Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs
This commit is contained in:
26
data/ioc/spyware/mvt/2022-06-23_rcs_lab/domains.txt
Normal file
26
data/ioc/spyware/mvt/2022-06-23_rcs_lab/domains.txt
Normal file
@@ -0,0 +1,26 @@
|
||||
119-tim.info
|
||||
133-tre.info
|
||||
146-fastweb.info
|
||||
155-wind.info
|
||||
159-windtre.info
|
||||
amex-co.info
|
||||
apps.fb-techsupport.com
|
||||
business.wind-h3g.info
|
||||
cloud-apple.info
|
||||
comtencentmobileqq-6ffb5.appspot.com
|
||||
comxdjajxclient.appspot.com
|
||||
fb-techsupport.com
|
||||
fintur-a111a.appspot.com
|
||||
ho-mobile.online
|
||||
iliad.info
|
||||
kena-mobile.info
|
||||
milf.house
|
||||
mobdemo.info
|
||||
mobilepays.info
|
||||
my190.info
|
||||
poste-it.info
|
||||
project1-c094e.appspot.com
|
||||
rojavanetwork.info
|
||||
safekeyservice-972cd.appspot.com
|
||||
store-apple.info
|
||||
wind-h3g.info
|
||||
@@ -0,0 +1,5 @@
|
||||
com.androidservices.support
|
||||
com.vodaservices
|
||||
com.fintur.support
|
||||
com.xdja.safekeyservice
|
||||
com.xdja.jxclient
|
||||
975
data/ioc/spyware/mvt/2022-06-23_rcs_lab/rcs.stix2
Normal file
975
data/ioc/spyware/mvt/2022-06-23_rcs_lab/rcs.stix2
Normal file
@@ -0,0 +1,975 @@
|
||||
{
|
||||
"type": "bundle",
|
||||
"id": "bundle--8fe0fa1c-a385-4539-9a3f-22c8e4d0d635",
|
||||
"objects": [
|
||||
{
|
||||
"type": "malware",
|
||||
"spec_version": "2.1",
|
||||
"id": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0",
|
||||
"created": "2022-06-24T13:12:26.333305Z",
|
||||
"modified": "2022-06-24T13:12:26.333305Z",
|
||||
"name": "RCSLab",
|
||||
"is_family": true
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--7c6b4d6d-a2eb-41ba-9be8-1793a9b2ed9d",
|
||||
"created": "2022-06-24T13:12:26.333619Z",
|
||||
"modified": "2022-06-24T13:12:26.333619Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='119-tim.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.333619Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--92d3f95d-f580-45a6-9692-6827ec325966",
|
||||
"created": "2022-06-24T13:12:26.339881Z",
|
||||
"modified": "2022-06-24T13:12:26.339881Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--7c6b4d6d-a2eb-41ba-9be8-1793a9b2ed9d",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--8a69c42b-6c5b-4351-a8f1-b8896460dd3b",
|
||||
"created": "2022-06-24T13:12:26.34046Z",
|
||||
"modified": "2022-06-24T13:12:26.34046Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='133-tre.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.34046Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--1a6b73c1-8047-4a86-8a0f-dc3057745902",
|
||||
"created": "2022-06-24T13:12:26.341296Z",
|
||||
"modified": "2022-06-24T13:12:26.341296Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--8a69c42b-6c5b-4351-a8f1-b8896460dd3b",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--5d1797b5-5aa0-4aa9-8153-82f1de10da25",
|
||||
"created": "2022-06-24T13:12:26.341518Z",
|
||||
"modified": "2022-06-24T13:12:26.341518Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='146-fastweb.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.341518Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--4770dc39-d90a-4347-b305-4cedb5028dc8",
|
||||
"created": "2022-06-24T13:12:26.342472Z",
|
||||
"modified": "2022-06-24T13:12:26.342472Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--5d1797b5-5aa0-4aa9-8153-82f1de10da25",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--324552fc-2fa9-45b7-a813-fb9033caf2eb",
|
||||
"created": "2022-06-24T13:12:26.342693Z",
|
||||
"modified": "2022-06-24T13:12:26.342693Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='155-wind.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.342693Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--b97ace08-1734-4ef5-b686-f17f20ecaed2",
|
||||
"created": "2022-06-24T13:12:26.343472Z",
|
||||
"modified": "2022-06-24T13:12:26.343472Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--324552fc-2fa9-45b7-a813-fb9033caf2eb",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--923369af-e465-4787-a235-80198057ee11",
|
||||
"created": "2022-06-24T13:12:26.343693Z",
|
||||
"modified": "2022-06-24T13:12:26.343693Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='159-windtre.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.343693Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--a67f1ffb-79ca-43d3-a185-d2fba4b1f217",
|
||||
"created": "2022-06-24T13:12:26.344322Z",
|
||||
"modified": "2022-06-24T13:12:26.344322Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--923369af-e465-4787-a235-80198057ee11",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--8b1dab2a-ee94-4d9a-aa52-180baeed3be1",
|
||||
"created": "2022-06-24T13:12:26.34454Z",
|
||||
"modified": "2022-06-24T13:12:26.34454Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='amex-co.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.34454Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--6f202350-8ca0-4a9f-8360-60c764dc28c4",
|
||||
"created": "2022-06-24T13:12:26.345345Z",
|
||||
"modified": "2022-06-24T13:12:26.345345Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--8b1dab2a-ee94-4d9a-aa52-180baeed3be1",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--c3d4e132-1311-4eeb-a293-f9ed98f623c4",
|
||||
"created": "2022-06-24T13:12:26.345566Z",
|
||||
"modified": "2022-06-24T13:12:26.345566Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='apps.fb-techsupport.com']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.345566Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--d2a418aa-e75f-444a-835c-5bcb7f9f58b3",
|
||||
"created": "2022-06-24T13:12:26.346385Z",
|
||||
"modified": "2022-06-24T13:12:26.346385Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--c3d4e132-1311-4eeb-a293-f9ed98f623c4",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--5daf9871-e1d5-456e-b3a4-4b3d6f7431fd",
|
||||
"created": "2022-06-24T13:12:26.346605Z",
|
||||
"modified": "2022-06-24T13:12:26.346605Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='business.wind-h3g.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.346605Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--6110248d-6c73-45b1-ae9d-236cad2a474e",
|
||||
"created": "2022-06-24T13:12:26.347419Z",
|
||||
"modified": "2022-06-24T13:12:26.347419Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--5daf9871-e1d5-456e-b3a4-4b3d6f7431fd",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--188342a3-2ed0-42ea-aa6e-5e41d473604d",
|
||||
"created": "2022-06-24T13:12:26.347656Z",
|
||||
"modified": "2022-06-24T13:12:26.347656Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='cloud-apple.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.347656Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--cc5927ba-6c8b-44f8-8eb7-83993c5828b8",
|
||||
"created": "2022-06-24T13:12:26.348513Z",
|
||||
"modified": "2022-06-24T13:12:26.348513Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--188342a3-2ed0-42ea-aa6e-5e41d473604d",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--7a4ea108-4d57-48c0-8d83-1243521dbc90",
|
||||
"created": "2022-06-24T13:12:26.348737Z",
|
||||
"modified": "2022-06-24T13:12:26.348737Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='comtencentmobileqq-6ffb5.appspot.com']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.348737Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--5b39695f-b470-489e-89d9-7f033bc8bc39",
|
||||
"created": "2022-06-24T13:12:26.349462Z",
|
||||
"modified": "2022-06-24T13:12:26.349462Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--7a4ea108-4d57-48c0-8d83-1243521dbc90",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--9f6af5b5-3c50-47e5-b259-70ff4c260db2",
|
||||
"created": "2022-06-24T13:12:26.349682Z",
|
||||
"modified": "2022-06-24T13:12:26.349682Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='comxdjajxclient.appspot.com']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.349682Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--6a0b7b23-c8fd-499f-8306-e0f6da3e681f",
|
||||
"created": "2022-06-24T13:12:26.350392Z",
|
||||
"modified": "2022-06-24T13:12:26.350392Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--9f6af5b5-3c50-47e5-b259-70ff4c260db2",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--58132773-47e3-4e94-a314-e03f2815cdf1",
|
||||
"created": "2022-06-24T13:12:26.350609Z",
|
||||
"modified": "2022-06-24T13:12:26.350609Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='fb-techsupport.com']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.350609Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--31f08a85-6930-44ac-88d6-6b7b94d92c33",
|
||||
"created": "2022-06-24T13:12:26.351318Z",
|
||||
"modified": "2022-06-24T13:12:26.351318Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--58132773-47e3-4e94-a314-e03f2815cdf1",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--f54d7d64-5e92-470f-aa06-dc7507230e86",
|
||||
"created": "2022-06-24T13:12:26.351538Z",
|
||||
"modified": "2022-06-24T13:12:26.351538Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='fintur-a111a.appspot.com']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.351538Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--7c217cf0-f45f-4dd3-8ce4-e844c38d4c5c",
|
||||
"created": "2022-06-24T13:12:26.352165Z",
|
||||
"modified": "2022-06-24T13:12:26.352165Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--f54d7d64-5e92-470f-aa06-dc7507230e86",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--c02b7f2f-0583-475a-a6c5-fe7b88ed4768",
|
||||
"created": "2022-06-24T13:12:26.352382Z",
|
||||
"modified": "2022-06-24T13:12:26.352382Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='ho-mobile.online']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.352382Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--ac5c41a1-891c-4930-a22f-c709a9d41040",
|
||||
"created": "2022-06-24T13:12:26.353073Z",
|
||||
"modified": "2022-06-24T13:12:26.353073Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--c02b7f2f-0583-475a-a6c5-fe7b88ed4768",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--8a7a2752-0176-43c3-b6e9-a552cd370535",
|
||||
"created": "2022-06-24T13:12:26.353292Z",
|
||||
"modified": "2022-06-24T13:12:26.353292Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='iliad.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.353292Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--74d9da1b-0a11-4a09-82fc-7b357a407e20",
|
||||
"created": "2022-06-24T13:12:26.353975Z",
|
||||
"modified": "2022-06-24T13:12:26.353975Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--8a7a2752-0176-43c3-b6e9-a552cd370535",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--06930171-82b7-4d74-b3f0-a6f0150c7157",
|
||||
"created": "2022-06-24T13:12:26.354193Z",
|
||||
"modified": "2022-06-24T13:12:26.354193Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='kena-mobile.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.354193Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--fc304f5c-ad2f-49d7-be95-7b0914691e6b",
|
||||
"created": "2022-06-24T13:12:26.354884Z",
|
||||
"modified": "2022-06-24T13:12:26.354884Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--06930171-82b7-4d74-b3f0-a6f0150c7157",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--6d48fc99-2480-408a-9bc2-0121f26828af",
|
||||
"created": "2022-06-24T13:12:26.3551Z",
|
||||
"modified": "2022-06-24T13:12:26.3551Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='milf.house']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.3551Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--b5a8821b-a640-4c2c-951d-3d14312eeccc",
|
||||
"created": "2022-06-24T13:12:26.355797Z",
|
||||
"modified": "2022-06-24T13:12:26.355797Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--6d48fc99-2480-408a-9bc2-0121f26828af",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--8061b446-98aa-4a24-be04-49acbc0a3c90",
|
||||
"created": "2022-06-24T13:12:26.356014Z",
|
||||
"modified": "2022-06-24T13:12:26.356014Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='mobdemo.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.356014Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--a99c0527-c20d-435b-a759-e5a9bcb4dd07",
|
||||
"created": "2022-06-24T13:12:26.356627Z",
|
||||
"modified": "2022-06-24T13:12:26.356627Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--8061b446-98aa-4a24-be04-49acbc0a3c90",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--7f5f2d9d-3430-42db-9dd5-8fc2dacc06ba",
|
||||
"created": "2022-06-24T13:12:26.356848Z",
|
||||
"modified": "2022-06-24T13:12:26.356848Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='mobilepays.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.356848Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--64598bb4-f1b6-4c3e-a39a-d2c48aa5b05d",
|
||||
"created": "2022-06-24T13:12:26.358088Z",
|
||||
"modified": "2022-06-24T13:12:26.358088Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--7f5f2d9d-3430-42db-9dd5-8fc2dacc06ba",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--03dee9cd-b168-450a-919a-7e79b6c84a63",
|
||||
"created": "2022-06-24T13:12:26.358312Z",
|
||||
"modified": "2022-06-24T13:12:26.358312Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='my190.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.358312Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--5af0f57f-9b7f-4a15-87fe-b9aed31286d2",
|
||||
"created": "2022-06-24T13:12:26.358992Z",
|
||||
"modified": "2022-06-24T13:12:26.358992Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--03dee9cd-b168-450a-919a-7e79b6c84a63",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--c9f2bb6a-0dd0-4f74-ae0e-b2ed16dcf601",
|
||||
"created": "2022-06-24T13:12:26.359217Z",
