Group5

APT / EstatalG0043 ↗
Origen🇮🇷 Irã
Técnicas (MITRE ATT&CK)4
FuenteMITRE ATT&CK
0
También conocido como:G0043

Sobre el grupo

Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack.

Técnicas (MITRE ATT&CK) 4

Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.

Vulnerabilidades explotadas

Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.

Infraestructura conocida 163

Indicadores reales (C2, dominios, URLs y hashes) asociados al malware que usa este grupo. Fuente: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hashd7fea5f6217db6e04f75333a65a46cdfcc523c7f3ddc29cfaecb18cd8876ea98NjRATthreatfox
sha1_hashca868ac1e4f42282fb74865fc2f9edf38b052e4bNjRATthreatfox
md5_hash1cf8cce965f8f2089ce67ef811b29d13NjRATthreatfox
sha1_hash19dc42491a499830d7638933b5f457740ffce395NjRATthreatfox
sha256_hashd5c4983535d57d69fc6f8c09ff4a3838d6a61ac6b149de67b89c0c062968d9cdNjRATthreatfox
md5_hash1742ad51f743c9e518abec7fc6f9451bNjRATthreatfox
ip:port81.71.128.221:14149NjRATthreatfox
ip:port156.223.213.38:1177NjRATthreatfox
sha256_hash47fa97e2a70af9612d5c0a024ba4cce2163aacad465e8fc4bf6abe1bd98bbb88NanoCoremalwarebazaar
ip:port188.209.158.187:1177NjRATthreatfox
ip:port156.223.177.158:1177NjRATthreatfox
ip:port172.94.46.114:1012NjRATthreatfox
sha256_hashea9f1901741fb76ca5eb7f48415d33d4eb7bc6fa3f3d8a47aa3babe8c1376efdNanoCoremalwarebazaar
sha256_hashf634762210e39bf8b8f436b40ee1cb122431f5558f96465c9f2e01cd8856296dNanoCoremalwarebazaar
sha256_hashe946713a98d119096e00d3c536d74608269bc402e0af213ec77e874a17f3164aNanoCoremalwarebazaar
sha1_hashb5abd48cdb1d3f97418047505d5a32e03e694fe5NjRATthreatfox
md5_hash2a85f2e5876b278a7af9393483de455bNjRATthreatfox
sha256_hashbae4f4322d4c215be01990ad77275474f829ed7b3731703ed07946ab9d041413NjRATthreatfox
ip:port105.72.55.52:8080NjRATthreatfox
ip:port8.148.27.183:12050NjRATthreatfox
domainzenvyus.ddns.netNjRATthreatfox
domainfouad-94.myq-see.comNjRATthreatfox
domainjoaoszr3.ddns.netNjRATthreatfox
ip:port187.101.57.177:1177NjRATthreatfox
sha1_hashfd7ec45552919baf92c37cb17b533d5eedfe5758NjRATthreatfox
md5_hash01af93c099eda51a2b46fb2108fc1e2aNjRATthreatfox
sha256_hashf9ac08dc0d9d265ba44e7b256cc554cd9a741ca2a7e4dc01807376a90f8b1024NjRATthreatfox
ip:port8.148.23.144:12329NjRATthreatfox
sha256_hashb106b83f8537dd027ba91b3994e1990c0ad195cc8a6ad37115cf8627b21a8797NanoCoremalwarebazaar
sha1_hashc9b310129dfd8ca8fbe110012ebb62282b8e3360NjRATthreatfox

+163 indicadores en total. Míralos todos en la página de IOCs.

El grupo Group5 usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →