Overview 43 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| domain | 36 | UNC5174-domain.txt |
| ipv4 | 6 | UNC5174.json |
| url | 1 | UNC5174.json |
Principal sources 9 reports
Ranked by how many of this actor's indicators each report brought in.
- 22x.com/malwrhunterteam/status/1925919454099054…
- 22sysdig.com/blog/unc5174-chinese-threat-actor-vshell
- 22virustotal.com/gui/file/7cbcf84de28d4bc3b21773babe730c…
- 16x.com/nahamike01/status/2054046181211426947
- 4x.com/nahamike01/status/2041035954950230099
- 4virustotal.com/gui/file/44c3885cb5ae32059e201fd3f5b877…
- 4virustotal.com/gui/file/8225ced200725fcce20ce365c4bafc…
- 1x.com/smica83/status/2052693305176015087
Timeline 43 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/nahamike01/status/2054046181211426947
domain 9oogle.net domain goo9le.net domain goole-app.com domain jajal.goo9le.net domain l1.mo1vip.org domain mo1vip.org domain ws.9oogle.net domain ws.goo9le.net domain ws.goole-app.com domain ws.mo1vip.org domain ws.z2s.us domain z2s.us ipv4 5.199.166.4:8080 ipv4 5.199.166.4:8443 ipv4 5.199.166.4:8880 url http://5.199.166.4 -
x.com/smica83/status/2052693305176015087 · virustotal.com/gui/file/a78188a50f25e9b28f52c297dc4137…
84.32.22.130:65512 -
x.com/nahamike01/status/2041035954950230099 · virustotal.com/gui/file/44c3885cb5ae32059e201fd3f5b877… · virustotal.com/gui/file/8225ced200725fcce20ce365c4bafc…
domain l1.topayapp.org domain topayapp.org domain w1.topayapp.org ipv4 84.32.22.130:8848 -
x.com/malwrhunterteam/status/1925919454099054… · sysdig.com/blog/unc5174-chinese-threat-actor-vshell · virustotal.com/gui/file/7cbcf84de28d4bc3b21773babe730c…
domain apib.googlespays.com domain bootstrapcdn.fun domain btt.evil.gooogleasia.com domain c1oudf1are.com domain chmobank.com domain googlespays.com domain https.sex666vr.com domain huionepay.me domain javaw.virustotal.xyz domain ks.evil.gooogleasia.com domain lin.c1oudf1are.com domain lin.huionepay.me domain lin.telegrams.icu domain mcafeecdn.xyz domain mtls.sex666vr.com domain samsungcdn.com domain start.bootstrapcdn.fun domain telegrams.icu domain virustotal.xyz domain vs.gooogleasia.com domain wg.gooogleasia.com ipv4 124.221.120.25:2222
Further reading 9
- x.com/malwrhunterteam/status/1925919454099054…
- virustotal.com/gui/file/a78188a50f25e9b28f52c297dc4137…
- x.com/smica83/status/2052693305176015087
- virustotal.com/gui/file/44c3885cb5ae32059e201fd3f5b877…
- x.com/nahamike01/status/2054046181211426947
- x.com/nahamike01/status/2041035954950230099
- virustotal.com/gui/file/8225ced200725fcce20ce365c4bafc…
- sysdig.com/blog/unc5174-chinese-threat-actor-vshell
- virustotal.com/gui/file/7cbcf84de28d4bc3b21773babe730c…