|
||||
"modified": "2022-06-24T13:12:26.359217Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='poste-it.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.359217Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--dc6a2c67-1408-492d-a9a7-dda6be484f09",
|
||||
"created": "2022-06-24T13:12:26.359902Z",
|
||||
"modified": "2022-06-24T13:12:26.359902Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--c9f2bb6a-0dd0-4f74-ae0e-b2ed16dcf601",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--7cb6e051-ef82-4a97-b469-81ec8aeee676",
|
||||
"created": "2022-06-24T13:12:26.360119Z",
|
||||
"modified": "2022-06-24T13:12:26.360119Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='project1-c094e.appspot.com']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.360119Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--47271d88-afac-417e-9420-4d03dcbf4c91",
|
||||
"created": "2022-06-24T13:12:26.360764Z",
|
||||
"modified": "2022-06-24T13:12:26.360764Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--7cb6e051-ef82-4a97-b469-81ec8aeee676",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--3f972bc5-0465-40d7-9435-43bc0943a849",
|
||||
"created": "2022-06-24T13:12:26.360981Z",
|
||||
"modified": "2022-06-24T13:12:26.360981Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='rojavanetwork.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.360981Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--764d101c-e77e-413d-9472-903ae2b49bb4",
|
||||
"created": "2022-06-24T13:12:26.36179Z",
|
||||
"modified": "2022-06-24T13:12:26.36179Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--3f972bc5-0465-40d7-9435-43bc0943a849",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--f8d4f1ae-856e-4d77-9019-d96ce0234133",
|
||||
"created": "2022-06-24T13:12:26.362009Z",
|
||||
"modified": "2022-06-24T13:12:26.362009Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='safekeyservice-972cd.appspot.com']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.362009Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--8293f9ae-efc9-41c2-babb-47f53ae28da0",
|
||||
"created": "2022-06-24T13:12:26.362831Z",
|
||||
"modified": "2022-06-24T13:12:26.362831Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--f8d4f1ae-856e-4d77-9019-d96ce0234133",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--9f94055e-37af-4f64-8143-0acdc305e246",
|
||||
"created": "2022-06-24T13:12:26.363048Z",
|
||||
"modified": "2022-06-24T13:12:26.363048Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='store-apple.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.363048Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--173b7391-2d03-4671-b186-3b3c995fc591",
|
||||
"created": "2022-06-24T13:12:26.363666Z",
|
||||
"modified": "2022-06-24T13:12:26.363666Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--9f94055e-37af-4f64-8143-0acdc305e246",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--b61779d9-d458-4ee3-aec0-617240a7b6f8",
|
||||
"created": "2022-06-24T13:12:26.363883Z",
|
||||
"modified": "2022-06-24T13:12:26.363883Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[domain-name:value='wind-h3g.info']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.363883Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--404cb59c-8579-4700-874c-df0de66a752c",
|
||||
"created": "2022-06-24T13:12:26.364618Z",
|
||||
"modified": "2022-06-24T13:12:26.364618Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--b61779d9-d458-4ee3-aec0-617240a7b6f8",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--e45361fc-f23f-4964-9c52-126298268a37",
|
||||
"created": "2022-06-24T13:12:26.364805Z",
|
||||
"modified": "2022-06-24T13:12:26.364805Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='e38d7ba21a48ad32963bfe6cb0203afe0839eca9a73268a67422109da282eae3']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.364805Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--f0c32e7b-2b2b-46aa-a908-fefdf4bf3845",
|
||||
"created": "2022-06-24T13:12:26.367888Z",
|
||||
"modified": "2022-06-24T13:12:26.367888Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--e45361fc-f23f-4964-9c52-126298268a37",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--e61c0dde-1826-482e-831e-f7382ae5f6ba",
|
||||
"created": "2022-06-24T13:12:26.368076Z",
|
||||
"modified": "2022-06-24T13:12:26.368076Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='fe95855691cada4493641bc4f01eb00c670c002166d6591fe38073dd0ea1d001']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.368076Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--c7d9f0ab-faf1-46f6-a912-6d4c21f2abad",
|
||||
"created": "2022-06-24T13:12:26.368803Z",
|
||||
"modified": "2022-06-24T13:12:26.368803Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--e61c0dde-1826-482e-831e-f7382ae5f6ba",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--0d246a65-89b3-4eff-a3d7-95897e1ae977",
|
||||
"created": "2022-06-24T13:12:26.368983Z",
|
||||
"modified": "2022-06-24T13:12:26.368983Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='243ea96b2f8f70abc127c8bc1759929e3ad9efc1dec5b51f5788e9896b6d516e']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.368983Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--20c01422-bee6-4835-94be-709d5ad6c07e",
|
||||
"created": "2022-06-24T13:12:26.369783Z",
|
||||
"modified": "2022-06-24T13:12:26.369783Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--0d246a65-89b3-4eff-a3d7-95897e1ae977",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--304b0611-d914-4d68-bc3c-cd2807ed668e",
|
||||
"created": "2022-06-24T13:12:26.369965Z",
|
||||
"modified": "2022-06-24T13:12:26.369965Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='a98a224b644d3d88eed27aa05548a41e0178dba93ed9145250f61912e924b3e9']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.369965Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--65da7ae0-f343-4c65-9976-6cef7aabee0a",
|
||||
"created": "2022-06-24T13:12:26.370688Z",
|
||||
"modified": "2022-06-24T13:12:26.370688Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--304b0611-d914-4d68-bc3c-cd2807ed668e",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--03041d38-2e4d-410d-ae3f-39306840313f",
|
||||
"created": "2022-06-24T13:12:26.37087Z",
|
||||
"modified": "2022-06-24T13:12:26.37087Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='c26220c9177c146d6ce21e2f964de47b3dbbab85824e93908d66fa080e13286f']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.37087Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--734b230c-a3f3-457c-8ec6-27c49869aff4",
|
||||
"created": "2022-06-24T13:12:26.371603Z",
|
||||
"modified": "2022-06-24T13:12:26.371603Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--03041d38-2e4d-410d-ae3f-39306840313f",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--98f7c1b0-629c-447a-abb3-9c99c78ef69d",
|
||||
"created": "2022-06-24T13:12:26.371788Z",
|
||||
"modified": "2022-06-24T13:12:26.371788Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='0759a60e09710321dfc42b09518516398785f60e150012d15be88bbb2ea788db']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.371788Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--eadab579-17b1-4cb3-a161-69d63f447030",
|
||||
"created": "2022-06-24T13:12:26.372585Z",
|
||||
"modified": "2022-06-24T13:12:26.372585Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--98f7c1b0-629c-447a-abb3-9c99c78ef69d",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--945c8790-e28d-4e3f-87bf-bf69b74a6331",
|
||||
"created": "2022-06-24T13:12:26.372769Z",
|
||||
"modified": "2022-06-24T13:12:26.372769Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='8ef40f13c6192bd8defa7ac0b54ce2454e71b55867bdafc51ecb714d02abfd1a']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.372769Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--e15ba27f-ea46-4803-b1e1-e4756503530d",
|
||||
"created": "2022-06-24T13:12:26.373569Z",
|
||||
"modified": "2022-06-24T13:12:26.373569Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--945c8790-e28d-4e3f-87bf-bf69b74a6331",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--57bc1215-e991-4831-9a75-fc19c5840cf4",
|
||||
"created": "2022-06-24T13:12:26.373751Z",
|
||||
"modified": "2022-06-24T13:12:26.373751Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='9146e0ede1c0e9014341ef0859ca62d230bea5d6535d800591a796e8dfe1dff9']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.373751Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--a4fd3ba7-d574-44b3-b2c3-1499b1c9cf40",
|
||||
"created": "2022-06-24T13:12:26.374665Z",
|
||||
"modified": "2022-06-24T13:12:26.374665Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--57bc1215-e991-4831-9a75-fc19c5840cf4",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--c6335115-b47a-4212-bda2-3d3ac12b18ee",
|
||||
"created": "2022-06-24T13:12:26.374849Z",
|
||||
"modified": "2022-06-24T13:12:26.374849Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[file:hashes.sha256='6eeb683ee4674fd5553fdc2ca32d77ee733de0e654c6f230f881abf5752696ba']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.374849Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--ff242d23-bab1-4faa-b668-1ae72fa969a1",
|
||||
"created": "2022-06-24T13:12:26.375662Z",
|
||||
"modified": "2022-06-24T13:12:26.375662Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--c6335115-b47a-4212-bda2-3d3ac12b18ee",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--dfedbd26-0d3e-4e66-b428-9990c435c31a",
|
||||
"created": "2022-06-24T13:12:26.37586Z",
|
||||
"modified": "2022-06-24T13:12:26.37586Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[app:id='com.androidservices.support']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.37586Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--d2ad1b53-111e-4bf1-bd97-34cd17dec9ff",
|
||||
"created": "2022-06-24T13:12:26.37681Z",
|
||||
"modified": "2022-06-24T13:12:26.37681Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--dfedbd26-0d3e-4e66-b428-9990c435c31a",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--2b781c83-df99-4875-aa6e-8e6bee322e0e",
|
||||
"created": "2022-06-24T13:12:26.376992Z",
|
||||
"modified": "2022-06-24T13:12:26.376992Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[app:id='com.vodaservices']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.376992Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--e066f24b-4ba4-4797-b807-6e0522311c03",
|
||||
"created": "2022-06-24T13:12:26.377573Z",
|
||||
"modified": "2022-06-24T13:12:26.377573Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--2b781c83-df99-4875-aa6e-8e6bee322e0e",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--f51f2f24-f14a-4e86-adca-28ef6aa2f66f",
|
||||
"created": "2022-06-24T13:12:26.377748Z",
|
||||
"modified": "2022-06-24T13:12:26.377748Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[app:id='com.fintur.support']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.377748Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--d50eca5a-0e18-4000-acb1-7869f1b8a1cc",
|
||||
"created": "2022-06-24T13:12:26.378323Z",
|
||||
"modified": "2022-06-24T13:12:26.378323Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--f51f2f24-f14a-4e86-adca-28ef6aa2f66f",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--786a496f-a543-4505-b1c6-d06b563424cd",
|
||||
"created": "2022-06-24T13:12:26.378497Z",
|
||||
"modified": "2022-06-24T13:12:26.378497Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[app:id='com.xdja.safekeyservice']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.378497Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--b28150db-88ac-465b-ad89-43145e327247",
|
||||
"created": "2022-06-24T13:12:26.379086Z",
|
||||
"modified": "2022-06-24T13:12:26.379086Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--786a496f-a543-4505-b1c6-d06b563424cd",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--bbbed2fa-aa2d-405b-9bb2-a1dd7fc43da2",
|
||||
"created": "2022-06-24T13:12:26.379267Z",
|
||||
"modified": "2022-06-24T13:12:26.379267Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[app:id='com.xdja.jxclient']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2022-06-24T13:12:26.379267Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--b8f9eb1a-55ee-4c17-8dc7-a631e6d42f64",
|
||||
"created": "2022-06-24T13:12:26.379843Z",
|
||||
"modified": "2022-06-24T13:12:26.379843Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--bbbed2fa-aa2d-405b-9bb2-a1dd7fc43da2",
|
||||
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
|
||||
}
|
||||
]
|
||||
}
|
||||
9
data/ioc/spyware/mvt/2022-06-23_rcs_lab/sha256.txt
Normal file
9
data/ioc/spyware/mvt/2022-06-23_rcs_lab/sha256.txt
Normal file
@@ -0,0 +1,9 @@
|
||||
e38d7ba21a48ad32963bfe6cb0203afe0839eca9a73268a67422109da282eae3
|
||||
fe95855691cada4493641bc4f01eb00c670c002166d6591fe38073dd0ea1d001
|
||||
243ea96b2f8f70abc127c8bc1759929e3ad9efc1dec5b51f5788e9896b6d516e
|
||||
a98a224b644d3d88eed27aa05548a41e0178dba93ed9145250f61912e924b3e9
|
||||
c26220c9177c146d6ce21e2f964de47b3dbbab85824e93908d66fa080e13286f
|
||||
0759a60e09710321dfc42b09518516398785f60e150012d15be88bbb2ea788db
|
||||
8ef40f13c6192bd8defa7ac0b54ce2454e71b55867bdafc51ecb714d02abfd1a
|
||||
9146e0ede1c0e9014341ef0859ca62d230bea5d6535d800591a796e8dfe1dff9
|
||||
6eeb683ee4674fd5553fdc2ca32d77ee733de0e654c6f230f881abf5752696ba
|
||||
3
data/ioc/spyware/mvt/2023-04-11_quadream/README.md
Normal file
3
data/ioc/spyware/mvt/2023-04-11_quadream/README.md
Normal file
@@ -0,0 +1,3 @@
|
||||
# Quadream KingSpawn indicators
|
||||
|
||||
Quadream indicators from [Citizen Lab](https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/) and [Microsoft](https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/) reports.
