Skip to main content

Overview

Episode 2 reveals extensive targeting of organizations across multiple countries in the Middle East and beyond. The evidence includes target lists, successful compromises, and attack infrastructure spanning numerous nations.

Primary Target Countries

The main countries targeted in Episode 2 documentation:
  • Jordan
  • Iran
  • Kuwait
  • Saudi Arabia
  • Turkey
Additional countries with documented attacks are detailed below.

Iran

Target Organizations

Documented Iranian targets include: Government Entities:
  • 217.218.21.105 - Setad Mobareze ba Qachaq v Arz (Anti-Smuggling and Currency Headquarters)
  • 178.252.191.163 - Qudsdaily (media organization)
Infrastructure Targets:
  • 109.125.132.66 - Shell deployed
  • 109.232.1.181 - Mail server
  • 185.110.30.177
  • 185.142.124.20
  • 185.172.212.18
  • 185.172.212.20
  • 185.179.222.50
  • 185.189.122.142 - Error status
  • 185.95.152.161
  • 185.95.180.51
  • 2.187.19.189
  • 217.219.209.11
  • 37.235.27.28 - Error status
  • 45.147.77.137 - LegacyDN
  • 46.100.58.29
Email Infrastructure:
  • mail.barez.org

Target Files

  • IR_Proxyshell_target.txt - Primary Iranian target list
  • IR_Proxyshell_target2.txt - Secondary Iranian target list

Kuwait

Target Organizations

Business Entities:
  • webmail.kccec.com.kw - Kuwait Canadian Consulting Engineers Company
  • mail.kfmb.com.kw - Kuwait Finance and Investment Company
  • mail.yousifi.com.kw - Yousifi Group
  • mail.sih-kw.com - Sultan International Holding
  • mail.montania.org
  • mail.kiti.com.kw
  • mail.azzadgroup.com.kw
Cloud Infrastructure:
  • mx03.koutcloud.com
  • mx02.koutcloud.com
  • mx2.specialitieskuwait.com
Insurance:
  • smg.zamzamtakaful.com
Industrial:
  • exch1.kyfco.com
IP Addresses:
  • 83.96.77.227
  • 83.96.120.39
  • 78.89.184.155
  • 62.215.215.46
  • 62.215.164.41
  • 62.215.142.5
  • 31.214.10.52
  • 193.22.172.225
  • 168.187.130.99

Target Files

  • KW_proxyshell_target.txt
  • kw-proxyshell-target.kw

Saudi Arabia

Target Organizations

Healthcare:
  • mail.almanahospital.com.sa - Al Mana Hospital (LegacyDN)
  • webmail.almanahospital.com.sa - Failed
  • mail.ihcc.sa - International Healthcare Consulting Company (LegacyDN)
  • outbound.familycare.com.sa - Failed
Industrial & Mining:
  • mail1.solbsteel.com - Solb Steel
  • mail.tanhatmining.com - Tanhat Mining
  • mail.alrashidabetong.com - Al Rashida Betong
Business Services:
  • mail.aiccp.com.sa - Arabian Industrial & Commercial Projects Company
  • mail.albarakatgroup.com
  • mail.arabian-homes.com
  • mail.goldenbrown.sa
  • mail.sosgroup.com
  • mail1.manafea.net - Shell deployed
  • smtp.baroid-sa.com
  • email.samama.com - Failed
IP Addresses:
  • 212.12.165.155 - Shell deployed
  • 212.12.178.178
  • 213.236.56.117
  • 37.224.113.215
  • 46.235.93.139 - Mail server
  • 77.240.91.151 - Failed
  • 77.240.91.154 - Failed
  • 77.240.91.155 - Failed
  • 77.240.93.43 - Mail server
  • 85.184.233.203 - Shell deployed
  • 87.101.187.92
  • 93.112.12.130
  • 94.77.201.86

Target Files

  • SA_Proxyshell_target.txt
  • 212.12.165.155.yml
  • 46.235.93.139.txt
  • 77.240.93.43.txt

