APT_CyberCriminal_Campagin_.../2016/2016.07.07.UNVEILING_PATCHWORK/IOCs/IOCs.csv
2018-01-10 14:17:42 +08:00

14 KiB

1Indicator TypeFile NameFile HashIPURLMutexDescription
2IP Address212[.]129.13.110AutoIt script C2
3IP Address212[.]129.7.146IP address used to connect to the cloud decoy with
4IP Address45[.]43.192.172IP address used in the powershell script
5IP Address178[.]162.210.242Suspected IOC
6IP Address178[.]162.210.243Suspected IOC
7IP Address178[.]162.210.244Suspected IOC
8IP Address178[.]162.210.245Suspected IOC
9IP Address178[.]162.210.246Suspected IOC
10IP Address178[.]162.210.247Suspected IOC
11IP Address178[.]162.210.248Suspected IOC
12IP Address178[.]162.236.40Suspected IOC
13IP Address37[.]48.77.214Suspected IOC
14IP Address37[.]48.77.215Suspected IOC
15IP Address37[.]58.60.195Suspected IOC
16IP Address43[.]249.37.173Suspected IOC
17IP Address46[.]165.225.66Suspected IOC
18IP Address46[.]165.229.7Suspected IOC
19IP Address46[.]165.229.8Suspected IOC
20IP Address46[.]165.229.9Suspected IOC
21IP Address46[.]165.248.236Suspected IOC
22IP Address46[.]165.248.237Suspected IOC
23IP Address46[.]165.248.238Suspected IOC
24IP Address46[.]165.248.239Suspected IOC
25IP Address46[.]165.248.240Suspected IOC
26IP Address46[.]165.248.241Suspected IOC
27IP Address46[.]165.248.243Suspected IOC
28IP Address46[.]166.163.243Suspected IOC
29IP Address46[.]166.163.244Suspected IOC
30IP Address46[.]166.163.246Suspected IOC
31IP Address91[.]229.79.181Suspected IOC
32IP Address91[.]229.79.182Suspected IOC
33IP Address91[.]229.79.183Suspected IOC
34IP Address91[.]229.79.184Suspected IOC
35IP Address91[.]229.79.185Suspected IOC
36IP Address91[.]229.79.186Suspected IOC
37IP Address91[.]229.79.187Suspected IOC
38IP Address91[.]229.79.188Suspected IOC
39IP Address91[.]229.79.189Suspected IOC
40IP Address91[.]229.79.190Suspected IOC
41IP Address93[.]115.95.132Suspected IOC
42IP Address94[.]242.219.203Suspected IOC
43IP Address94[.]242.223.19Suspected IOC
44IP Address94[.]242.223.20Suspected IOC
45IP Address94[.]242.223.24Suspected IOC
46IP Address94[.]242.223.28Suspected IOC
47IP Address94[.]242.231.244Suspected IOC
48IP Address95[.]141.34.242Suspected IOC
49IP Address95[.]141.34.245Suspected IOC
50IP Address95[.]141.34.246Suspected IOC
51IP Address95[.]211.205.142Suspected IOC
52IP Address95[.]211.205.161Suspected IOC
53IP Address95[.]211.205.163Suspected IOC
54IP Address95[.]211.205.164Suspected IOC
55IP Address95[.]211.205.165Suspected IOC
56IP Address95[.]211.205.166Suspected IOC
57IP Address95[.]211.3.135Suspected IOC
58File Hashupsrv.exe076aa7f5f6a5bdd9acdee55c6e3de54e6e8d5fd6fe2a03c165a23861e315f3f5