|
||||
164
data/ioc/spyware/mvt/2023-04-11_quadream/domains.txt
Normal file
164
data/ioc/spyware/mvt/2023-04-11_quadream/domains.txt
Normal file
@@ -0,0 +1,164 @@
|
||||
addictmetui.com
|
||||
adeptary.com
|
||||
agronomsdoc.com
|
||||
allplaces.online
|
||||
aniarchit.com
|
||||
aqualizas.com
|
||||
bcarental.com
|
||||
beendos.com
|
||||
bestteamlife.com
|
||||
betterstime.com
|
||||
bgnews-bg.com
|
||||
bikersrental.com
|
||||
biznomex.com
|
||||
brushyourteeth.online
|
||||
careerhub4u.com
|
||||
careers4ad.com
|
||||
choccoline.com
|
||||
classiccolor.live
|
||||
cleanitgo.info
|
||||
climatestews.com
|
||||
codinerom.com
|
||||
codingstudies.com
|
||||
comeandpet.me
|
||||
countshops.com
|
||||
ctbgameson.com
|
||||
datacentertime.com
|
||||
deliverystorz.com
|
||||
designaroo.org
|
||||
designspacing.org
|
||||
digital-mar.com
|
||||
dressuse.com
|
||||
dsudro.com
|
||||
earthyouwantiis.com
|
||||
eccocredit.com
|
||||
ecologitics.com
|
||||
eedloversra.online
|
||||
e-gaming.online
|
||||
elektrozi.com
|
||||
elvacream.com
|
||||
enrollering.com
|
||||
foodyplates.com
|
||||
forestaaa.com
|
||||
fosterunch.com
|
||||
foundurycolletive.com
|
||||
fullaniimal.com
|
||||
fullmoongreyparty.org
|
||||
fullstorelife.com
|
||||
furiamoc.com
|
||||
gameboysess.com
|
||||
gameizes.com
|
||||
gamezess.com
|
||||
gamingcolonys.com
|
||||
gardenearthis.com
|
||||
garilc.com
|
||||
globepayinfo.com
|
||||
goodsforuw.com
|
||||
goshopeerz.com
|
||||
gosport24.com
|
||||
greenrunners.org
|
||||
healthcovid19.com
|
||||
hinterfy.com
|
||||
homeigardens.com
|
||||
homelosite.com
|
||||
hopsite.online
|
||||
hotalsextra.com
|
||||
hoteliqo.com
|
||||
hoteluxurysm.com
|
||||
incollegely.org
|
||||
inneture.com
|
||||
i-reality.online
|
||||
iwoodstor.xyz
|
||||
job4uhunt.com
|
||||
jungelfruitime.com
|
||||
jyfa.xyz
|
||||
kidsfunland.org
|
||||
kidzalnd.org
|
||||
kidzlande.com
|
||||
kikocruize.com
|
||||
koraliowe.com
|
||||
lateparties.com
|
||||
linestrip.online
|
||||
localtallk.store
|
||||
londonistory.com
|
||||
luxario.org
|
||||
meehealth.org
|
||||
mikontravels.com
|
||||
monvesting.com
|
||||
motorgamings.com
|
||||
mwww.ro
|
||||
naturemeter.org
|
||||
navadatime.com
|
||||
newsandlocalupdates.com
|
||||
newsbuiltin.online
|
||||
newslocalupdates.com
|
||||
newz-globe.com
|
||||
noraplant.com
|
||||
nordmanetime.com
|
||||
novinite.biz
|
||||
nutureheus.com
|
||||
pachadesert.com
|
||||
pennywines.com
|
||||
planetosgame.com
|
||||
planningly.org
|
||||
playozas.com
|
||||
powercodings.com
|
||||
projectoid.org
|
||||
razzodev.com
|
||||
recover-your-body.xyz
|
||||
recovery-plan.org
|
||||
redanddred.com
|
||||
reloadyourbrowser.info
|
||||
rentalproct.com
|
||||
retailmark.net
|
||||
runningandbeyond.org
|
||||
setclass.live
|
||||
sevensdfe.com
|
||||
shoeszise.xyz
|
||||
shoplifys.com
|
||||
shoppingeos.com
|
||||
sidelot.org
|
||||
skyphotogreen.com
|
||||
space-moon.com
|
||||
sseamb.com
|
||||
stayle.co
|
||||
stockstiming.org
|
||||
studiesutshifts.com
|
||||
studyreaserch.com
|
||||
study-search.com
|
||||
studyshifts.com
|
||||
studysliii.com
|
||||
styleanature.com
|
||||
stylelifees.com
|
||||
subcloud.online
|
||||
sunclub.site
|
||||
sunnyweek.site
|
||||
sunsandlights.com
|
||||
takebreak.io
|
||||
takestox.com
|
||||
teachlearning.org
|
||||
techpowerlight.com
|
||||
thegreenlight.xyz
|
||||
thenewsfill.com
|
||||
thepila.com
|
||||
thetimespress.com
|
||||
timeeforsports.com
|
||||
tokenberries.com
|
||||
topuprr.com
|
||||
transformaition.com
|
||||
treerroots.com
|
||||
unitedyears.com
|
||||
vinoneros.com
|
||||
wellnessjane.org
|
||||
whiteandpiink.com
|
||||
white-rhino.online
|
||||
wikipedoptions.com
|
||||
wilddog.site
|
||||
wildhour.store
|
||||
wombatcash.com
|
||||
womnbling.com
|
||||
youristores.com
|
||||
zebra-arts.com
|
||||
zedforme.com
|
||||
zeebefg.com
|
||||
zooloow.com
|
||||
2
data/ioc/spyware/mvt/2023-04-11_quadream/file_paths.txt
Normal file
2
data/ioc/spyware/mvt/2023-04-11_quadream/file_paths.txt
Normal file
@@ -0,0 +1,2 @@
|
||||
/private/var/db/com.apple.xpc.roleaccountd.staging/subridged
|
||||
/private/var/db/com.apple.xpc.roleaccountd.staging/PlugIns/fud.appex/
|
||||
40
data/ioc/spyware/mvt/2023-04-11_quadream/generate_stix.py
Normal file
40
data/ioc/spyware/mvt/2023-04-11_quadream/generate_stix.py
Normal file
@@ -0,0 +1,40 @@
|
||||
import sys
|
||||
import os
|
||||
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
if os.path.isfile("kingspawn.stix2"):
|
||||
os.remove("kingspawn.stix2")
|
||||
|
||||
with open("domains.txt") as f:
|
||||
domains = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("file_paths.txt") as f:
|
||||
filepaths = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("processes.txt") as f:
|
||||
processes = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
res = []
|
||||
malware = Malware(name="KingSpawn", is_family=False, description="IOCs related to Quadream KingsPawn or Reign spyware")
|
||||
res.append(malware)
|
||||
for d in domains:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for f in filepaths:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:path='{}']".format(f), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for p in processes:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[process:name='{}']".format(p), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
bundle = Bundle(objects=res)
|
||||
with open("kingspawn.stix2", "w+") as f:
|
||||
f.write(bundle.serialize(indent=4))
|
||||
print("kingspawn.stix2 file created")
|
||||
4024
data/ioc/spyware/mvt/2023-04-11_quadream/kingspawn.stix2
Normal file
4024
data/ioc/spyware/mvt/2023-04-11_quadream/kingspawn.stix2
Normal file
File diff suppressed because it is too large
Load Diff
1
data/ioc/spyware/mvt/2023-04-11_quadream/processes.txt
Normal file
1
data/ioc/spyware/mvt/2023-04-11_quadream/processes.txt
Normal file
@@ -0,0 +1 @@
|
||||
com.apple.avcapture
|
||||
@@ -0,0 +1,76 @@
|
||||
|
||||
8181data.com
|
||||
adcreatorfree.net
|
||||
addatamarket.net
|
||||
adsfreetracking.com
|
||||
adsspacefree.com
|
||||
adtreks.net
|
||||
ans7tv.net
|
||||
anstv.net
|
||||
baba8861.com
|
||||
backuprabbit.com
|
||||
balancedcistern.com
|
||||
beifang6688.com
|
||||
bestnewsfeed.net
|
||||
bestonlineads.net
|
||||
businessvideonews.com
|
||||
click-farm.net
|
||||
cloudsponcer.com
|
||||
cloudyundat.com
|
||||
crowd-tracking.com
|
||||
cruxness.com
|
||||
datamarketplace.net
|
||||
dreamshoppingphoto.com
|
||||
edgeserverapi.com
|
||||
fastads4free.com
|
||||
fastfindads.net
|
||||
floranewstoday.net
|
||||
freeaddelivery.com
|
||||
freeadvertisementsonline.com
|
||||
futebolnoticia.net
|
||||
globalpromonet.com
|
||||
growthtransport.com
|
||||
haidishabu.com
|
||||
healthymarshmellow.com
|
||||
improvingfitness.net
|
||||
kickoffortea.com
|
||||
koppercables.com
|
||||
mechanicsfoundry.com
|
||||
mediaclickers.net
|
||||
mediumgates.com
|
||||
mobilegamerstats.com
|
||||
mysyncs.com
|
||||
networkaccessory.com
|
||||
nimbulusdrifting.net
|
||||
onlineadvalue.com
|
||||
pandabeachmetrics.com
|
||||
papershopclip.com
|
||||
perksync.com
|
||||
pleekerion.com
|
||||
qinggang26.com
|
||||
quickdatafeed.com
|
||||
regionalcdn.net
|
||||
scoreclicks.com
|
||||
senlin83.com
|
||||
smartsavingmarketing.com
|
||||
snoweeanalytics.com
|
||||
statherder.com
|
||||
static3video.com
|
||||
stretchingnoun.com
|
||||
swimporchingnow.com
|
||||
tagclick-cdn.com
|
||||
tangpingzy.com
|
||||
tempoinformacao.net
|
||||
tenvmms.cloud
|
||||
titanhound.com
|
||||
topographyupdates.com
|
||||
tradeadvantages.com
|
||||
unlimitedteacup.com
|
||||
updateads.net
|
||||
updatedadsfree.com
|
||||
virtuallaughing.com
|
||||
weathercasting.net
|
||||
web-trackers.com
|
||||
wheelgroupmarketing.com
|
||||
windpoweredalgae.com
|
||||
yuxbaozh1.com
|
||||
@@ -0,0 +1,36 @@
|
||||
travislong544@yahoo.com
|
||||
norsarall87@outlook.com
|
||||
jesteristhebestband@gmail.com
|
||||
christineashleysmith@gmail.com
|
||||
homicidalwombat@yahoo.com
|
||||
nigelmlevy@gmail.com
|
||||
supercatman15@hotmail.com
|
||||
shannonkelly404@gmail.com
|
||||
superhugger21@gmail.com
|
||||
parkourdiva@yahoo.com
|
||||
naturelover1972@outlook.com
|
||||
sasquatchdreams@outlook.com
|
||||
trunkfullofbeans@yahoo.com
|
||||
danielhbarnes2@gmail.com
|
||||
patriotsman121@gmail.com
|
||||
wheelsordoors@yahoo.com
|
||||
janahodges324@gmail.com
|
||||
mibarham@outlook.com
|
||||
tinyjax89@gmail.com
|
||||
nonbaguette@yahoo.com
|
||||
slbrimms96@outlook.com
|
||||
costamaria91@outlook.com
|
||||
hyechink97@gmail.com
|
||||
greatoleg9393@mail.com
|
||||
popanddangle@outlook.com
|
||||
maxjar90@mail.com
|
||||
chongwonnam@gmail.com
|
||||
wopperplopper1@aol.com
|
||||
bajablaster101@gmail.com
|
||||
carlson31773@outlook.com
|
||||
fsozgur@outlook.com
|
||||
soccerchk835@gmail.com
|
||||
stephamartinez122@gmail.com
|
||||
popcornkerner@gmail.com
|
||||
pupperoni1989@outlook.com
|
||||
biglesterjames5@gmail.com
|
||||
@@ -0,0 +1,42 @@
|
||||
import sys
|
||||
import os
|
||||
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
malware_name = "OperationTriangulation"
|
||||
stix_name = "operation_triangulation.stix2"
|
||||
if os.path.isfile(stix_name):
|
||||
os.remove(stix_name)
|
||||
|
||||
with open("domains.txt") as f:
|
||||
domains = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("processes.txt") as f:
|
||||
processes = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("emails.txt") as f:
|
||||
emails = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
res = []
|
||||
malware = Malware(name=malware_name, is_family=False, description="IOCs related to Operation Triangulation iOS spyware documented by Kaspersky Labs.")
