Update ETAC_Vetted_UkraineRussiaWar_IOCs.csv

Этот коммит содержится в:
BushidoToken 2022-03-08 23:57:59 +00:00 коммит произвёл GitHub
родитель 16dea823be
Коммит d83b972234
Не найден ключ, соответствующий данной подписи
Идентификатор ключа GPG: 4AEE18F83AFDEB23

Просмотреть файл

@ -2091,3 +2091,13 @@ MD5,d2a795af12e937eb8a89d470a96f15a5,"""core.dll"" Malicious DLL",hxxps://twitte
MD5,fb418bb5bd3e592651d0a4f9ae668962,"""Windows Prefetch.lnk"" Malicious LNK",hxxps://twitter.com/h2jazi/status/1500607147989684224,
Domain,xbeta.online,C2 server,hxxps://twitter.com/h2jazi/status/1500607147989684224,
IPv4,185.175.158.27,C2 server,hxxps://twitter.com/cluster25_io/status/1499678960782823432,
MD5,65237e705e842da0a891c222e57fe095,microbackdoor.dll (MicroBackdoor),hxxps://cert.gov.ua/article/37626,
Hostname,id-unconfirmeduser[.]frge[.]io,FancyBear/APT28,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,hatdfg-rhgreh684[.]frge[.]io,FancyBear/APT28,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,ua-consumerpanel[.]frge[.]io,FancyBear/APT28,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,consumerspanel[.]frge[.]io,FancyBear/APT28,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,accounts[.]secure-ua[.]website,Ghostwriter/UNC1151,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,i[.]ua-passport[.]tope,Ghostwriter/UNC1151,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,login[.]creditals-email[.]space,Ghostwriter/UNC1151,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,post[.]mil-gov[.]space,Ghostwriter/UNC1151,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,
Hostname,verify[.]rambler-profile[.]site,Ghostwriter/UNC1151,hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine,

1 Type Indicator Context Source
2091 MD5 fb418bb5bd3e592651d0a4f9ae668962 "Windows Prefetch.lnk" Malicious LNK hxxps://twitter.com/h2jazi/status/1500607147989684224
2092 Domain xbeta.online C2 server hxxps://twitter.com/h2jazi/status/1500607147989684224
2093 IPv4 185.175.158.27 C2 server hxxps://twitter.com/cluster25_io/status/1499678960782823432
2094 MD5 65237e705e842da0a891c222e57fe095 microbackdoor.dll (MicroBackdoor) hxxps://cert.gov.ua/article/37626
2095 Hostname id-unconfirmeduser[.]frge[.]io FancyBear/APT28 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2096 Hostname hatdfg-rhgreh684[.]frge[.]io FancyBear/APT28 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2097 Hostname ua-consumerpanel[.]frge[.]io FancyBear/APT28 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2098 Hostname consumerspanel[.]frge[.]io FancyBear/APT28 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2099 Hostname accounts[.]secure-ua[.]website Ghostwriter/UNC1151 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2100 Hostname i[.]ua-passport[.]tope Ghostwriter/UNC1151 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2101 Hostname login[.]creditals-email[.]space Ghostwriter/UNC1151 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2102 Hostname post[.]mil-gov[.]space Ghostwriter/UNC1151 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine
2103 Hostname verify[.]rambler-profile[.]site Ghostwriter/UNC1151 hxxps://blog.google/threat-analysis-group/update-threat-landscape-ukraine