Group5

APT / StateG0043
Origin🇮🇷 Irã
Techniques (MITRE ATT&CK)4
SourceMITRE ATT&CK
0
Also known as:G0043

Vexday analysis

Grupo de ameaça com suposta origem iraniana — embora a atribuição não seja definitiva —, o Group5 (identificador MITRE ATT&CK G0043) tem como alvo indivíduos ligados à oposição síria, utilizando spearphishing e ataques de watering hole com temas sírios e iranianos como isca. O grupo emprega ferramentas de acesso remoto amplamente disponíveis, incluindo njRAT, NanoCore e o RAT para Android DroidJack. Ao todo, são documentadas 4 técnicas no framework MITRE ATT&CK associadas a este agente.

Techniques (MITRE ATT&CK) 4

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 80

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port2.56.165.157:991NjRATthreatfox
ip:port47.122.115.225:13152NjRATthreatfox
ip:port129.208.124.105:1177NjRATthreatfox
sha256_hash33211c0e7a7b9545c13addcd452b68ab0f72b2d5fad857a7a3dd75c34a3fff09njratmalwarebazaar
ip:port47.122.116.54:13676NjRATthreatfox
sha256_hashbf5fb2be03196a2931ed05489bcd245fabaa63ecd4ba67eee64af468c12f6148NanoCoremalwarebazaar
sha256_hash24f100f0064fceabca8917f51631a4a987dc20cea19dda11d11f773534c54c8eNanoCoremalwarebazaar
sha256_hash9bf266d90d33000f52e6d46a6329a4b85c9477180b8eb20f840a0852bf3e9814NanoCoremalwarebazaar
sha1_hash70c24a2bb97c0b995bce9c7cee42d1cc856d177bNjRATthreatfox
md5_hashac061db892ad8cd21a565996bdb33d5cNjRATthreatfox
sha256_hash135732f938ca6b6e1fd1974ba172665d3c474b5346e035ea24c37b03500fb4e9NjRATthreatfox
sha256_hash135732f938ca6b6e1fd1974ba172665d3c474b5346e035ea24c37b03500fb4e9njratmalwarebazaar
sha256_hash50c73ca933a5d95e73a74b83d62084c85ad3f8acd39af2d218763a9270825dc2NanoCoremalwarebazaar
md5_hashb9fbf6f35099d3dd0f984ffb7e027b35NjRATthreatfox
sha1_hash2f6e93b860cef097c863668b1f38a6f7088bcb77NjRATthreatfox
sha256_hash06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075eNjRATthreatfox
ip:port82.102.219.33:1177NjRATthreatfox
ip:port188.212.158.102:1177NjRATthreatfox
ip:port188.48.226.49:1177NjRATthreatfox
ip:port103.233.194.35:1177NjRATthreatfox
sha256_hash03d2e8ef968a70c032ffb01c98b29ab612ae48043b44e63d15c2504f7f85de13NjRATthreatfox
md5_hash0f74892809973a93321c7ba05bdf61caNjRATthreatfox
sha1_hashd0b31bfd1d8e40efc3b3b30c1cf9b655c9365935NjRATthreatfox
sha1_hashb65b3aba7086a8db3b452f171782af7eab4cbeb5NjRATthreatfox
md5_hashcee0e495adc06bbac4be33544bd393caNjRATthreatfox
sha256_hashe95766d2d9dcc598cada3c33133935fda7d54d245d8a46fc05be47986e036fffNjRATthreatfox
ip:port45.154.207.60:5763NjRATthreatfox
md5_hash69d0de9e78ec99497182dcb635a1c610NjRATthreatfox
sha256_hash91009d9f4544faf57503ca3d5b83038d9e861f086c3c00fd703b3190ab7e1787NjRATthreatfox
sha1_hashda567ab609c3fb5f2cbf9e85e09d7668c7d0384cNjRATthreatfox

+80 indicators in total. See them all on the IOCs page.

Group5 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →