Sobre el grupo
Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack.
Técnicas (MITRE ATT&CK) 4
Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.
Vulnerabilidades explotadas
Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.
Infraestructura conocida 163
Indicadores reales (C2, dominios, URLs y hashes) asociados al malware que usa este grupo. Fuente: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
d7fea5f6217db6e04f75333a65a46cdfcc523c7f3ddc29cfaecb18cd8876ea98NjRATthreatfoxca868ac1e4f42282fb74865fc2f9edf38b052e4bNjRATthreatfox1cf8cce965f8f2089ce67ef811b29d13NjRATthreatfox19dc42491a499830d7638933b5f457740ffce395NjRATthreatfoxd5c4983535d57d69fc6f8c09ff4a3838d6a61ac6b149de67b89c0c062968d9cdNjRATthreatfox1742ad51f743c9e518abec7fc6f9451bNjRATthreatfox81.71.128.221:14149NjRATthreatfox156.223.213.38:1177NjRATthreatfox47fa97e2a70af9612d5c0a024ba4cce2163aacad465e8fc4bf6abe1bd98bbb88NanoCoremalwarebazaar188.209.158.187:1177NjRATthreatfox156.223.177.158:1177NjRATthreatfox172.94.46.114:1012NjRATthreatfoxea9f1901741fb76ca5eb7f48415d33d4eb7bc6fa3f3d8a47aa3babe8c1376efdNanoCoremalwarebazaarf634762210e39bf8b8f436b40ee1cb122431f5558f96465c9f2e01cd8856296dNanoCoremalwarebazaare946713a98d119096e00d3c536d74608269bc402e0af213ec77e874a17f3164aNanoCoremalwarebazaarb5abd48cdb1d3f97418047505d5a32e03e694fe5NjRATthreatfox2a85f2e5876b278a7af9393483de455bNjRATthreatfoxbae4f4322d4c215be01990ad77275474f829ed7b3731703ed07946ab9d041413NjRATthreatfox105.72.55.52:8080NjRATthreatfox8.148.27.183:12050NjRATthreatfoxzenvyus.ddns.netNjRATthreatfoxfouad-94.myq-see.comNjRATthreatfoxjoaoszr3.ddns.netNjRATthreatfox187.101.57.177:1177NjRATthreatfoxfd7ec45552919baf92c37cb17b533d5eedfe5758NjRATthreatfox01af93c099eda51a2b46fb2108fc1e2aNjRATthreatfoxf9ac08dc0d9d265ba44e7b256cc554cd9a741ca2a7e4dc01807376a90f8b1024NjRATthreatfox8.148.23.144:12329NjRATthreatfoxb106b83f8537dd027ba91b3994e1990c0ad195cc8a6ad37115cf8627b21a8797NanoCoremalwarebazaarc9b310129dfd8ca8fbe110012ebb62282b8e3360NjRATthreatfox+163 indicadores en total. Míralos todos en la página de IOCs.
Referencias
El grupo Group5 usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.
Conocer el Pentest Autónomo con IA →