THREAT_ACTOR · G0002
Moafee
Also known as: Moafee
Profile
Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group DragonOK.
MITRE ATT&CK ↗Techniques
1 ATT&CK techniques attributed to this actor.
Software
1 malware/tools attributed to this actor.
PoisonIvy
Related corpus activity
14 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Moafee.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| b5b603ff57142a454c3b0fb12eb8a4eb | hash | — | 80 | 2 |
| d89bb4b23a67814ef511e4e9dda7ad36fa519a322fa7c25ea451c7dd7ef61e54 | hash | — | 80 | 2 |
| f6e4b09ef788adef3f65fd2b99da8f5be5391be29471676dc07040a56c8fdfab | hash | — | 80 | 2 |
| cf64c7e2e3897ae5fce3d5414e3d1d27 | hash | — | 80 | 2 |
| 78945c844fc23dd3446cf17987edeeb6cc21986820c92df82a126af24a5a38d1 | hash | — | 80 | 2 |
| c333a821f1764abe2aed2c1ab27d2349f64e4264 | hash | — | 80 | 2 |
| 04ccc8f9f5e343f94ad9f41f08439b545d4b8486 | hash | — | 80 | 2 |
| 41999a3d0da035ff8068905c90235ea50121329cb0661e38d745974ebf5e3ae2 | hash | — | 80 | 2 |
| http://glot.io/snippets/hfd3x9ueu5 | url | supply_chain | 75 | 1 |
| 185.76.243.85 | ip | — | 70 | 1 |
| 138.124.186.2 | ip | — | 70 | 1 |
| akmuniverstall.top | domain | — | 65 | 2 |
| xn--fiqq24b9hejs1c.clickvector.tech | domain | — | 65 | 3 |
| bsc.blockrazor.xyz | domain | — | 65 | 3 |