|
||||
res.append(malware)
|
||||
for d in domains:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for p in processes:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[process:name='{}']".format(p), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for e in emails:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[email-addr:value='{}']".format(e), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
bundle = Bundle(objects=res)
|
||||
with open(stix_name, "w+") as f:
|
||||
f.write(bundle.serialize(indent=4))
|
||||
print("{} file created".format(stix_name))
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1 @@
|
||||
BackupAgent
|
||||
@@ -0,0 +1,7 @@
|
||||
dns.win10micros0ft.com
|
||||
www.andropwn.xyz
|
||||
update.umisen.com
|
||||
alxc.tbtianyan.com
|
||||
yxwasec.com
|
||||
smiss.imwork.net
|
||||
huaxin-bantian.duckdns.org
|
||||
@@ -0,0 +1,51 @@
|
||||
import sys
|
||||
import os
|
||||
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
malware_name = "WyrmSpy_DragonEgg"
|
||||
stix_name = "wyrmspy_dragonegg.stix2"
|
||||
if os.path.isfile(stix_name):
|
||||
os.remove(stix_name)
|
||||
|
||||
with open("domains.txt") as f:
|
||||
domains = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("ip-addresses.txt") as f:
|
||||
ips = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("sha256.txt") as f:
|
||||
sha256 = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("package_names.txt") as f:
|
||||
package_names = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
res = []
|
||||
malware = Malware(name=malware_name, is_family=False, description="IOCs related to WyrmSpy and DragonEgg Android spyware documented by Lookout.")
|
||||
res.append(malware)
|
||||
for d in domains:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for ip in ips:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[ipv4-addr:value='{}']".format(ip),
|
||||
pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for s in sha256:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:hashes.sha256='{}']".format(s), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for p in package_names:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[app:id='{}']".format(p), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
bundle = Bundle(objects=res)
|
||||
with open(stix_name, "w+") as f:
|
||||
f.write(bundle.serialize(indent=4))
|
||||
print("{} file created".format(stix_name))
|
||||
@@ -0,0 +1,5 @@
|
||||
116.205.4.18
|
||||
121.42.149.52
|
||||
118.193.39.165
|
||||
121.201.109.98
|
||||
103.43.17.99
|
||||
@@ -0,0 +1,7 @@
|
||||
com.android.system.configs.service
|
||||
com.hx.rootwifi
|
||||
com.adobe.flash.listen.beta
|
||||
com.adobe.flash.jni
|
||||
com.adobe.flash.dex
|
||||
remote.google.rt.googleservice
|
||||
xx.an
|
||||
34
data/ioc/spyware/mvt/2023-07-25_wyrmspy_dragonegg/sha256.txt
Normal file
34
data/ioc/spyware/mvt/2023-07-25_wyrmspy_dragonegg/sha256.txt
Normal file
@@ -0,0 +1,34 @@
|
||||
b66847d571e471ac78ffa11a82dded5ac6d2f52b25304adbfab90716d22c0905
|
||||
6caf068e1c0be245083aa6c3b92bd34909cb57d3d989cf509db18a8be4045fc5
|
||||
43193e32872c589785ae720da875e5e20099a5fa36c8aee838034c91986ed34c
|
||||
4355b4eb3d73b96577194cbd0ff319e0f4ff02d0cabdde8b15e1abd1840e6481
|
||||
6b9a540801613a2abd15b5994def2ac4904a896e14e1ab364b032de5b3d1e098
|
||||
8bf60e625d628e39320015de654933947b56621d8a4538f9be55c27ffc29a99c
|
||||
db389366540d43ffa1451fae16e0ab34bf266b9c88aff65d919f474e9430d5d6
|
||||
9bcaf637cfeab36e5f4301d4f018f7e6b8e9e30db108e7b7668bdb2250110407
|
||||
8c01132a0c1c7799e44608247f93d4680935f36df3fc94d59c7da83afe375ff2
|
||||
8d7fd7dcf5f0e144f3e3cc96ebf3ab8789d0d8edaeefa65e0f03dac67c1f046f
|
||||
82c75b521fd03f6c4074494f0e3c46cc7aa8e5b88c28ebb08401a50109206668
|
||||
7a618ac4a0fb2b68df540554ee99aa48caa148b3dd2800777a084a7322efe22f
|
||||
36d72fedc17be9936f182b38ca98c40a0f9ba44cac170bd63cbded9568452d25
|
||||
1d76df42d77080a96f885ed31ab8a83f4f985e071e715fd54297dab398c4be6b
|
||||
6fc9a0881719ddfd1973f7ce62fa000279fda2ab5a03a4676e15c5e838b8c7ff
|
||||
af139a04f314ccfb31a1d48ae9a434f26cb5fe1ca173acc479e7dc95a1f90260
|
||||
d773c969c1be976410b9d8304fe6c07b142766f7bec2242e0eb5c18d3503eec1
|
||||
38e18d79b83e7c0afbe1ac246a7a5fe6b2783adc085e9aeb2ec610e76f5ccaad
|
||||
92ce9de120ebd88f0126644697e9840489b2c2497e5c99acfa7dd680d98cf075
|
||||
c45a82123c985f2fd18e6763b76443ba6c49d12df3d7fe445a19c8fcdc6de846
|
||||
4fd5f3c3e4bc4c354d0e4de0bebfdb85e1bab5e5f1ea24ce18b947377a7e2423
|
||||
fa4a0aaa6b8f25e8f177ce2e3202c933c2358d4a45d94427dd54df83778a4225
|
||||
79028b82a4715160db89bb6ea7d7e2961e0f0e084b8abc21bb4d677ec4cc8d5a
|
||||
9ba0078a12f7cd515303aefdb151d65a2d3cb1188242e72e3bd9e629dc246582
|
||||
017f30bf39d897d1b52c6d035dde5d2578d18d774b39fe76daf67f53d9a08ce9
|
||||
b29cddc09cf65b4cda6b3898257f978265478af3ed3217c1be2c3fb729233739
|
||||
77504bf799b9a35d493b2363e7665b3dc3b9db32f337f03db1aabe4b3c5a5e05
|
||||
2594d654e4e820495392424e52c79d8ea89a8063ebb05bc6cf9f8547605db3a1
|
||||
48cd527254084d5e80cd86155a9a23702bdbd586752d27c6e3b6260fa8a86eb4
|
||||
79a316353747d11ca0ac00e6cbe1e1ce80061d067d9ff3274be33c40d12ca5de
|
||||
0bdefeee83c758c45a54b20674208e1fa26a2d47c862abdffd2c39a345379e0a
|
||||
68494cde4ee344cba80e8651c579418f2ce534018d88745797f030a3115ed19b
|
||||
9ef830205b7cf0d59d495f722fc61cc3a9f938972e24bae05fa8620b43ed264a
|
||||
ee90d36b384d92a0c9609eab0a3fe0f2af245c281473b4ff0cdd8caeed34fe97
|
||||
File diff suppressed because it is too large
Load Diff
21
data/ioc/spyware/mvt/LICENSE
Normal file
21
data/ioc/spyware/mvt/LICENSE
Normal file
@@ -0,0 +1,21 @@
|
||||
MIT License
|
||||
|
||||
Copyright (c) 2022 MVT
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
of this software and associated documentation files (the "Software"), to deal
|
||||
in the Software without restriction, including without limitation the rights
|
||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
copies of the Software, and to permit persons to whom the Software is
|
||||
furnished to do so, subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
SOFTWARE.
|
||||
9
data/ioc/spyware/mvt/README.md
Normal file
9
data/ioc/spyware/mvt/README.md
Normal file
@@ -0,0 +1,9 @@
|
||||
# mvt-indicators
|
||||
|
||||
This repository contains the index to known publicly available indicators of compromise comptable with MVT. It also contains indicators file created and contributed by the community, gathered from published research.
|
||||
|
||||
## How to contribute new indicators of compromise
|
||||
|
||||
To contribute new indicators of compromise you are invited to submit pull requests to this repository including a new folder in the format of `YYYY-MM-DD_short_description`, containing text files for each indicators category as well as a [STIX2](https://oasis-open.github.io/cti-documentation/stix/intro.html) file to be used with MVT. To generate a STIX2 file you can use the utility [stix2gen](https://github.com/botherder/stix2gen) (please refer to its repository for instructions on how to use).
|
||||
|
||||
When submitting a new pull request, please include the source of these indicators as well as any reference to related publicly available research and documentation.
