{
  "metadata": {
    "generator": "Bulwark Black IOC Extractor",
    "source": "https://bulwarkblack.com/gunra-ransomware-vpn-compromise-incident-response/",
    "fang": "live",
    "exported_at": "2026-08-12T15:04:29Z",
    "total": 35,
    "categories": 6
  },
  "iocs": {
    "IPv4": [
      "103.125.234.14",
      "123.184.143.105",
      "123.244.187.144",
      "123.246.37.108",
      "182.204.16.112",
      "182.204.21.240",
      "182.204.39.118",
      "211.21.210.181",
      "23.239.119.2",
      "23.239.119.3",
      "23.239.119.4",
      "23.239.119.5",
      "23.239.119.6",
      "67.43.53.10",
      "70.36.99.82",
      "86.54.28.216",
      "91.201.66.146"
    ],
    "Domains": [
      "Datapub.news",
      "StopRansomware.gov",
      "datapub.news",
      "intel.breakglass.tech",
      "stopransomware.gov",
      "www.cloudsek.com",
      "www.cyfirma.com"
    ],
    "URLs": [
      "Datapub.news",
      "https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying",
      "https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker",
      "https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/"
    ],
    "Email Addresses": [
      "contact@cisa.dhs.gov"
    ],
    "sha256": [
      "2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751",
      "834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1",
      "91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0",
      "a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9"
    ],
    "CVEs": [
      "CVE-2024-55591",
      "CVE-2025-24472"
    ]
  }
}