Overview 111 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| domain | 76 | UNC2596-domain.txt |
| ipv4 | 16 | UNC2596.json |
| url_path | 16 | UNC2596.json |
| url | 3 | UNC2596.json |
Principal sources 42 reports
Ranked by how many of this actor's indicators each report brought in.
- 22twitter.com/Joseliyo_Jstnk/status/16758035904626851…
- 22twitter.com/suyog41/status/1692424324874211646
- 22twitter.com/blackorbird/status/1694622415006105954
- 22blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-…
- 22explore.avertium.com/resource/two-microsoft-zero-day-vulnera…
- 22cert.gov.ua/article/5077168 (# UAC-0168)
- 22virustotal.com/gui/ip-address/213.139.204.173/relations
- 22virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2…
Timeline 111 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
welivesecurity.com/en/eset-research/update-winrar-tools-no…
campanole.com gohazeldale.com melamorri.com srlaptop.com -
community.emergingthreats.net/t/ruleset-update-summary-2024-11-26-v10…
1drv.us.com -
welivesecurity.com/en/eset-research/romcom-exploits-firefo…
correctiv.sbs cwise.store devolredir.com economistjournal.cloud journalctd.live redirconnectwise.cloud redircorrectiv.com redjournal.cloud -
blog.talosintelligence.com/uat-5647-romcom
domain adbefnts.dev domain adcreative.pictures domain apisolving.com domain copdaemi.top domain creativeadb.com domain devhubs.dev domain dnsresolver.online domain pos-st.top domain store-images.org domain wirelesszone.top url_path /ipns/k51qzi5uqu5dgn9wgsaxb7cfvinmk27eusoufaxrp8qd1ri5kamf41bg7gpydm url_path /k51qzi5uqu5dgn9wgsaxb7cfvinmk27eusoufaxrp8qd1ri5kamf41bg7gpydm -
unit42.paloaltonetworks.com/snipbot-romcom-malware-variant · app.validin.com/detail?find=185.225.74.94&type=ip4&ref_…
1drv.fileshare.direct adobe.cloudcreative.digital certifysop.com cethernet.com cloudcreative.digital dns-msn.com docstorage.link drv2ms.com drvmcprotect.com fastshare.click fileshare.direct ilogicflow.com linedrv.com mcprotect.cloud olminx.com publicshare.link sitepanel.top webtimeapi.com xeontime.com -
twitter.com/DmitriyMelikov/status/17219919584642051… · virustotal.com/gui/ip-address/201.174.21.202/relations · virustotal.com/gui/file/b9ea82bd961210c69cf1141321be73… · virustotal.com/gui/file/b595ed2252d82bbfea276d40615c4a…
ipv4 201.174.21.202:137 ipv4 201.174.21.202:139 ipv4 201.174.21.202:445 url http://201.174.21.202 url_path /abc/filename111111111111.url url_path /filename111111111111.url -
twitter.com/TLP_R3D/status/1705917480844120192 · trendmicro.com/en_us/research/23/j/void-rabisu-targets… · trendmicro.com/content/dam/trendmicro/global/en/resear… · virustotal.com/gui/ip-address/185.250.150.204/relations · virustotal.com/gui/ip-address/45.137.155.163/relations
budgetnews.org kayakahead.net mctelemetryzone.com pap-cut.com redditanalytics.pm speedymarker.com wplsummit.com -
twitter.com/TLP_R3D/status/1705917480844120192 · trendmicro.com/en_us/research/23/j/void-rabisu-targets… · trendmicro.com/content/dam/trendmicro/global/en/resear… · virustotal.com/gui/ip-address/185.250.150.204/relations · virustotal.com/gui/ip-address/45.137.155.163/relations
digitalsolutionstime.com netstaticsinformation.com wirelessvezion.com -
twitter.com/Joseliyo_Jstnk/status/16758035904626851… · twitter.com/suyog41/status/1692424324874211646 · twitter.com/blackorbird/status/1694622415006105954 · blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-… · explore.avertium.com/resource/two-microsoft-zero-day-vulnera… · cert.gov.ua/article/5077168 (# UAC-0168) · virustotal.com/gui/ip-address/213.139.204.173/relations · virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2… · virustotal.com/gui/file/a61b2eafcf39715031357df6b01e85… · virustotal.com/gui/file/ddf15e9ed54d18960c28fb9a058662… · virustotal.com/gui/file/6dc514b4b2090ddc852fc6ea62da09…
altimata.org bentaxworld.com dashboard.penofach.com penofach.com -
twitter.com/Joseliyo_Jstnk/status/16758035904626851… · twitter.com/suyog41/status/1692424324874211646 · twitter.com/blackorbird/status/1694622415006105954 · blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-… · explore.avertium.com/resource/two-microsoft-zero-day-vulnera… · cert.gov.ua/article/5077168 (# UAC-0168) · virustotal.com/gui/ip-address/213.139.204.173/relations · virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2… · virustotal.com/gui/file/a61b2eafcf39715031357df6b01e85… · virustotal.com/gui/file/ddf15e9ed54d18960c28fb9a058662… · virustotal.com/gui/file/6dc514b4b2090ddc852fc6ea62da09…
/MSHTML_C7 /MSHTML_C7/RFile.asp /MSHTML_C7/start.xml /MSHTML_C7/zip_k1.asp /MSHTML_C7/zip_k2.asp /MSHTML_C7/zip_k3.asp -
twitter.com/Joseliyo_Jstnk/status/16758035904626851… · twitter.com/suyog41/status/1692424324874211646 · twitter.com/blackorbird/status/1694622415006105954 · blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-… · explore.avertium.com/resource/two-microsoft-zero-day-vulnera… · cert.gov.ua/article/5077168 (# UAC-0168) · virustotal.com/gui/ip-address/213.139.204.173/relations · virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2… · virustotal.com/gui/file/a61b2eafcf39715031357df6b01e85… · virustotal.com/gui/file/ddf15e9ed54d18960c28fb9a058662… · virustotal.com/gui/file/6dc514b4b2090ddc852fc6ea62da09…
domain finformservice.com domain ukrainianworldcongress.info ipv4 104.234.239.26:137 ipv4 104.234.239.26:139 ipv4 104.234.239.26:445 ipv4 109.105.198.145:8080 ipv4 65.21.27.250:8080 url http://104.234.239.26 url http://74.50.94.156 url_path /mds/D-------------------------- url_path /mds/O-------------------------- url_path /mds/s-------------------------- -
twitter.com/TLP_R3D/status/1655687889391431680 · twitter.com/TLP_R3D/status/1655844785075224576 · twitter.com/TLP_R3D/status/1656270702700273666 · twitter.com/k3yp0d/status/1655840102638137347 · twitter.com/k3yp0d/status/1655841493934800896 · virustotal.com/gui/ip-address/104.234.10.207/relations · virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de… · virustotal.com/gui/file/1308146f161ed60c86532dd2d2de8d… · virustotal.com/gui/file/a5dae9b7ff88276f699eece44eb4b1…
15.235.203.250:444 -
twitter.com/TLP_R3D/status/1655687889391431680 · twitter.com/TLP_R3D/status/1655844785075224576 · twitter.com/TLP_R3D/status/1656270702700273666 · twitter.com/k3yp0d/status/1655840102638137347 · twitter.com/k3yp0d/status/1655841493934800896 · virustotal.com/gui/ip-address/104.234.10.207/relations · virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de… · virustotal.com/gui/file/1308146f161ed60c86532dd2d2de8d… · virustotal.com/gui/file/a5dae9b7ff88276f699eece44eb4b1…
domain rdp-devolutions.com domain startleague.net ipv4 2.57.90.16:7931 ipv4 217.195.153.39:7931 ipv4 46.246.98.15:7931 -
twitter.com/TLP_R3D/status/1655687889391431680 · twitter.com/TLP_R3D/status/1655844785075224576 · twitter.com/TLP_R3D/status/1656270702700273666 · twitter.com/k3yp0d/status/1655840102638137347 · twitter.com/k3yp0d/status/1655841493934800896 · virustotal.com/gui/ip-address/104.234.10.207/relations · virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de… · virustotal.com/gui/file/1308146f161ed60c86532dd2d2de8d… · virustotal.com/gui/file/a5dae9b7ff88276f699eece44eb4b1…
domain postnordpakker.com domain wexonlake.com ipv4 104.234.10.207:7931 url_path /itrdd/kcrs/ url_path /itrdd/kcrs/file1.txt url_path /itrdd/kcrs/file2.txt -
proofpoint.com/us/daily-ruleset-update-summary-20221104
keepas.org you-supported.com -
twitter.com/Unit42_Intel/status/1588199843981402114 · twitter.com/malware_traffic/status/1588211727891570…
wveeam.com -
cert.gov.ua/article/2394117 (Ukrainian) · virustotal.com/gui/file/c149474f97140c3381bda3ad2451f2…
domain 4qzm.com domain advanced-ip-scaner.com domain advanced-ip-scanners.com domain aspx.io domain gov.mil.ua.aspx.io domain mil.ua.aspx.io domain mill.co.ua domain notfiled.com domain ua.aspx.io ipv4 185.56.137.104:4444 ipv4 69.49.231.103:4444 ipv4 69.49.245.55:4444 -
unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius · otx.alienvault.com/pulse/62f36c89909d6b719ba8d340
combinedresidency.org optasko.com
Further reading 42
- virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de…
- proofpoint.com/us/daily-ruleset-update-summary-20221104
- virustotal.com/gui/ip-address/201.174.21.202/relations
- welivesecurity.com/en/eset-research/romcom-exploits-firefo…
- cert.gov.ua/article/5077168 (# UAC-0168)
- cert.gov.ua/article/2394117 (Ukrainian)
- community.emergingthreats.net/t/ruleset-update-summary-2024-11-26-v10…
- virustotal.com/gui/ip-address/104.234.10.207/relations
- virustotal.com/gui/ip-address/45.137.155.163/relations
- twitter.com/DmitriyMelikov/status/17219919584642051…
- virustotal.com/gui/file/3a3138c5add59d2172ad33bc6761f2…
- welivesecurity.com/en/eset-research/update-winrar-tools-no…
- virustotal.com/gui/file/6dc514b4b2090ddc852fc6ea62da09…
- virustotal.com/gui/ip-address/213.139.204.173/relations
- trendmicro.com/en_us/research/23/j/void-rabisu-targets…
- app.validin.com/detail?find=185.225.74.94&type=ip4&ref_…
- virustotal.com/gui/file/a61b2eafcf39715031357df6b01e85…
- twitter.com/TLP_R3D/status/1656270702700273666
- unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
- twitter.com/TLP_R3D/status/1705917480844120192
- blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-…
- virustotal.com/gui/file/b595ed2252d82bbfea276d40615c4a…
- twitter.com/k3yp0d/status/1655840102638137347
- virustotal.com/gui/file/1308146f161ed60c86532dd2d2de8d…
- twitter.com/suyog41/status/1692424324874211646
- trendmicro.com/content/dam/trendmicro/global/en/resear…
- virustotal.com/gui/file/ddf15e9ed54d18960c28fb9a058662…
- virustotal.com/gui/ip-address/185.250.150.204/relations
- twitter.com/Unit42_Intel/status/1588199843981402114
- virustotal.com/gui/file/b9ea82bd961210c69cf1141321be73…
- unit42.paloaltonetworks.com/snipbot-romcom-malware-variant
- twitter.com/malware_traffic/status/1588211727891570…
- virustotal.com/gui/file/a5dae9b7ff88276f699eece44eb4b1…
- blog.talosintelligence.com/uat-5647-romcom
- twitter.com/k3yp0d/status/1655841493934800896
- twitter.com/TLP_R3D/status/1655687889391431680
- virustotal.com/gui/file/c149474f97140c3381bda3ad2451f2…
- otx.alienvault.com/pulse/62f36c89909d6b719ba8d340
- twitter.com/blackorbird/status/1694622415006105954
- explore.avertium.com/resource/two-microsoft-zero-day-vulnera…
2 more, and the report behind every indicator, in UNC2596.json.