|
||||
0
data/ioc/spyware/mvt/ResidentBat/domains.txt
Normal file
0
data/ioc/spyware/mvt/ResidentBat/domains.txt
Normal file
87
data/ioc/spyware/mvt/ResidentBat/generate_stix.py
Normal file
87
data/ioc/spyware/mvt/ResidentBat/generate_stix.py
Normal file
@@ -0,0 +1,87 @@
|
||||
import sys
|
||||
import os
|
||||
from stix2.v21 import (Indicator, Malware, Relationship, Bundle)
|
||||
|
||||
|
||||
from stix2 import CustomObservable
|
||||
|
||||
# @CustomObservable('x-new-observable-2', [
|
||||
# ('a_property', properties.StringProperty(required=True)),
|
||||
# ('property_2', properties.IntegerProperty()),
|
||||
# ], [
|
||||
# 'a_property'
|
||||
# ])
|
||||
# class NewObservable2():
|
||||
# pass
|
||||
|
||||
def hash_format(hash):
|
||||
if len(hash) == 32:
|
||||
return "md5"
|
||||
elif len(hash) == 40:
|
||||
return "sha1"
|
||||
elif len(hash) == 64:
|
||||
return "sha256"
|
||||
else:
|
||||
return None
|
||||
|
||||
if __name__ == "__main__":
|
||||
malware_name = "ResidentBat"
|
||||
stix2_file_name = "residentbat.stix2"
|
||||
if os.path.isfile(stix2_file_name):
|
||||
os.remove(stix2_file_name)
|
||||
|
||||
with open("domains.txt") as f:
|
||||
domains = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("ip-addresses.txt") as f:
|
||||
ips = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("package_names.txt") as f:
|
||||
package_names = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("package_cert_hashes.txt") as f:
|
||||
package_cert_hashes = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("sha256.txt") as f:
|
||||
sha256_hashes = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
res = []
|
||||
malware = Malware(name=malware_name, is_family=False, description="IOCs for ResidentBat")
|
||||
res.append(malware)
|
||||
for d in domains:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for ip in ips:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[ipv4-addr:value='{}']".format(ip),
|
||||
pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for package_name in package_names:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[app:id='{}']".format(package_name), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for cert_hash in package_cert_hashes:
|
||||
hash_type = hash_format(cert_hash)
|
||||
if not hash_type:
|
||||
raise ValueError("Unknown hash type for {}".format(cert_hash))
|
||||
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern=f"[app:cert.{hash_type}='{cert_hash}']", pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for sha256_hash in sha256_hashes:
|
||||
if not hash_format(sha256_hash) == "sha256":
|
||||
raise ValueError("File hash is not in SHA256 format: {}".format(sha256_hash))
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern=f"[file:hashes.sha256='{sha256_hash}']", pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
|
||||
bundle = Bundle(objects=res)
|
||||
with open(stix2_file_name, "w+") as f:
|
||||
f.write(bundle.serialize(pretty=True, indent=4))
|
||||
print("{} file created".format(stix2_file_name))
|
||||
24
data/ioc/spyware/mvt/ResidentBat/ip-addresses.txt
Normal file
24
data/ioc/spyware/mvt/ResidentBat/ip-addresses.txt
Normal file
@@ -0,0 +1,24 @@
|
||||
62.109.26.144
|
||||
91.107.122.180
|
||||
5.129.230.104
|
||||
82.146.35.54
|
||||
62.109.12.75
|
||||
79.132.136.191
|
||||
83.220.169.120
|
||||
5.129.213.114
|
||||
5.253.63.176
|
||||
62.109.11.98
|
||||
62.109.19.123
|
||||
185.248.103.85
|
||||
5.129.231.158
|
||||
185.18.54.246
|
||||
91.240.87.211
|
||||
185.248.103.128
|
||||
185.248.103.247
|
||||
188.120.230.46
|
||||
37.46.133.87
|
||||
5.253.61.156
|
||||
79.132.141.31
|
||||
37.46.128.62
|
||||
91.228.152.4
|
||||
91.192.102.69
|
||||
8
data/ioc/spyware/mvt/ResidentBat/package_cert_hashes.txt
Normal file
8
data/ioc/spyware/mvt/ResidentBat/package_cert_hashes.txt
Normal file
@@ -0,0 +1,8 @@
|
||||
18afc5c6bfaee504a26291f6bf3e6f823dbedd54bba0c4acac2e7c2414b3e24d
|
||||
c1884e617348ebbdfe7cfe5fc99945b37296d6ebc6059bb74fbaeea277d32941
|
||||
e5016f3cfb937d502dabedc32ca3bdef3bbcce032fb3b1bff3b9c6482895f4fd
|
||||
d12616542268d32329f1c4357b5d5a57e954e13d2338d27bb8439794291b8c6d
|
||||
3e9f1192e33cb851b48479629c93d29770a4f76af00f1e42a3c6e7f97db62c79
|
||||
6782039a81a85264acdc6af0973b225ada6009f76faae7f948a1de040bb32f0c
|
||||
a6a067b0d899fb514b7b4597d4fe16fcd4d7e5c361f6c84b3d45ed7e394036c7
|
||||
6d6278ffc80ad9dd1b1c6b445847ce108f3ea5ce349f232689e9b8c1fd10801e
|
||||
8
data/ioc/spyware/mvt/ResidentBat/package_names.txt
Normal file
8
data/ioc/spyware/mvt/ResidentBat/package_names.txt
Normal file
@@ -0,0 +1,8 @@
|
||||
com.google.android.service
|
||||
com.google.bat
|
||||
com.huaweisettingsapp.mkz
|
||||
com.linkedln.service
|
||||
com.oneplussync.bat
|
||||
cm.google.android.apps.assistant
|
||||
com.android.framework.safety
|
||||
com.hihonor.core.service
|
||||
1168
data/ioc/spyware/mvt/ResidentBat/residentbat.stix2
Normal file
1168
data/ioc/spyware/mvt/ResidentBat/residentbat.stix2
Normal file
File diff suppressed because it is too large
Load Diff
9
data/ioc/spyware/mvt/ResidentBat/sha256.txt
Normal file
9
data/ioc/spyware/mvt/ResidentBat/sha256.txt
Normal file
@@ -0,0 +1,9 @@
|
||||
07d39205f9ba159236477a02cdb3350fac4f158e0dbf26576bb50604339b1f42
|
||||
820c394b22b950335eb5cf21bc7df5c7a33081169f41440c74d67e7a8f196960
|
||||
fe05ba40f2d4b15db83524c169d030d097abc6713139ce6068969d97a24aa195
|
||||
77126e749a9c1144ae3cebb8deb0b72fc90d4eb73d1072a69a1248b4f518bb47
|
||||
c3b92d05b105465881c0f68f5cf6c3edb24d2e5317ffd1256cb68c7921fe0721
|
||||
0ed73428c7729806be57989f340a09a323af914f197cc0cbb5509316ca5baf7b
|
||||
48e87bfcaa665bfbfcb027227384905878f090bbc19d02f74c41ade3cafb0950
|
||||
02dc81ea172e45f0a6fd7241fffd1042f6925c52d2f91dee36085634207be4f1
|
||||
0ed73428c7729806be57989f340a09a323af914f197cc0cbb5509316ca5baf7b
|
||||
3016
data/ioc/spyware/mvt/candiru/candiru.stix2
Normal file
3016
data/ioc/spyware/mvt/candiru/candiru.stix2
Normal file
File diff suppressed because it is too large
Load Diff
125
data/ioc/spyware/mvt/candiru/domains.txt
Normal file
125
data/ioc/spyware/mvt/candiru/domains.txt
Normal file
@@ -0,0 +1,125 @@
|
||||
ambiguouscommerce.com
|
||||
antperspective.com
|
||||
aperturebelt.com
|
||||
asknapkin.com
|
||||
barnsecret.com
|
||||
baseagriculture.com
|
||||
basicstraw.com
|
||||
basinapposite.com
|
||||
beneathbreadth.com
|
||||
bizarreclassify.com
|
||||
blockroster.net
|
||||
bondmuscle.com
|
||||
breadgroomer.com
|
||||
bronzemonth.com
|
||||
browniebell.com
|
||||
bypassbirch.com
|
||||
bypasscalculate.com
|
||||
bypasscommerce.com
|
||||
calmbase.org
|
||||
cartoondrop.net
|
||||
chickenstrawberry.com
|
||||
citecivilization.com
|
||||
closetmeat.com
|
||||
commonclever.com
|
||||
concretebottle.com
|
||||
conquerconfess.com
|
||||
containsnow.com
|
||||
contradictionblindness.com
|
||||
convincechaotic.com
|
||||
cooperatedisinfect.net
|
||||
cottonbread.com
|
||||
cranberrybear.com
|
||||
cropcritique.com
|
||||
crossoverdue.com
|
||||
damageconsider.com
|
||||
deardrill.com
|
||||
dediccatedconsideration.com
|
||||
deducedefend.com
|
||||
deliverconcern.net
|
||||
densefoot.com
|
||||
desireeclipse.com
|
||||
detaincharity.net
|
||||
deterdiffusion.com
|
||||
devotionbelief.com
|
||||
distractionfar.com
|
||||
drivesplash.com
|
||||
drummerjourney.com
|
||||
dumplingbell.com
|
||||
electric-prime.com
|
||||
elifluousscintillam.com
|
||||
eminententwine.com
|
||||
exhibitexpanse.com
|
||||
fallaciousessential.net
|
||||
fearevolve.com
|
||||
fileswaper.com
|
||||
finalsalami.com
|
||||
flexibleelevator.com
|
||||
foamdirection.com
|
||||
forecastgarden.com
|
||||
goatsandals.com
|
||||
golfconcert.com
|
||||
groundbreakinginitative.com
|
||||
guitarcalculate.com
|
||||
hostilefauna.com
|
||||
isolatelecture.com
|
||||
jellybat.net
|
||||
jobmarcher.com
|
||||
journeyjest.net
|
||||
kartingrumble.com
|
||||
labyrinthextravagance.org
|
||||
leafconfuse.net
|
||||
lessonhandle.com
|
||||
macrodrop.net
|
||||
macromint.net
|
||||
maturitygenesis.com
|
||||
measurecabin.com
|
||||
mushroompalm.com
|
||||
notableexam.org
|
||||
notionnowadays.com
|
||||
outdooutcome.com
|
||||
parkourbus.com
|
||||
patternperiod.com
|
||||
penslice.com
|
||||
pepperdominate.com
|
||||
prawnbasket.com
|
||||
predictproper.com
|
||||
pressaviation.com
|
||||
profligatecensure.com
|
||||
rollstrech.com
|
||||
romancedrum.com
|
||||
sacrificeprincipal.net
|
||||
salmonpride.net
|
||||
scoreparade.com
|
||||
selectedpazzle.com
|
||||
shareitwork.com
|
||||
signifyslight.com
|
||||
spongefruit.com
|
||||
stablesurface.com
|
||||
strangegarden.org
|
||||
stylebrakedown.com
|
||||
suggestutterly.com
|
||||
sunsetpotential.com
|
||||
tacticscheap.net
|
||||
tidalscreen.com
|
||||
tubeshape.com
|
||||
ultimatematter.info
|
||||
velvetpremier.com
|
||||
windomination.com
|
||||
noc-service-streamer.com
|
||||
fbcdnads.live
|
||||
hilocake.info
|
||||
backxercise.com
|
||||
winmslaf.xyz
|
||||
service-deamon.com
|
||||
online-affiliate-mon.com
|
||||
codeingasmylife.com
|
||||
kenoratravels.com
|
||||
weathercheck.digital
|
||||
colorpallatess.com
|
||||
library-update.com
|
||||
online-source-validate.com
|
||||
grayhornet.com
|
||||
johnshopkin.net
|
||||
eulenformacion.com
|
||||
pochtarossiy.info
|
||||
26
data/ioc/spyware/mvt/candiru/generate_stix.py
Normal file
26
data/ioc/spyware/mvt/candiru/generate_stix.py
Normal file
@@ -0,0 +1,26 @@
|
||||
import sys
|
||||
import os
|
||||
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
malware_name = "Candiru"
|
||||
stix_name = "candiru.stix2"
|
||||
if os.path.isfile(stix_name):
|
||||
os.remove(stix_name)
|
||||
|
||||
with open("domains.txt") as f:
|
||||
domains = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
res = []
|
||||
malware = Malware(name=malware_name, is_family=False, description="IOCs related to Candiru's DevilsTongue.")
|
||||
res.append(malware)
|
||||
for d in domains:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
bundle = Bundle(objects=res)
|
||||
with open(stix_name, "w+") as f:
|
||||
f.write(bundle.serialize(indent=4))
|
||||
print("{} file created".format(stix_name))
|
||||
6
data/ioc/spyware/mvt/cellebrite/README.md
Normal file
6
data/ioc/spyware/mvt/cellebrite/README.md
Normal file
@@ -0,0 +1,6 @@
|
||||
# Cellebrite
|
||||
|
||||
Indicators of compromise to detect Cellebrite on Android.
|
||||
|
||||
Sources:
|
||||
* [From Protest to Peril - Cellebrite Used Against Jordanian Civil Society](https://citizenlab.ca/research/from-protest-to-peril-cellebrite-used-against-jordanian-civil-society/)
|
||||
40
data/ioc/spyware/mvt/cellebrite/cellebrite.stix2
Normal file
40
data/ioc/spyware/mvt/cellebrite/cellebrite.stix2
Normal file
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"type": "bundle",
|
||||
"id": "bundle--ce7cc5a8-fa53-4ff4-841b-cf526f3c8b07",
|
||||
"objects": [
|
||||
{
|
||||
"type": "malware",
|
||||
"spec_version": "2.1",
|
||||
"id": "malware--afe324d5-5d65-4060-92f9-98a5012557d0",
|
||||
"created": "2026-01-22T21:58:55.050482Z",
|
||||
"modified": "2026-01-22T21:58:55.050482Z",
|
||||
"name": "Cellebrite",
|
||||
"description": "IOCs for Cellebrite",
|
||||
"is_family": false
|
||||
},
|
||||
{
|
||||
"type": "indicator",
|
||||
"spec_version": "2.1",
|
||||
"id": "indicator--55319823-913e-4283-9454-156ef3bd285c",
|
||||
"created": "2026-01-22T21:58:55.051167Z",
|
||||
"modified": "2026-01-22T21:58:55.051167Z",
|
||||
"indicator_types": [
|
||||
"malicious-activity"
|
||||
],
|
||||
"pattern": "[app:id='com.client.appA']",
|
||||
"pattern_type": "stix",
|
||||
"pattern_version": "2.1",
|
||||
"valid_from": "2026-01-22T21:58:55.051167Z"
|
||||
},
|
||||
{
|
||||
"type": "relationship",
|
||||
"spec_version": "2.1",
|
||||
"id": "relationship--2abc42e6-3375-4bd3-a746-6199e8af5ce8",
|
||||
"created": "2026-01-22T21:58:55.063505Z",
|
||||
"modified": "2026-01-22T21:58:55.063505Z",
|
||||
"relationship_type": "indicates",
|
||||
"source_ref": "indicator--55319823-913e-4283-9454-156ef3bd285c",
|
||||
"target_ref": "malware--afe324d5-5d65-4060-92f9-98a5012557d0"
|
||||
}
|
||||
]
|
||||
}
|
||||
38
data/ioc/spyware/mvt/cellebrite/generate_stix.py
Normal file
38
data/ioc/spyware/mvt/cellebrite/generate_stix.py
Normal file
@@ -0,0 +1,38 @@
|
||||
import sys
|
||||
import os
|
||||
from stix2.v21 import (Indicator, Malware, Relationship, Bundle)
|
||||
|
||||
|
||||
from stix2 import CustomObservable
|
||||
|
||||
def hash_format(hash):
|
||||
if len(hash) == 32:
|
||||
return "md5"
|
||||
elif len(hash) == 40:
|
||||
return "sha1"
|
||||
elif len(hash) == 64:
|
||||
return "sha256"
|
||||
else:
|
||||
return None
|
||||
|
||||
if __name__ == "__main__":
|
||||
malware_name = "Cellebrite"
|
||||
stix2_file_name = "cellebrite.stix2"
|
||||
if os.path.isfile(stix2_file_name):
|
||||
os.remove(stix2_file_name)
|
||||
|
||||
with open("package_names.txt") as f:
|
||||
package_names = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
res = []
|
||||
malware = Malware(name=malware_name, is_family=False, description="IOCs for Cellebrite")
|
||||
res.append(malware)
|
||||
for package_name in package_names:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[app:id='{}']".format(package_name), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
bundle = Bundle(objects=res)
|
||||
with open(stix2_file_name, "w+") as f:
|
||||
f.write(bundle.serialize(pretty=True, indent=4))
|
||||
print("{} file created".format(stix2_file_name))
|
||||
1
data/ioc/spyware/mvt/cellebrite/package_names.txt
Normal file
1
data/ioc/spyware/mvt/cellebrite/package_names.txt
Normal file
@@ -0,0 +1 @@
|
||||
com.client.appA
|
||||
188
data/ioc/spyware/mvt/indicators.yaml
Normal file
188
data/ioc/spyware/mvt/indicators.yaml
Normal file
@@ -0,0 +1,188 @@
|
||||
indicators:
|
||||
-
|
||||
type: github
|
||||
name: NSO Group Pegasus Indicators of Compromise
|
||||
sources:
|
||||
- Amnesty International
|
||||
references:
|
||||
- https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/
|
||||
github:
|
||||
owner: AmnestyTech
|
||||
repo: investigations
|
||||
branch: master
|
||||
path: 2021-07-18_nso/pegasus.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Predator Spyware Indicators of Compromise
|
||||
sources:
|
||||
- Meta
|
||||
- Amnesty International
|
||||
- Citizen Lab
|
||||
- Cisco
|
||||
- Inside Story
|
||||
- iVerify
|
||||
references:
|
||||
- https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/
|
||||
- https://about.fb.com/news/2021/12/taking-action-against-surveillance-for-hire/
|
||||
- https://blog.talosintelligence.com/mercenary-intellexa-predator/
|
||||
- https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/
|
||||
- https://insidestory.gr/article/predatorgate-ti-egrafan-ta-sms-pagida-poy-elavan-epiheirimaties-ypoyrgoi-kai-dimosiografoi
|
||||
- https://iverify.io/blog/trust-broken-at-the-core
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: intellexa_predator/predator.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: RCS Lab Spyware Indicators of Compromise
|
||||
sources:
|
||||
- Google
|
||||
- Lookout
|
||||
references:
|
||||
- https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan/
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: 2022-06-23_rcs_lab/rcs.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Stalkerware Indicators of Compromise
|
||||
sources:
|
||||
- ECHAP
|
||||
references:
|
||||
- https://github.com/AssoEchap/stalkerware-indicators
|
||||
github:
|
||||
owner: AssoEchap
|
||||
repo: stalkerware-indicators
|
||||
branch: master
|
||||
path: generated/stalkerware.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Surveillance campaign linked to mercenary spyware company
|
||||
sources:
|
||||
- Amnesty International
|
||||
- Google
|
||||
references:
|
||||
- https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
|
||||
- https://www.amnesty.org/en/latest/news/2023/03/new-android-hacking-campaign-linked-to-mercenary-spyware-company/
|
||||
github:
|
||||
owner: AmnestyTech
|
||||
repo: investigations
|
||||
branch: master
|
||||
path: 2023-03-29_android_campaign/malware.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Quadream KingSpawn Indicators of Compromise
|
||||
sources:
|
||||
- Citizen Lab
|
||||
- Microsoft
|
||||
references:
|
||||
- https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: 2023-04-11_quadream/kingspawn.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Operation Triangulation Indicators of Compromise
|
||||
sources:
|
||||
- Kaspersky Lab
|
||||
references:
|
||||
- https://securelist.com/operation-triangulation/109842/
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: 2023-06_01_operation_triangulation/operation_triangulation.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: WyrmSpy and DragonEgg Indicators of Compromise
|
||||
sources:
|
||||
- Lookout
|
||||
references:
|
||||
- https://www.lookout.com/threat-intelligence/article/wyrmspy-dragonegg-surveillanceware-apt41
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: 2023-07-25_wyrmspy_dragonegg/wyrmspy_dragonegg.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Wintego Helios Indicators of Compromise
|
||||
sources:
|
||||
- Amnesty International
|
||||
references:
|
||||
- https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/
|
||||
github:
|
||||
owner: AmnestyTech
|
||||
repo: investigations
|
||||
branch: master
|
||||
path: 2024-05-02_wintego_helios/wintego_helios.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: NoviSpy (Serbia) Indicators of Compromise
|
||||
sources:
|
||||
- Amnesty International
|
||||
references:
|
||||
- https://securitylab.amnesty.org/latest/2024/12/serbia-a-digital-prison-spyware-and-cellebrite-used-on-journalists-and-activists/
|
||||
github:
|
||||
owner: AmnestyTech
|
||||
repo: investigations
|
||||
branch: master
|
||||
path: 2024-12-16_serbia_novispy/novispy.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Candiru (DevilsTongue) Indicators of Compromise
|
||||
sources:
|
||||
- Microsoft
|
||||
- Recorded Future
|
||||
references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
|
||||
- https://www.recordedfuture.com/research/tracking-candirus-devilstongue-spyware
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: candiru/candiru.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: ResidentBat Indicators of Compromise
|
||||
sources:
|
||||
- Reporters Without Borders
|
||||
- RESIDENT.NGO
|
||||
references:
|
||||
- https://rsf.org/en/exclusive-rsf-uncovers-new-spyware-belarus
|
||||
- https://rsf.org/sites/default/files/medias/file/2025/12/report.pdf
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: ResidentBat/residentbat.stix2
|
||||
|
||||
-
|
||||
type: github
|
||||
name: Cellebrite Indicators of Compromise
|
||||
sources:
|
||||
- Citizen Lab
|
||||
references:
|
||||
- https://citizenlab.ca/research/from-protest-to-peril-cellebrite-used-against-jordanian-civil-society/
|
||||
github:
|
||||
owner: mvt-project
|
||||
repo: mvt-indicators
|
||||
branch: main
|
||||
path: cellebrite/cellebrite.stix2
|
||||
22
data/ioc/spyware/mvt/intellexa_predator/README.md
Normal file
22
data/ioc/spyware/mvt/intellexa_predator/README.md
Normal file
@@ -0,0 +1,22 @@
|
||||
# Predator Spyware Indicators of Compromise
|
||||
|
||||
This repository contains network and device indicators of compromised (IoCs) related to the IOS and Android Predator spyware tools developed by the cyber-surveillance company Intellexa (formerly Cytrox). These indicators were extracted from multiple reports including:
|
||||
|
||||
* [Threat Report on the Surveillance-for-Hire Industry](https://about.fb.com/news/2021/12/taking-action-against-surveillance-for-hire/) by Meta
|
||||
* ["Pegasus vs. Predator - Dissident’s Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware"](https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/) report by the Citizen Lab
|
||||
* ["Predator in the wires - Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions"](https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/) report by the Citizen Lab
|
||||
* [Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware](https://blog.talosintelligence.com/mercenary-intellexa-predator/) by Cisco Talos
|
||||
* [Predatorgate: Τι έγραφαν τα SMS-παγίδα που έλαβαν επιχειρηματίες, υπουργοί και δημοσιογράφοι](https://insidestory.gr/article/predatorgate-ti-egrafan-ta-sms-pagida-poy-elavan-epiheirimaties-ypoyrgoi-kai-dimosiografoi) by Inside Story
|
||||
* [Active Lycantrox infrastructure illumination](https://blog.sekoia.io/active-lycantrox-infrastructure-illumination/) by Sekoia
|
||||
* [Predator Spyware Operators Rebuild Multi-Tier Infrastructure to Target Mobile Devices](https://www.recordedfuture.com/predator-spyware-operators-rebuild-multi-tier-infrastructure-target-mobile-devices) by Recorded Future
|
||||
* [The Predator spyware ecosystem is not dead](https://blog.sekoia.io/the-predator-spyware-ecosystem-is-not-dead/) by Sekoia
|
||||
* [Trust Broken at the Core](https://iverify.io/blog/trust-broken-at-the-core) by iVerify
|
||||
* Additional indicators of compromise were identified by the Amnesty Tech Security Lab as part of an independent investigation.
