Overview 17 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| ipv4 | 9 | UNC961.json |
| url | 8 | UNC961.json |
Principal sources 7 reports
Ranked by how many of this actor's indicators each report brought in.
- 17mandiant.com/resources/mobileiron-log4shell-exploita…
- 17mandiant.com/resources/blog/unc961-multiverse-financ…
- 17crowdstrike.com/blog/prophet-spider-exploits-citrix-sha…
- 17otx.alienvault.com/pulse/6244606893ddbc9a6a5bbdeb
- 17otx.alienvault.com/pulse/641c9c1ed12f8bb9ab022552
- 17virustotal.com/gui/file/1c26b4078c75e10420f5a556e25654…
- 17virustotal.com/gui/file/ec8fcc5f5bc33d9cbe3b1d14a2c39b…
Related groups 5
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 17 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
mandiant.com/resources/mobileiron-log4shell-exploita… · mandiant.com/resources/blog/unc961-multiverse-financ… · crowdstrike.com/blog/prophet-spider-exploits-citrix-sha… · otx.alienvault.com/pulse/6244606893ddbc9a6a5bbdeb · otx.alienvault.com/pulse/641c9c1ed12f8bb9ab022552 · virustotal.com/gui/file/1c26b4078c75e10420f5a556e25654… · virustotal.com/gui/file/ec8fcc5f5bc33d9cbe3b1d14a2c39b…
ipv4 107.181.187.184:443 ipv4 149.28.200.140:443 ipv4 149.28.71.70:443 ipv4 162.33.178.149:443 ipv4 185.172.129.215:443 ipv4 195.149.87.87:443 ipv4 34.102.54.152:443 ipv4 45.61.136.188:443 url http://107.181.187.184 url http://149.28.200.140 url http://149.28.71.70 url http://162.33.178.149 url http://185.172.129.215 url http://195.149.87.87 url http://34.102.54.152 url http://45.61.136.188 -
mandiant.com/resources/mobileiron-log4shell-exploita… · mandiant.com/resources/blog/unc961-multiverse-financ… · crowdstrike.com/blog/prophet-spider-exploits-citrix-sha… · otx.alienvault.com/pulse/6244606893ddbc9a6a5bbdeb · otx.alienvault.com/pulse/641c9c1ed12f8bb9ab022552 · virustotal.com/gui/file/1c26b4078c75e10420f5a556e25654… · virustotal.com/gui/file/ec8fcc5f5bc33d9cbe3b1d14a2c39b…
107.181.187.184:4242
Further reading 7
- otx.alienvault.com/pulse/6244606893ddbc9a6a5bbdeb
- otx.alienvault.com/pulse/641c9c1ed12f8bb9ab022552
- mandiant.com/resources/blog/unc961-multiverse-financ…
- crowdstrike.com/blog/prophet-spider-exploits-citrix-sha…
- virustotal.com/gui/file/1c26b4078c75e10420f5a556e25654…
- virustotal.com/gui/file/ec8fcc5f5bc33d9cbe3b1d14a2c39b…
- mandiant.com/resources/mobileiron-log4shell-exploita…