Turkey

Target Organizations

Government:
  • eposta.mfa.gov.ct.tr - Ministry of Foreign Affairs (critical target)
  • smtp.aydinaski.gov.tr - Aydin ASKİ (Water and Sewerage)
  • mail.bahcelievler.bel.tr - Bahçelievler Municipality
  • mail.mersin.bel.tr - Mersin Municipality
Manufacturing & Industrial:
  • exchange.akbasoglu.com - Akbaşoğlu Group
  • hibrit.magmaweld.com - Magma Welding
  • mail.akartextile.com - Akar Textile
  • mail.basturkcam.com.tr - Baştürk Glass
  • mail.duzeymode.com - Düzey Fashion
  • msexc.aydintextil.com.tr - Aydın Textile
  • mail.mtplastech.com.tr - MT Plastech
  • mail.narkonteks.com - Narkon Textiles
Technology & Services:
  • mail.dnstrade.com.tr - DNS Trade
  • antivirusgw.teknikgumruk.com.tr - Teknik Gümrük (Customs Consulting)
  • mail.itpro.com.tr - IT Pro
  • mail.uzmantek.com - Uzmantek
  • mail1.otaknetworks.com - Otak Networks
  • srv0.kurgu-e.com - Kurgu-e
Food & Hospitality:
  • mail.24yemek.com.tr - 24 Yemek (Food Services)
  • mail.bilpagida.com - Bil Gıda (Food)
Healthcare:
  • mail.nisahastanesi.com - Nisa Hospital
Education:
  • mail.dcaokullari.com - DCA Schools
Other Organizations:
  • mail.basakoglu.com.tr
  • mail.gopayless.com.tr
  • mail.kmcgroup.com.tr - KMC Group
  • mail.noahsark.com.tr
  • mail.ozerensigorta.com - Özeren Insurance
  • mail.taf-inter.com
  • mail.umur.com.tr
  • mail.zenitled.com.tr - Zenit LED
  • owa.myl.com.tr
  • webmail.calor.com.tr
  • webmail.intimesolutions.net
Static IPs:
  • static-169-40-68-212.sadecehosting.net
  • static-185-132-125-83.ptr.name.tr
  • ulak.neutecin.com

Target Files

  • TR_Exchange_target.txt
  • hibrit.magmaweld.com.lua
  • mail.dnstrade.com.tr.sql
  • target turkey.tr

Additional Target Countries

Austria (AT)

Target File: AT_proxyshell_target.txt

Australia (AU)

Target File: AU_Proxyshell_target.txt

Azerbaijan (AZ)

Notable Targets:
  • Oil and energy sector companies
  • Multiple Exchange servers compromised
Evidence: 100+ target files showing systematic exploitation

Belgium (BE)

Multiple organizations targeted with ProxyShell attacks.

Bahrain (BH)

Target File: BH_proxy_Shell_target.txt Documented Compromises:
  • 37.131.21.238 - Multiple attack attempts
  • 80.95.221.227
  • 80.95.213.101
  • 80.95.211.36
  • 80.95.222.211

Canada (CA)

Multiple organizations targeted across Canadian infrastructure.

Egypt (EG)

Target File: EG_Proxyshell_target.txt Government and commercial entities targeted.

Greece (GR)

Businesses and organizations subjected to ProxyShell exploitation attempts.

India (IN)

Various companies and services targeted.

Jordan (JO)

While specific organizational details are redacted in available files, Jordan is explicitly mentioned in the README as one of the primary target countries for this episode.

Attack Statistics

Based on documented evidence:
  • Countries Affected: 15+ documented in detail
  • Organizations Targeted: 200+ unique targets
  • Successful Compromises: Dozens of confirmed webshell deployments
  • Attack Vector: Primarily ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207)
  • Target Sectors: Government, Healthcare, Manufacturing, Technology, Finance, Education, Energy

Geographic Distribution

Middle East Focus

The primary focus remains on Middle East countries:
  • Jordan
  • Iran
  • Kuwait
  • Saudi Arabia
  • Turkey
  • Bahrain
  • Egypt

Extended Targets

Additional targeting across:
  • Europe (Austria, Belgium, Greece)
  • Asia (India, Azerbaijan)
  • North America (Canada)
  • Oceania (Australia)

Target Selection Criteria

Based on the evidence, Department 40 appears to target:
  1. Government Entities: Ministries, municipalities, regulatory bodies
  2. Critical Infrastructure: Water, energy, telecommunications
  3. Healthcare Organizations: Hospitals and medical facilities
  4. Financial Services: Banks, insurance companies
  5. Manufacturing: Industrial companies across various sectors
  6. Media Organizations: News outlets and publishers
  7. Educational Institutions: Schools and universities
The systematic nature of these attacks demonstrates a well-organized intelligence gathering operation aligned with IRGC-IO strategic objectives.

Build docs developers (and LLMs) love