README.MD

February 28, 2026 · View on GitHub

Copyright © @RedDrip (https://ti.qianxin.com/)

Here are indicators of compromise (IOCs) collected from public resources and our own investigations. Details include sample hash, file type, malware family, as well as first seen and file name from VirusTotal in format below:

HashTypeFamilyFirst_SeenName
8e2b5b95980cf52e99acfa95f5e1570bWin32 DLL2019-11-11 15:22:00C:\Users<USER>\AppData\Local\Temp~$doc-ad9b812a-88b2-454c-989f-7bb5fe98717e.ole
3c3b2cc9ff5d7030fb01496510ac75f2DOC2019-11-11 11:13:02?-????2019?????????????????.doc
3a8c80d73f9beebd828c3aa172c747faRAR2019-11-07 01:23:39Noi dung don cau cuu.rar
82990e2c0432e579a00ab1f75da0dd65TXT2019-10-26 11:05:08lang.ps1
a87ada040f7250b59910345ee0b339b4RAR2019-10-23 09:20:16Thu moi.rar
dbdbcd220475678c4becdc57a9233e20Win32 EXE2019-10-18 07:28:19AcroRd32.exe
e7de9a64266f07168def534852349957RARKryptik2019-09-16 00:18:57Don khieu nai.rar
90c66c76095ef1ad5a79e63a544c1bbaWin32 DLLKryptik2019-09-13 06:02:21123456

We will keep updating this project and hope this could help the security community to fight against malware and targeted attack.

If you find an error, please contact us at ti_support@qianxin.com and we’ll try to improve the IOCs.

GroupnameTotalUpdatedata
APT-LY-10066162026/02/12
APT-Q-12882026/02/12
APT-Q-15112026/02/12
APT-Q-27180452026/02/12
APT-Q-63612026/02/12
APT28796322026/02/12
APT33235672026/02/12
APT35812026/02/12
APT3717772026/02/12
babyelephant20202026/02/12
Bloody Wolf30252026/02/12
Bluenoroff group1592026/02/12
C-Major61812026/02/12
Citrine Sleet222026/02/12
CL-STA-0043932026/02/12
Confucius17452026/02/12
CoreWerewolf612026/02/12
DarkGaboon10812026/02/12
Darkhotel319432026/02/12
Donot485192026/02/12
dragonforce25162026/02/12
EarthEstries32132026/02/12
EncryptHub10422026/02/12
FaceDuck Group2502172026/02/12
FIN764422026/02/12
Gamaredon Group665592026/02/12
Ghostwriter48202026/02/12
Higaisa252918462026/02/12
Homeland Justice862026/02/12
Inception Framework1712026/02/12
Infy group215192026/02/12
Kimsuky422592026/02/12
KONNI207392026/02/12
Lazarus Group183132026/02/12
Librarian Ghouls2082026/02/12
LUNAR SPIDER37302026/02/12
MKLG2052026/02/12
MuddyWater370512026/02/12
Mysterious Elephant39162026/02/12
NoName057565112026/02/12
OceanLotus1230362026/02/12
OilRig11312026/02/12
Operation SideCopy66192026/02/12
PatchWork1271312026/02/12
ref77072042026/02/12
Sandworm5952026/02/12
Sidewinder263572026/02/12
Silent Werewolf1952026/02/12
TA55840672026/02/12
TAG-1001072026/02/12
ToddyCat5312026/02/12
Turla45552026/02/12
UAC-006324132026/02/12
UAC-01844832026/02/12
UAC-024513132026/02/12
UAT-53942772026/02/12
UNC11517142026/02/12
UNC154968332026/02/12
UNC5174872026/02/12
UNC522147312026/02/12
UNC5267332026/02/12
UTG-Q-015612026/02/12
VasyGrek53242026/02/12
Void Blizzard13132026/02/12
WIRTE54162026/02/12