|
||||
|
||||
The STIX2 file can be used with the [Mobile Verification Toolkit](https://github.com/mvt-project/mvt) to look for potential signs of compromise on Android phones and iPhones.
|
||||
|
||||
It includes the following files:
|
||||
* `config_profiles.txt`: UUID of suspicious configuration profiles dropped by the Predator spyware
|
||||
* `predator.stix2`: [STIX2](https://oasis-open.github.io/cti-documentation/stix/intro.html) file containing all indicators
|
||||
* `domains.txt`: list of Predator domains
|
||||
* `file_paths.txt`: file paths for Predator payloads on disk in Android and iOS.
|
||||
@@ -0,0 +1 @@
|
||||
76DAB334-7E17-475D-A5D6-0794EB5818A5
|
||||
569
data/ioc/spyware/mvt/intellexa_predator/domains.txt
Normal file
569
data/ioc/spyware/mvt/intellexa_predator/domains.txt
Normal file
@@ -0,0 +1,569 @@
|
||||
02s.co
|
||||
06g.co
|
||||
09a.co
|
||||
2-gis.kz
|
||||
2y4nothing.xyz
|
||||
5m5.io
|
||||
9o.gg
|
||||
actualite.emergence-mada.com
|
||||
actumali.org
|
||||
addons.news
|
||||
adenuncia.com
|
||||
adibjan.net
|
||||
adservices.gr.com
|
||||
adultpcz.xyz
|
||||
advertsservices.com
|
||||
advfb.xyz
|
||||
affise.app
|
||||
africa-confidentiel.fr
|
||||
afrinew.net
|
||||
air-shopping.net
|
||||
allafrika.live
|
||||
almal-news.com
|
||||
almasryelyuom.com
|
||||
almasrylayoum.com
|
||||
alpineai.uk
|
||||
alraeeenews.com
|
||||
alraeesnews.net
|
||||
altsantiri.news
|
||||
amazing.lab
|
||||
ancienthistory.xyz
|
||||
android-apps.tech
|
||||
angop.co
|
||||
aoatlasescort.com
|
||||
api-apple-buy.com
|
||||
api-telecommunication.com
|
||||
applepps.com
|
||||
apps-ios.net
|
||||
aramexegypt.com
|
||||
astanapark.com
|
||||
atheere.com
|
||||
audit-pvv.com
|
||||
bank-alahly.com
|
||||
bbcsworld.com
|
||||
bbitly.com
|
||||
beroxe.com
|
||||
bestwesternt.com
|
||||
betly.me
|
||||
bit-li.com
|
||||
bitlinkin.xyz
|
||||
bit-li.ws
|
||||
bitlly.live
|
||||
bi.tly.gr.com
|
||||
bi.tly.link
|
||||
bit-ly.link
|
||||
bit-ly.org
|
||||
bitlyrs.com
|
||||
bitshort.info
|
||||
bitt.fi
|
||||
bityl.me
|
||||
bity.ws
|
||||
blacktrail.xyz
|
||||
blitzmedia.live
|
||||
blocoinformativo.com
|
||||
bmw.gr.com
|
||||
bni-madagascar.com
|
||||
bookjob.club
|
||||
breaknews.live
|
||||
brkorage.live
|
||||
browsercheck.services
|
||||
btlin.life
|
||||
buildneeds.net
|
||||
bulk-ads.com
|
||||
bumabara.bid
|
||||
burgerprince.us
|
||||
businesnews.net
|
||||
businessafricaonline.org
|
||||
bw-guardian.com
|
||||
cabinet-salyk.kz
|
||||
candidaturasminfin.info
|
||||
candidaturassonangol.info
|
||||
canyouc.xyz
|
||||
carrefourmisr.com
|
||||
cbbc01.xyz
|
||||
c.betly.me
|
||||
celebrnewz.xyz
|
||||
cellconn.net
|
||||
centent-management.net
|
||||
charmander.xyz
|
||||
chat-support.support
|
||||
chatwithme.store
|
||||
cibeg.online
|
||||
citroen.gr.com
|
||||
ckforward.one
|
||||
clazc.com
|
||||
clckbck.com
|
||||
clcti.net
|
||||
clockupdate.com
|
||||
cloudstatistics.net
|
||||
cloudtimesync.com
|
||||
clubs-k.com
|
||||
cnn.gr.com
|
||||
cnn-portugal.com
|
||||
coazoa.com
|
||||
conlnk.one
|
||||
connectivitychecker.com
|
||||
connectivitycheck.live
|
||||
connectivitycheck.online
|
||||
conodeti.com
|
||||
contents-domain.com
|
||||
copy-note.net
|
||||
corporatebusinesssolution.net
|
||||
correiosdeangola.info
|
||||
cosmote.center
|
||||
covid19masks.shop
|
||||
crashonline.site
|
||||
culniks.info
|
||||
cut.red
|
||||
cyber.country
|
||||
danas.bid
|
||||
dealstransfer.net
|
||||
despachantonline.com
|
||||
despachosnegocios
|
||||
dhll.live
|
||||
distedc.com
|
||||
download4you.xyz
|
||||
dragonair.xyz
|
||||
dw-news.co
|
||||
dzhabarzan.com
|
||||
eagerfox.xyz
|
||||
ebill.cosmote.center
|
||||
edolio5.com
|
||||
efsyn.news
|
||||
efsyn.online
|
||||
eg-gov.org
|
||||
egypt-post.com
|
||||
egyqaz.com
|
||||
ehudaldaa.com
|
||||
e-kgd.kz
|
||||
elpais.me
|
||||
elwatnanews.com
|
||||
emvolio-gov.gr
|
||||
engine.ninja
|
||||
enigmase.xyz
|
||||
enikos.news
|
||||
ereportaz.news
|
||||
escortbabesluxo.com
|
||||
espressonews.gr.com
|
||||
etisalategypt.tech
|
||||
etisalatgreen.com
|
||||
eventes.org
|
||||
eventnews.live
|
||||
ewish.cards
|
||||
exclusivo24h.com
|
||||
factosdiarios.co
|
||||
factosdiarios.online
|
||||
fastdownload.me
|
||||
fastnews.biz
|
||||
fast-notify.com
|
||||
fastuploads.xyz
|
||||
fbc8213450838f7ae251d4519c195138.xyz
|
||||
fdnews.info
|
||||
ferrari.gr.com
|
||||
ffoxnewz.com
|
||||
fimes.gr.com
|
||||
fireup.xyz
|
||||
fisherman.engine.ninja
|
||||
flash.gr.com
|
||||
flexipagez.com
|
||||
flowercafee.com
|
||||
flytaps.com
|
||||
folha8.net
|
||||
folha9.info
|
||||
folha-9.com
|
||||
forwardeshoptt.com
|
||||
fr-monde.com
|
||||
gabzmus.com
|
||||
geloraku.id
|
||||
get-location.com
|
||||
get-location.net
|
||||
getsignalapps.com
|
||||
getsignalapps.live
|
||||
getupdatesnow.xyz
|
||||
glbnews.live
|
||||
goldenscent.net
|
||||
goldenscint.com
|
||||
goldescent.com
|
||||
gorlovski.com
|
||||
gorows.live
|
||||
gosokm.com
|
||||
gostosadeluxo.com
|
||||
growebservice.com
|
||||
grupohel.social
|
||||
grvnews.live
|
||||
guardian-tt.me
|
||||
guardnew.live
|
||||
guardnews.live
|
||||
gulfsports.info
|
||||
gulfsports.live
|
||||
gulfweather.live
|
||||
heaven.army
|
||||
heiiasjournai.com
|
||||
hellasjournal.company
|
||||
hellasjournal.website
|
||||
hellottec.art
|
||||
hempower.shop
|
||||
highclub.life
|
||||
hopnope.xyz
|
||||
icloudeu.com
|
||||
icloudflair.com
|
||||
iibt.xyz
|
||||
ikea-egypt.net
|
||||
ilnk.xyz
|
||||
imparcialpress.com
|
||||
inews.gr.com
|
||||
informacao24.com
|
||||
informationrank.net
|
||||
informburo.info
|
||||
infosms-a.site
|
||||
in-politics.com
|
||||
inservices.digital
|
||||
insider.gr.com
|
||||
instagam.click
|
||||
instagam.in
|
||||
instagam.photos
|
||||
instegram.co
|
||||
insurance.gr.com
|
||||
intercontinentalhg.com
|
||||
intnews.world
|
||||
invoker.icu
|
||||
ios-apps.store
|
||||
iosmnbg.com
|
||||
itcgr.live
|
||||
itly.link
|
||||
itter.me
|
||||
jakalas.online
|
||||
jofki.com
|
||||
jornaldeangola.co
|
||||
jornaldeangola.info
|
||||
jornaldeangola.net
|
||||
jornalf8.co
|
||||
jornalf8.com
|
||||
jquery-updater.xyz
|
||||
jumia-egy.com
|
||||
kalwaski.xyz
|
||||
kapital-news.com
|
||||
kathimerini.news
|
||||
kejoranews.net
|
||||
kinder.engine.ninja
|
||||
koenigseggg.com
|
||||
kohaicorp.com
|
||||
kollesa.com
|
||||
koora-egypt.com
|
||||
kormoran.bid
|
||||
kranos.gr.com
|
||||
krisha-kz.com
|
||||
kroal.com
|
||||
kz-news.cc
|
||||
kz-shops.me
|
||||
ladiesclubhouse.com
|
||||
lamborghini-s.shop
|
||||
landingpge.xyz
|
||||
landingpg.xyz
|
||||
leanwithme.xyz
|
||||
leefco.net
|
||||
lexpress.me
|
||||
lexpress-mg.xyz
|
||||
lexpressmg.xyz
|
||||
lifestyleshops.net
|
||||
lilpastanews.co
|
||||
limk.one
|
||||
linkit.cloud
|
||||
linkit.digital
|
||||
link-m.xyz
|
||||
link-protection.com
|
||||
linktothisa.xyz
|
||||
liponals.store
|
||||
live24.gr.com
|
||||
liveco.live
|
||||
livingwithbadkidny.xyz
|
||||
llinkedin.net
|
||||
lnkedin.org
|
||||
localegem.net
|
||||
lttlnk.net
|
||||
lubentv.com
|
||||
lusofonia-mundo.com
|
||||
lylink.online
|
||||
mada.sahia-mijoro.com
|
||||
magnum-kz.com
|
||||
makeitshort.xyz
|
||||
mastershop.biz
|
||||
mb-ph.net
|
||||
md-news-direct.com
|
||||
midi-madgasikara.co
|
||||
mifcbook.link
|
||||
miniiosapps.xyz
|
||||
mitube1.link
|
||||
mlinks.ws
|
||||
mmegi.co
|
||||
mobnetlink1.com
|
||||
mobnetlink2.com
|
||||
mobnetlink3.com
|
||||
moncn.co
|
||||
mozillaupdate.xyz
|
||||
msas.ws
|
||||
msbsck.com
|
||||
mujimbo.co
|
||||
mujimbos.co
|
||||
mujmbosnoticias.com
|
||||
mulherevips.com
|
||||
mult.icaixa.info
|
||||
mundodenoticias.online
|
||||
mycoffeeshop.shop
|
||||
myfawry.net
|
||||
myfcbk.net
|
||||
mytrips.quest
|
||||
myutbe.net
|
||||