59File Hash7zip.exe9dae4a24095b9a3870579a63c94c73fe8de205c70d95dfdb0dc9c87709215953
60File Hashsysvolinfo.exef5e4d5d5fde978968dce4db4120ecbb68898d5fdf55860e61058d91db29b7d91
61File Hashuplv1032.exe1da99f69735d203a3d52ff1bb2ede75fe69601259efa6c5a080024ddf9276297
62File Hashsysvolinfo.exe variant13b0f3b63ce276f8d30ac4f95b03485a6fe532754494f9848e875c460b121b28
63File HashUAC Bypasser607454369fa5d96fab6fec7a52a518eefed5136e4ebd4cfed238ccbb0f5b180f
64File Hash13_Five_Year_Plan_2016-20-1.ppsd44793b9584c9ca8a982a05bb6cfc06599e081c411f35f163fbd7eacad5eb584
65File Hashaeropower.pps7dd68cab710cd1e8f099f2d2d8b67d9c3f8cb113c9bb44ea4a08ee76d49ed19c
66File Hashaustralia_fonops_1.pps04c7f88f284c2466b4814bb02eefb4a02ac118a2d584ba9baec9c7af1fa1de7b
67File Hashaustralia_fonops_2.pps99a24d92f650faadc46c65bad65013cf3f1587a01f62f31aac20eb8864c21bee
68File Hashaviation_1.ppscdd540c01e25b3a7e122c9c01cfc1c7399ed65f3963ff20fa1685b4c504035ca
69File Hashaviation_2.pps4d041a1bfd8dda989faa6a5a37ba49f988478dadaa110cdf9a98002f12a4b931
70File Hashbeauty3.pps660b2d4baa7965acd7182bdbeaa8cdf66290968ecddc77d53517fe24882c95f9
71File Hashbeauty6.pps0819f50d7a0c045188c4068b88c915f3a652c073e3081cb30a20aaf6298840bd
72File HashCHINA_FEAR_US_3.pps905fe9820538943a4ad32499f9dad3eae6ff7677882ff2a39ef98a0147ae3dd1
73File HashCHINA_FEAR_US_6.ppsa335613dad36911f947fdfd3dda8897a71889513f9009385c84e48c2b7fe7236
74File Hashchinamilstrength.pps1f6108718ac9a29fe0e1e2d7fc2a7793ad4e20033921945c2ac0b5603e591298
75File HashChina_Response_NKorea_Nuclear_Test1.ppsc98caa28f5114e3c37efd59cb3c2471a4c64cca3ecd6188d5efe547f1cae0e9d
76File HashChina_Response_NKorea_Nuclear_Test2.ppsbbe27671b94d040342312431a24ebb4f9685ee950efeb526b1ffd765f3e7c7dd
77File Hashchinascyberarmy2015_1.ppsfdc6afccd5dc015c138c05ba7c325fc119dfd79e913ddab292575586f1657cae
78File Hashchinascyberarmy2015_2.pps8770819471130b056822c334f8735453c3fd7d3495ae5ad98d372241872be7c5
79File HashCHINA'S_PUZZLING_DEFENSE_AGREEMENT_WITH_AUSTRALIA_1.pps8cb2f737dd535f76e420fdcd747e5c943868c10b8f895722a298b83f331d728e
80File HashCHINA'S_PUZZLING_DEFENSE_AGREEMENT_WITH_AUSTRALIA_2.pps70d368e2a8bc7e5d0673dabe6d5897062dbc51103227a9e4efd38a09ee8a2042
81File HashChina_two_child_policy_will_underwhelm1.pps23d69451b4f7d9e3df5b92523e4574246bdfc786d48b20e9f0c45a25d985e191
82File HashChinaUS_1.ppsb9c24e26c90fd83ad8258a90b1c84022d180c0223f182f96c928333f2e9c5934
83File HashChinaUS_2.pps065321d0497565871bcfe5ee606636e9d0f2975558ee838122bbbe78ffd2d367
84File Hashchinesemilstrat_1.pps158919e9ca13db3747708b56397b63431ad864879abe1f5f3c4c178d8fae1149
85File Hashchinesemilstrat_2.pps6cb9b489f27517b21db61398cc103f863eb71e1034997e7f54b463be9c34568b
