/article/5077168 (# UAC-0168) · virustotal.com/gui/ip-address/213.139.204.173/relations · virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2… · virustotal.com/gui/file/a61b2eafcf39715031357df6b01e85… · virustotal.com/gui/file/ddf15e9ed54d18960c28fb9a058662… · virustotal.com/gui/file/6dc514b4b2090ddc852fc6ea62da09…

    altimata.org
    bentaxworld.com
    dashboard.penofach.com
    penofach.com

  10. 6 url_path3 yrs ago

    twitter.com/Joseliyo_Jstnk/status/16758035904626851… · twitter.com/suyog41/status/1692424324874211646 · twitter.com/blackorbird/status/1694622415006105954 · blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-… · explore.avertium.com/resource/two-microsoft-zero-day-vulnera… · cert.gov.ua/article/5077168 (# UAC-0168) · virustotal.com/gui/ip-address/213.139.204.173/relations · virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2… · virustotal.com/gui/file/a61b2eafcf39715031357df6b01e85… · virustotal.com/gui/file/ddf15e9ed54d18960c28fb9a058662… · virustotal.com/gui/file/6dc514b4b2090ddc852fc6ea62da09…

    /MSHTML_C7
    /MSHTML_C7/RFile.asp
    /MSHTML_C7/start.xml
    /MSHTML_C7/zip_k1.asp
    /MSHTML_C7/zip_k2.asp
    /MSHTML_C7/zip_k3.asp

  11. 2 domain, 5 ipv4, 2 url, 3 url_path3 yrs ago

    twitter.com/Joseliyo_Jstnk/status/16758035904626851… · twitter.com/suyog41/status/1692424324874211646 · twitter.com/blackorbird/status/1694622415006105954 · blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-… · explore.avertium.com/resource/two-microsoft-zero-day-vulnera… · cert.gov.ua/article/5077168 (# UAC-0168) · virustotal.com/gui/ip-address/213.139.204.173/relations · virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2… · virustotal.com/gui/file/a61b2eafcf39715031357df6b01e85… · virustotal.com/gui/file/ddf15e9ed54d18960c28fb9a058662… · virustotal.com/gui/file/6dc514b4b2090ddc852fc6ea62da09…

    domainfinformservice.com
    domainukrainianworldcongress.info
    ipv4104.234.239.26:137
    ipv4104.234.239.26:139
    ipv4104.234.239.26:445
    ipv4109.105.198.145:8080
    ipv465.21.27.250:8080
    urlhttp://104.234.239.26
    urlhttp://74.50.94.156
    url_path/mds/D--------------------------
    url_path/mds/O--------------------------
    url_path/mds/s--------------------------

  12. 1 ipv43 yrs ago

    twitter.com/TLP_R3D/status/1655687889391431680 · twitter.com/TLP_R3D/status/1655844785075224576 · twitter.com/TLP_R3D/status/1656270702700273666 · twitter.com/k3yp0d/status/1655840102638137347 · twitter.com/k3yp0d/status/1655841493934800896 · virustotal.com/gui/ip-address/104.234.10.207/relations · virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de… · virustotal.com/gui/file/1308146f161ed60c86532dd2d2de8d… · virustotal.com/gui/file/a5dae9b7ff88276f699eece44eb4b1…

    15.235.203.250:444

  13. 2 domain, 3 ipv43 yrs ago

    twitter.com/TLP_R3D/status/1655687889391431680 · twitter.com/TLP_R3D/status/1655844785075224576 · twitter.com/TLP_R3D/status/1656270702700273666 · twitter.com/k3yp0d/status/1655840102638137347 · twitter.com/k3yp0d/status/1655841493934800896 · virustotal.com/gui/ip-address/104.234.10.207/relations · virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de… · virustotal.com/gui/file/1308146f161ed60c86532dd2d2de8d… · virustotal.com/gui/file/a5dae9b7ff88276f699eece44eb4b1…

    domainrdp-devolutions.com
    domainstartleague.net
    ipv42.57.90.16:7931
    ipv4217.195.153.39:7931
    ipv446.246.98.15:7931

  14. 2 domain, 1 ipv4, 3 url_path3 yrs ago

    twitter.com/TLP_R3D/status/1655687889391431680 · twitter.com/TLP_R3D/status/1655844785075224576 · twitter.com/TLP_R3D/status/1656270702700273666 · twitter.com/k3yp0d/status/1655840102638137347 · twitter.com/k3yp0d/status/1655841493934800896 · virustotal.com/gui/ip-address/104.234.10.207/relations · virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de… · virustotal.com/gui/file/1308146f161ed60c86532dd2d2de8d… · virustotal.com/gui/file/a5dae9b7ff88276f699eece44eb4b1…

    domainpostnordpakker.com
    domainwexonlake.com
    ipv4104.234.10.207:7931
    url_path/itrdd/kcrs/
    url_path/itrdd/kcrs/file1.txt
    url_path/itrdd/kcrs/file2.txt

  15. 2 domain3 yrs ago

    proofpoint.com/us/daily-ruleset-update-summary-20221104

    keepas.org
    you-supported.com

  16. 1 domain4 yrs ago

    twitter.com/Unit42_Intel/status/1588199843981402114 · twitter.com/malware_traffic/status/1588211727891570…

    wveeam.com

  17. 9 domain, 3 ipv44 yrs ago

    cert.gov.ua/article/2394117 (Ukrainian) · virustotal.com/gui/file/c149474f97140c3381bda3ad2451f2…

    domain4qzm.com
    domainadvanced-ip-scaner.com
    domainadvanced-ip-scanners.com
    domainaspx.io
    domaingov.mil.ua.aspx.io
    domainmil.ua.aspx.io
    domainmill.co.ua
    domainnotfiled.com
    domainua.aspx.io
    ipv4185.56.137.104:4444
    ipv469.49.231.103:4444
    ipv469.49.245.55:4444

  18. 2 domain4 yrs ago

    unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius · otx.alienvault.com/pulse/62f36c89909d6b719ba8d340

    combinedresidency.org
    optasko.com

Further reading 42

2 more, and the report behind every indicator, in UNC2596.json.