mywebsitevpstest.xyz
|
||||
nabde.app
|
||||
nabd.site
|
||||
nassosblog.gr.com
|
||||
nemshi.net
|
||||
nemshi-news.live
|
||||
nemshi-news.xyz
|
||||
networkenterprise.net
|
||||
newsbeast.gr.com
|
||||
newslive2.xyz
|
||||
newspool.net
|
||||
newsreuter.com
|
||||
newsworldsports.co
|
||||
newzeto.xyz
|
||||
newzgroup.xyz
|
||||
niceonase.com
|
||||
niceonesa.net
|
||||
nikjol.xyz
|
||||
nissan.gr.com
|
||||
nm-weather.live
|
||||
nospam.kz
|
||||
notifications-sec.com
|
||||
notify-kz.info
|
||||
notify-service.biz
|
||||
novojornal.co
|
||||
novojornal.info
|
||||
novosti.bid
|
||||
nur-news.com
|
||||
oilgy.xyz
|
||||
olexegy.com
|
||||
olimpbets.kz
|
||||
olxeg.com
|
||||
omanreal.net
|
||||
omeega.xyz
|
||||
ongs.life
|
||||
ongsworld.com
|
||||
onlineservices.gr.com
|
||||
onlinewebinarmarketing.com
|
||||
orangegypt.co
|
||||
orchomenos.news
|
||||
ordas-kz.com
|
||||
otaupdatesios.com
|
||||
paok-24.com
|
||||
pastepast.net
|
||||
pasteposta.com
|
||||
pdfviewer.app
|
||||
pelovkin.com
|
||||
people-beeline.com
|
||||
peticaonline.comv
|
||||
plastictoysworld.com
|
||||
platinalines.com
|
||||
playestore.net
|
||||
plinkypong.com
|
||||
pocopoc.xyz
|
||||
podcastnow.club
|
||||
politika.bid
|
||||
politique-koaci.info
|
||||
popup-pw.info
|
||||
portalxa.com
|
||||
post-kz.info
|
||||
post-notify.info
|
||||
prmopromo.com
|
||||
pronews.gr.com
|
||||
protothema.live
|
||||
proupload.xyz
|
||||
ps1link.xyz
|
||||
ps2link.xyz
|
||||
qamqors.net
|
||||
qazsporttv.com
|
||||
quick-ads.com
|
||||
quickupdates.xyz
|
||||
qwert.xyz
|
||||
qwxzyl.com
|
||||
rcuples.com
|
||||
redeitt.com
|
||||
redirecting.live
|
||||
redirecting.page
|
||||
redirto.info
|
||||
rozavetrovv.com
|
||||
safelyredirecting.com
|
||||
safelyredirecting.digital
|
||||
schedulefestival.com
|
||||
sdntribune.co
|
||||
sec-flare.com
|
||||
sepenet.gr.com
|
||||
sephoragroup.com
|
||||
servers-mobile.info
|
||||
serviceupdaterequest.com
|
||||
sextape225.me
|
||||
shanam.org
|
||||
shop-collect.com
|
||||
shortely.xyz
|
||||
shorten.fi
|
||||
shortenurls.me
|
||||
shortly.work
|
||||
shortmee.one
|
||||
shortwidgets.com
|
||||
shortxyz.com
|
||||
showsme.info
|
||||
shoxtek.com
|
||||
sicnoticia.com
|
||||
simetricode.uk
|
||||
sinai-new.com
|
||||
sitepref.xyz
|
||||
skollie.online
|
||||
skranski.com
|
||||
sky-news.live
|
||||
smallme.net
|
||||
smcu.me
|
||||
smsuns.com
|
||||
snapfire.xyz
|
||||
sniper.pet
|
||||
soccer-bw.com
|
||||
solargoup.xyz
|
||||
solargroup.xyz
|
||||
soq.one
|
||||
spacsaver.info
|
||||
speedygonzales.xyz
|
||||
speedymax.shop
|
||||
speedy.sbs
|
||||
sportnow.news
|
||||
sports-mdg.xyz
|
||||
sportsnewz.site
|
||||
static-graph.com
|
||||
stonisi.news
|
||||
suarajubi.com
|
||||
suarajubi.net
|
||||
suarapapua.co
|
||||
supportset.net
|
||||
sustanbuild.com
|
||||
suzuki.gr.com
|
||||
svetovid.bid
|
||||
symoty.com
|
||||
syncservices.one
|
||||
synctimestamp.com
|
||||
syncupdate.site
|
||||
sysly.sbs
|
||||
sysnet.life
|
||||
taagangola.co
|
||||
t-bit.me
|
||||
tclnk.live
|
||||
telecomegy-ads.com
|
||||
telenorconn.com
|
||||
tengrinnews.live
|
||||
teslali.com
|
||||
teslal.shop
|
||||
teslal.xyz
|
||||
tesla-s.shop
|
||||
tgrthgsrgwrthwrtgwr.xyz
|
||||
thintank.co
|
||||
tickets-kz.com
|
||||
timestampsync.com
|
||||
timeupdateservice.com
|
||||
timeupdate.xyz
|
||||
tiny.gr.com
|
||||
tinylinks.live
|
||||
tinyulrs.com
|
||||
tinyurl.cloud
|
||||
tiol.xyz
|
||||
tly.gr.com
|
||||
tly.link
|
||||
tobupmi.com
|
||||
tohna.net
|
||||
tokoulouri.live
|
||||
tovima.live
|
||||
traffic-moi-eg.org
|
||||
t-ready.me
|
||||
trecvf.xyz
|
||||
trecv.xyz
|
||||
tribune-mg.xyz
|
||||
trkc.online
|
||||
truelocation.org
|
||||
tsapp.me
|
||||
tsrt.xyz
|
||||
tupuca.co
|
||||
tvxs.news
|
||||
tw.itter.me
|
||||
twtter.net
|
||||
ube.gr.com
|
||||
uberegypt.cn.com
|
||||
ulstur.co
|
||||
unitei.co
|
||||
universedades.com
|
||||
updates4you.xyz
|
||||
updateservice.center
|
||||
updatetime.zone
|
||||
updatingnews.xyz
|
||||
updete.xyz
|
||||
url-promo.club
|
||||
url-tiny.app
|
||||
uservicescheck.com
|
||||
uservicesforyou.com
|
||||
utube.digital
|
||||
utube.to
|
||||
vaovao.soutien-a-rajoelina.com
|
||||
vendaswebs.com
|
||||
verifyurl.me
|
||||
vestinfo.net
|
||||
vestinfo.org
|
||||
vestinfos.net
|
||||
vinho-online.com
|
||||
vinhosadega.com
|
||||
visavfsglobal.co
|
||||
viva.gr.com
|
||||
vlast-news.com
|
||||
vodafoneegypt.tech
|
||||
vodafonegypt.com
|
||||
vouliwatch.gr.com
|
||||
vslojasvendas.com
|
||||
wa-info.com
|
||||
walatparez.com
|
||||
wavekli.xyz
|
||||
weathear.live
|
||||
weather-live.com
|
||||
weathernewz.xyz
|
||||
weathersite.online
|
||||
webaffise.com
|
||||
weekendcool.com
|
||||
wesalcity.net
|
||||
we-site.net
|
||||
wha.tsapp.me
|
||||
whatssapp.co
|
||||
worldnws.xyz
|
||||
wtc1111.com
|
||||
wtc2222.com
|
||||
wtc3333.com
|
||||
wts-app.info
|
||||
xf.actor
|
||||
xnxx-hub.com
|
||||
xyvok.xyz
|
||||
yallakora-egy.com
|
||||
youarefired.xyz
|
||||
yo-um7.com
|
||||
youtub.app
|
||||
yo.utube.digital
|
||||
youtub-eg.com
|
||||
yout.ube.gr.com
|
||||
youtube.gr.live
|
||||
youtu-be.net
|
||||
youtubesyncapi.com
|
||||
yo.utube.to
|
||||
youtube.voto
|
||||
youtubewatch.co
|
||||
yuom7.net
|
||||
z2a.digital
|
||||
z2adigital.cloud
|
||||
z2digital.cloud
|
||||
zakorn.com
|
||||
zikolo.net
|
||||
zoometting.com
|
||||
zougla.gr.com
|
||||
zougla.news
|
||||
ztb-news.com
|
||||
16
data/ioc/spyware/mvt/intellexa_predator/file_paths.txt
Normal file
16
data/ioc/spyware/mvt/intellexa_predator/file_paths.txt
Normal file
@@ -0,0 +1,16 @@
|
||||
/private/var/tmp/UserEventAgent
|
||||
/private/var/tmp/com.apple.WebKit.Networking
|
||||
/private/var/tmp/hooker
|
||||
/private/var/tmp/takePhoto
|
||||
/private/var/logs/keybagd/
|
||||
/private/var/tmp/kusama.txt
|
||||
/private/var/tmp/etherium.txt
|
||||
/private/var/tmp/helper.sock
|
||||
/private/var/tmp/etherium.txt
|
||||
/private/var/tmp/l/
|
||||
/tmp/etherium.txt
|
||||
/tmp/kusama.txt
|
||||
/tmp/l/
|
||||
/data/local/tmp/wd/pred.so
|
||||
/data/local/tmp/wd/fs.db
|
||||
/data/local/tmp/wd/
|
||||
41
data/ioc/spyware/mvt/intellexa_predator/generate_stix.py
Normal file
41
data/ioc/spyware/mvt/intellexa_predator/generate_stix.py
Normal file
@@ -0,0 +1,41 @@
|
||||
import sys
|
||||
import os
|
||||
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
if os.path.isfile("predator.stix2"):
|
||||
os.remove("predator.stix2")
|
||||
|
||||
with open("config_profiles.txt") as f:
|
||||
configs = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
|
||||
with open("domains.txt") as f:
|
||||
domains = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
with open("file_paths.txt") as f:
|
||||
filepaths = list(set([a.strip() for a in f.read().split()]))
|
||||
|
||||
res = []
|
||||
malware = Malware(name="Predator", is_family=False, description="IOCs for Intellexa Predator")
|
||||
res.append(malware)
|
||||
for d in domains:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for f in filepaths:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:path='{}']".format(f), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
for c in configs:
|
||||
i = Indicator(indicator_types=["malicious-activity"], pattern="[configuration-profile:id='{}']".format(c), pattern_type="stix")
|
||||
res.append(i)
|
||||
res.append(Relationship(i, 'indicates', malware))
|
||||
|
||||
bundle = Bundle(objects=res)
|
||||
with open("predator.stix2", "w+") as f:
|
||||
f.write(bundle.serialize(indent=4))
|
||||
print("predator.stix2 file created")
|
||||
14056
data/ioc/spyware/mvt/intellexa_predator/predator.stix2
Normal file
14056
data/ioc/spyware/mvt/intellexa_predator/predator.stix2
Normal file
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user