security.com · Crawled Jul 25, 2026

Ukrainian Organizations Still Heavily Targeted by Russian Attacks | SECURITY.COM

27 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

Russian-linked attackers continue to target Ukrainian organizations with a focus on espionage and persistent access. The intrusions involved the use of webshells, living-off-the-land tactics, and minimal malware deployment to harvest credentials and sensitive data. Techniques included memory dumping, registry exfiltration, and disabling security tools, indicating a highly skilled and stealthy threat actor.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 27 extracted

Type Value Detail
IP 185[.]145[.]245[.]209 Details →
Domain ciscoheartbeat[.]com Details →
SHA-256 636e04f0618dd578d107f440b1cf6c910502d160130adae5e415b2dd2b36abcb Details →
SHA-256 70a5492db39585ec18de512058a5389c9a4043fba13ca8ad7d057ead66298626 Details →
SHA-256 69cb709bffbeccea60776c49935acb41ecfb160973f1f11b195007c254c1c28c Details →
SHA-256 8c07c37ac84d4c6fd76de3d966e26b65e401bc641a845baf6f73ad0d6a10fc6b Details →
SHA-256 44b1f3f06607cd3ee16517d31b30208910ce678cb69ba7a0514546dff183dfce Details →
SHA-256 cf8e09f013fcb5f34c8c274bf07d9047956ba441dabf2d3de87ea025e14058b7 Details →
SHA-256 2866763ebd3124bfe9cf3f65d6341dda6bbb98e2653c98dd2f001f152e082291 Details →
SHA-256 08ced2cca0b22dd7a211ebf318b8186fc1c2149943338c77ee2ac677b473727f Details →
SHA-256 79d1c7158d374ed80ec7f9305f6638ad95aefd600c9e280fc7fe081c7ef2f4b4 Details →
SHA-256 e9a19d42da93e9257dc9b89afc34341e1c13d6a6f7dacd309f2fc545e6b749a3 Details →
SHA-256 8140326d7474722e6bdd51dd305609e82319c0150ed429b74587d689acea2d54 Details →
SHA-256 ba6301e35fc3feb41ece82e518f97a81263aa3bd750de7a84eef01dbf15f3507 Details →
SHA-256 c2cf27810cc11ed7c6ae9f70f156f18cf3f73550ab5d675278e3b725fc88e2b0 Details →
SHA-256 e03b8c54ac916b363f956e4e4e04a19eb4119455d8006c92e9328e16a8cee52f Details →
SHA-256 8fe4e336fbac4f5227f802ba1853f1b07ffdb414cec961c532c115078a2aa55e Details →
SHA-256 8eb178d5b1d528380c9ccfe1ea7f43aebd97b018a5b449ec911a05c0bd52d207 Details →
SHA-256 6865685f75a64780aa24a05b267bea128bcc6efdc682fa2893e13a4f63e6d6e7 Details →
SHA-256 47e83dfd0f9680d2e9623fee92c0acc4db40ea4272edeb53164304620305a24f Details →
Filename service.aspx Details →
Filename link.ps1 Details →
Filename dotnet-install.ps1 Details →
Filename service.exe Details →
Filename cloud.exe Details →
Filename winbox64.exe Details →
Filename assembler.py Details →

MITRE ATT&CK TTPs 41 techniques

T1003 OS Credential Dumping · Credential Access T1012 Query Registry · Discovery T1016 System Network Configuration Discovery · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1057 Process Discovery · Discovery T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1069.002 Domain Groups · Discovery T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1081 T1081 T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1090.002 External Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1120 Peripheral Device Discovery · Discovery T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1136.002 Domain Account · Persistence T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1217 Browser Information Discovery · Discovery T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access