Skip to content

Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.

License

Notifications You must be signed in to change notification settings

RedDrip7/APT_Digital_Weapon

Folders and files

NameName
Last commit message
Last commit date

Latest commit

b338abc · Mar 24, 2025

History

55 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Copyright © @RedDrip (https://ti.qianxin.com/)

Here are indicators of compromise (IOCs) collected from public resources and our own investigations. Details include sample hash, file type, malware family, as well as first seen and file name from VirusTotal in format below:

Hash Type Family First_Seen Name
8e2b5b95980cf52e99acfa95f5e1570b Win32 DLL 2019-11-11 15:22:00 C:\Users<USER>\AppData\Local\Temp~$doc-ad9b812a-88b2-454c-989f-7bb5fe98717e.ole
3c3b2cc9ff5d7030fb01496510ac75f2 DOC 2019-11-11 11:13:02 ?-????2019?????????????????.doc
3a8c80d73f9beebd828c3aa172c747fa RAR 2019-11-07 01:23:39 Noi dung don cau cuu.rar
82990e2c0432e579a00ab1f75da0dd65 TXT 2019-10-26 11:05:08 lang.ps1
a87ada040f7250b59910345ee0b339b4 RAR 2019-10-23 09:20:16 Thu moi.rar
dbdbcd220475678c4becdc57a9233e20 Win32 EXE 2019-10-18 07:28:19 AcroRd32.exe
e7de9a64266f07168def534852349957 RAR Kryptik 2019-09-16 00:18:57 Don khieu nai.rar
90c66c76095ef1ad5a79e63a544c1bba Win32 DLL Kryptik 2019-09-13 06:02:21 123456

We will keep updating this project and hope this could help the security community to fight against malware and targeted attack.

If you find an error, please contact us at [email protected] and we’ll try to improve the IOCs.

Groupname Total Update data
APT-Q-63 5 4 2025-03-21
APT28 751 4 2025-03-21
APT29 455 11 2025-03-21
APT33 157 34 2025-03-21
APT34 151 2 2025-03-21
APT35 1 1 2025-03-21
APT37 157 9 2025-03-21
Bloody Wolf 5 5 2025-03-21
C-Major 617 67 2025-03-21
Confucius 169 1 2025-03-21
Contagious Interview 48 4 2025-03-21
DarkGaboon 99 99 2025-03-21
Donot 438 10 2025-03-21
dragonforce 3 3 2025-03-21
Earth Minotaur 18 18 2025-03-21
EarthEstries 18 2 2025-03-21
EncryptHub 17 17 2025-03-21
FaceDuck Group 2480 13 2025-03-21
FIN7 550 2 2025-03-21
Gamaredon Group 547 27 2025-03-21
Ghostwriter 28 9 2025-03-21
Inception Framework 9 4 2025-03-21
InvisiMole 9 4 2025-03-21
Kimsuky 310 56 2025-03-21
KONNI 148 15 2025-03-21
Lazarus Group 1828 2 2025-03-21
MuddyWater 311 5 2025-03-21
Nobelium 19 18 2025-03-21
OceanLotus 1143 111 2025-03-21
Operation SideCopy 41 23 2025-03-21
PatchWork 1220 21 2025-03-21
ref7707 16 16 2025-03-21
Sandworm 54 49 2025-03-21
Sidewinder 143 32 2025-03-21
Turla 446 14 2025-03-21
UAC 82 23 2025-03-21
UAC-0006 30 30 2025-03-21
UAC-0063 9 9 2025-03-21
UAC-0099 29 6 2025-03-21

About

Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published