# IOClist - hostname # # Use these IOCs at your own risk. # # See : http://www.botvrij.eu # solitary-dawn-61af.mfeagents.workers.dev # hostname - ToddyCat: Keep calm and check logs (372) www.githubdd.workers.dev # hostname - ToddyCat: Keep calm and check logs (372) www.joshan.pro # hostname - The attack against Danish critical infrastructure (377) east-healthy-dress.glitch.me # hostname - New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs (385) coral-polydactyl-dragonfruit.glitch.me # hostname - New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs (385) kwhfibejjyxregxmnpcs.supabase.co # hostname - New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs (385) epibvgvoszemkwjnplyc.supabase.co # hostname - New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs (385) ndrrftqrlblfecpupppp.supabase.co # hostname - New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs (385) cloud-document-edit.onrender.com # hostname - New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs (385) lo0.systemctl.network # hostname - Turkish espionage campaigns in the Netherlands (389) forward.boord.info # hostname - Turkish espionage campaigns in the Netherlands (389) 22.imohub.workers.dev # hostname - Backdoor Activator Malware Running Rife Through Torrents of macOS Apps (390) web.bonuscave.com # hostname - Earth Preta Campaign Uses DOPLUGS to Target Asia (409) www.markplay.net # hostname - Earth Preta Campaign Uses DOPLUGS to Target Asia (409) images.markplay.net # hostname - Earth Preta Campaign Uses DOPLUGS to Target Asia (409) news.comsnews.com # hostname - Earth Preta Campaign Uses DOPLUGS to Target Asia (409) images.kiidcloud.com # hostname - Earth Preta Campaign Uses DOPLUGS to Target Asia (409) birngthemhomenow.co.il # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) teledyneflir.com.de # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) airconnectionapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) airconnectionsapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) airconnectionsapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) airgadgetsolution.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) airgadgetsolutions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) altnametestapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) answerssurveytest.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) apphrquestion.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) apphrquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) apphrquizapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) arquestionsapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) arquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) audiomanagerapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) audioservicetestapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) blognewsalphaapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) blogvolleyballstatusapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) blogvolleyballstatus.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) boeisurveyapplications.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) browsercheckap.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) browsercheckingapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) browsercheckjson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) changequestionstypeapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) changequestionstypejsonapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) changequestiontypesapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) changequestiontypes.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) checkapicountryquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) checkapicountryquestionsjson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) checkservicecustomerapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) coffeeonlineshop.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) coffeeonlineshoping.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) connectairapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) connectionhandlerapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) countrybasedquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) customercareserviceapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) customercareservice.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) emiratescheckapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) emiratescheckapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) engineeringrssfeed.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) engineeringssfeed.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) exchtestcheckingapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) exchtestcheckingapihealth.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) flighthelicopterahtest.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) helicopterahtest.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) helicopterahtests.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) helicoptersahtests.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) hiringarabicregion.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) homefurniture.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) hrapplicationtest.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) humanresourcesapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) humanresourcesapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) humanresourcesapiquiz.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) iaidevrssfeed.centralus.cloudapp.azure.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) iaidevrssfeed.centrualus.cloudapp.azure.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) iaidevrssfeed.cloudapp.azure.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) iaidevrssfeedp.cloudapp.azure.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) identifycheckapplication.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) identifycheckapplications.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) identifycheckingapplications.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) ilengineeringrssfeed.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) integratedblognewfeed.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) integratedblognewsapi.azurewebsites.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) integratedblognewsapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) integratedblognews.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) intengineeringrssfeed.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) intergratedblognewsapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) javaruntime.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) javaruntimestestapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) javaruntimetestapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) javaruntimeversioncheckingapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) javaruntimeversionchecking.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) jupyternotebookcollection.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) jupyternotebookcollections.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) jupyternotebookscollection.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) logsapimanagement.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) logsapimanagements.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) logupdatemanagementapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) logupdatemanagementapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) manpowerfeedapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) manpowerfeedapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) marineblogapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) notebooktextchecking.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) notebooktextcheckings.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) notebooktexts.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) onequestionsapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) onequestionsapicheck.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) onequestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) openapplicationcheck.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) optionalapplication.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) personalitytestquestionapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) personalizationsurvey.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) qaquestionapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) qaquestionsapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) qaquestionsapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) qaquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) queryfindquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) queryquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) questionsapplicationapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) questionsapplicationapijson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) questionsapplicationbackup.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) questionsdatabases.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) questionsurveyapp.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) questionsurveyappserver.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) quiztestapplication.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) refaeldevrssfeed.centralus.cloudapp.azure.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) regionuaequestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) registerinsurance.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) roadmapselectorapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) roadmapselector.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) sportblogs.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) surveyappquery.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) surveyonlinetestapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) surveyonlinetest.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) technewsblogapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) testmanagementapi1.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) testmanagementapis.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) testmanagementapisjson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) testquestionapplicationapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) testtesttes.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) tiappschecktest.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) tnlsowkis.westus3.cloudapp.azure.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) tnlsowki.westus3.cloudapp.azure.com # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) turkairline.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) uaeaircheckon.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) uaeairchecks.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) vscodeupdater.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) workersquestionsapi.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) workersquestions.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) workersquestionsjson.azurewebsites.net # hostname - When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors (411) cecar.com.ar # hostname - FakeBat delivered via several active malvertising campaigns (413) estiloplus.tur.ar # hostname - FakeBat delivered via several active malvertising campaigns (413) arr-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) portu-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) xwago.creativeplus.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) wae4w.mariomanagement.biz.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) h4aowa.mariostrategy.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) yaiinr.actiongroup.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) e0aonr.creativeplus.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) wiae5.marioadvisory.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) caiiaf.businesswise.biz.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) 2joafm.marioanalytics.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) nqaa8e.businesswise.biz.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) nweow8.mariostrategy.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) wba0s.produtoeletro.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) 4hawb.produtoeletro.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) cua3e.mariosolutions.biz.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) eeiul.marioadvisory.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) kka5c.marioanalytics.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) w8oaa0.mariosolutions.biz.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) 0tuiwp.mariomanagement.biz.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) lwafa.actiongroup.my.id # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) avfa-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) factalia-ofh2cutija-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) gasgas-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) haergsd-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) jx-krrdbo6imq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) ptb-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) ptm-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) pto-wd3463btrq-uc.a.run.app # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) 1.tcp.sa.ngrok.io # hostname - Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns (416) webmail.facadesolutionsuae.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) wody-info-files.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) kzgw-wody.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) nas-files.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) e-nas.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) ua-calendar.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) calendarua.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) calendar-ua.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) e-gov-am.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) e-gov.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) info-mod.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) e-mod.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) rada-zakon.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) militarysupport.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) sgg-files.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) sgg-gov.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) presidencia-docs.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) files-presidencia.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) e-presidencia.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) presidencia-files.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) presidencia-gov.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) presidencia-gob.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) gcsd.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) emod.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) e-military.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) dls-gov.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) eecommission.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418) eecommission-drive.firstcloudit.com # hostname - Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns (418)