86File Hashcppcc_1.pps5e4dd3e3d21a25a2680320ad79ef773f133312210adcd45b09bfb183c5797004
87File Hashcppcc_2.pps04317dd251b6eb22ce0941dda9821463fe53a51140d4ac639b9d0463dbf61372
88File Hashelection.pps7ce893d1e08ef1ce62706eabe9aa0813e5e495d4f24955ca5020c3191968ec3a
89File Hashenggmarvels_1.pps79af494cfb231c267d3149d4922a16ea0086c4ba63b584e6ff8dc463235eb999
90File Hashenggmarvels_2.pps0803956f7919f3ac71f345a59c3803b0ab5e32e8f9c408b0eff0716a013c020d
91File Hashfengnew33.ppscaf046809672fa9b162ddb633f12f1c817c8aab42da994398135b0b2b5b2f01c
92File Hashfengnew36.ppse61a805907a44c61458baae92cb9a2bb901d76102fe94ae0a6ef287cf71fb4ae
93File Hashfengnew63.pps3e282a1cdcc692415998633af2a15d79dcfb2ce90734bf90138e9bd3e3c32f7f
94File Hashfengnew66.pps0edb3efd98de5d135f3326129a4d7a5546484570d9949e6103179a0e5e6b97dd
95File Hashfuturedrones_1.pps13f03f67d748ece55bcdd77373668e89d97c340f426aac5097817b6bb91c6844
96File Hashfuturedrones_2.pps43c1bee83e6f814a4028192f9f52fb89fea986815da43654ce991f06bbd48b5e
97File Hashgaokaonewschedule_1.ppsa725cf180706c6060f344ac8cecc1c23e90358a1170c61db7dd8a3be4d109e8b
98File Hashgaokaonewschedule_2.pps12ffc8454be5a73a894eea89d1617d256f0e65fe403a2c19558b3f484c7cbe03
99File Hashharbin_1.pps2c1a70bf43bd622201321e902982153f13414e2f42f0a17fad0e9d35ba8613f4
100File HashImplication_China_mil_reforms_1.pps97503d2302fc3b51f666f6d4ea067b499d185f807fb5a61cee49851d0417ade8
101File Hashjapan_pivot_1.pps887cc8220cd9722d114cf575f1cb7758c2e10f3d8904121dc9fe0b749c6955bb
102File Hashjapan_pivot_2.pps18af865435967f803a2b2cf8ef0ec1a859d6d9612a59c01a59c77d31fda9c91d
103File Hashjtopcentrecomn.pps7169ee156199b86e7149cb9c49a146b5d20afe02d90d315e00b3980419c41d14
104File Hashkorea1.pps1ea09eb00f49a92505c22f2f4569e035894cb765a8be87adcbc94c01a8d9d5c0
105File Hashmilitarizationofsouthchinasea_1.pps53a30dfd90bd1208dcfe534ccd0b798d629aa989ccaeae952384cfe9ecb17369
106File Hashmilitarizationofsouthchinasea_2.pps9d0d420c696083023300545754f0428549bb62f33c6e492eb4ace8ce95ce8af0
107File HashMilitaryReforms1.ppsccbbf41f7e385f511ec25925cdc177bb23a3106974fa1c61fdfea4af70489b36
108File HashMilitaryReforms2.pps09d7cd078a46a33750b002594eb7340af55a1cefe5f4451a8bdfcd6af97449bf
109File HashMilReforms_1.ppsc126471d35f0fcff4ebafd8fb331e328b67e07312fbaa60c8a131e318b41a839
110File HashMilReforms_2.ppsc2d39a5ed25caf84d5ce68375e420b6445aff0c63a7f820ae6a3d0e24eb5e161
111File Hashmy_lovely_pics_3.pps39cf8b7bbceac5d150cc9fafbf2d7492d353771ec40919d1777fba8d6d2da2b4
112File Hashmy_lovely_pics_6.ppscc810280206c3ee96f88840d6e23bd2c849bfb48f4e97c2ea1c8ef47ce06ba9b
113File Hashmy_photos_3.ppsb4487148d05bc4acc932b47c0a01371c459eea12fc7fd4f21af127dee2f619f4
114File Hashmy_photos_6.pps1c60523b5c2cfc176549d4a8c14c2759c504cce23da86cf3dcb99c21ddf30f5a
115File Hashnail_art_3.pps48219520a01ef9ec5f499cdb3f3ad8e9899b0c15800acb66cb0df5fe74f49cce
116File Hashnail_art_6.pps77a43ddd5b90b25b189f970ec76224085f7b7210922e611ed38905d4190d7cc3
117File Hashnetflix1.pps88e2e7df29450f673081161e105b561f67bba65ce00d12da90b26149c2960631
118File Hashnetflix2.pps2f6ed134adf8d29dd9e25b8f8f863389742dd5ff6d9104329c2fecb66b9e1604
119File HashObama_Gift_China_1.pps77b1ea1a200a17f8e14a8b6471ee6c4921c8c6b59026ce799ecaf7edd54b15e8
120File HashObama_Gift_China_2.pps21b2f9c134a8fe2f021884852b41eed5739c791a19f0145a5a665015cede543b
121File Hashpension_1.pps6b821ad306c9baa18b7d77a06bbbff032a55ba1bc4b7f93b747477facb8b8fa0
122File Hashstewardess1.ppsd4a9a07192ba6ddafe86ea8c72277650cc8996cd1ec487d3677d8a4e92e28983
123File Hashstewardess2.pps8869567e461c5fe15e4a2d66e28a04445eebf76a0fdc3fc98e3edca6f032e423
124File Hashsyria_china.pps53dc1535397fe9bdefd4d69bf8b22751668dfc1054713aab71b6048fbd23423a
125File HashTaiwanDiplomaticAccess_1.ppsda06b7ee42a7d2f0cf7dd5f225373806cd054b2a3b8fdbba7a0873479c98dfba
126File HashTaiwanDiplomaticAccess_2.ppseb31ffe6666d8307fa59da3d41a5bf0d9f936d909a5f955e0329ab24d64bce90
127File Hashtibetculture_1.ppseed9c5e8ec7d25a5c9f15d30d80413edf65ec4f495c3d244c9d55d134e0cccef
128File Hashtibetculture_2.ppsf9a9808927bccb8a08828b16cf288a89a1b0b67fe55055f5bbcd777fc312b4ce
129File HashunderestimatingUS_1.ppsa358679e2474750c0ae064590e80085035cdec6028c9025cf4dc48dd610de88e
130File HashunderestimatingUS_2.pps511111ebb818471c1402631494aade54f3d13b57eb9cc705392edb615153950d
131File HashUruguayJan-Jun_1o.pps637b305164ed634f4c20bcb89030417f9d41446e5c8517e671ef4c122195ccea
132File Hashuruguayjan-jun_1.ppsfe3f4bd9810389e68ead6d29270050275440281de0b78532ea9c71d9b3db41f6
133File HashUruguayJan-Jun_2o.pps5f203ea304b97727e6a607c54713da69925337ac1eff98c7761e184c33d37c4d
134File Hashuruguayjan-jun_2.ppsb9f0e2b6ca667cbabcec0c2cd311eefb831776c33ab679a109345507030b259d
135File HashUruguayJul-Dec_1o.pps66c946d8915c367ec23fedecaa730493d9df292d8b13fbdd56ffcda49a065ac2
136File Hashuruguayjul-dec_1.ppsa870b9b7d84bbb95da6dcb633f74731b316f4bc77bd71edc779928b71c1e5a4f
137File HashUruguayJul-Dec_2o.pps0abd0d44d12993124ba3081990342ea7d5ab75d1e639b60a4d02960ed2f54b66
138File Hashuruguayjul-dec_2.ppsaf826881bfead39e6319131359521502076a83d75f02ab2fd0754c5a82ab2f73
139File Hashus_srilanka_relations_1.pps665b6ffd8ada42e0a1e77a377970eec3b2b8a915d101c7888d1b28e86c80ebfa
140File Hashus_srilanka_relations_2.ppse01b1267f5c12291dbcbaa04fcd558b8f7415f11dfe0f2a4cdabe8e69277e52a
141File HashWILL_ISIS_INFECT_BANGLADESH.pps75f8073fa5f842a6ca78e27a703a6b0a30ecba3f9f51e23fcf810b2489db5fb5
142File Hashzodiac_1.pps53d6ae6e3f883f1e1ebc9e0b6bdbd8ec8dad344b0988fb4e28b17c19f7385e7e
143File Hashzodiac_2.pps55a5d4f879250dbe57523c7caf7fd55b7324043780dd697e9a8b7061500c8c85
144URLhttp://212[.]129.13.110/update-request.php?profile=Upload file link used in sysvolinfo.exe
145URLhttp://212[.]129.13.110/dropper.php?profile=C&C url used by sysvolinfo.exe
146URLhttp://cnmilit[.]comSpear phishing dropper
147URLhttp://t.ymlp50[.]com/jmyafaejshbafahshaaambmus/click.phpSpear phishing dropper
148URLmozarting[.]comSuspected IOC
149URLblingblingg[.]comSuspected IOC
150URLaaskmee[.]comSuspected IOC
151URLrevoltmax[.]comSuspected IOC
152URLeyescreem[.]comSuspected IOC
153URLoutlookkz[.]comSuspected IOC
154URLxmachinez[.]comSuspected IOC
155URLpizzahomez[.]comSuspected IOC
156URLnewsnstat[.]comSuspected IOC
157URL163-cn[.]orgSuspected IOC
158URLcnmilit[.]comSuspected IOC
159URL81-cn[.]netSuspected IOC
160URLclimaxcn[.]comSuspected IOC
161URLexpatchina[.]infoSuspected IOC
162URLmiltechweb[.]comSuspected IOC
163URLnduformation[.]comSuspected IOC
164URLsecurematrixx[.]comSuspected IOC
165URLxbladezz[.]comSuspected IOC
166URLasiandefnetwork[.]comSuspected IOC
167URLdailychina[.]newsSuspected IOC
168URLsinodefprog[.]infoSuspected IOC
169URLqqgroups[.]infoSuspected IOC
170URLchinastrat[.]comSuspected IOC
171URLmiltechcn[.]comSuspected IOC
172URLnumeronez[.]comSuspected IOC
173URLtelemediaz[.]comSuspected IOC
174URLmajidalfuttaiim[.]comSuspected IOC
175URLwebworldreq[.]comSuspected IOC
176URLnextraload[.]comSuspected IOC
177URLjunshiyuehui[.]comSuspected IOC
178URLcndailynetwork[.]infoSuspected IOC
179URLextrememachine[.]orgSuspected IOC
180URLwikifedia[.]spaceSuspected IOC
181URLyue-lao[.]infoSuspected IOC
182URLyou-yisi[.]comSuspected IOC
183URLannchenn[.]comSuspected IOC
184URLoffice-rb-support[.]comSuspected IOC
185URLgreatdexter[.]comSuspected IOC
186URLhaiwaipengyou[.]comSuspected IOC
187URLextremerebolt[.]comSuspected IOC
188URLmatrixrevolt[.]comSuspected IOC
189URLinfo81[.]comSuspected IOC
190URLchinastrats[.]comSuspected IOC
191URLepg-cn[.]comSuspected IOC
192URLnutcn[.]comSuspected IOC
193URLmodgovcn[.]comSuspected IOC
194URLclimaxcn[.]comSuspected IOC
195URLsocialfreakzz[.]comSuspected IOC
196URLmilitaryworkerscn[.]comSuspected IOC
197URLextremebolt[.]comSuspected IOC
198URLlujunxinxi[.]comSuspected IOC
199URLletsgetclose[.]comSuspected IOC
200URLmilresearchcn[.]comSuspected IOC
201URLalfred.ignorelist[.]comSuspected IOC
202URLsymantecz[.]comSuspected IOC
203URLnudtcn[.]comSuspected IOC
204Mutex{9754893678976458374658764387563876}Mutex used in 7zip.exe