Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs

This commit is contained in:
SsSnake
2026-07-13 15:45:47 -07:00
parent 925216290f
commit e48d577bd5
387 changed files with 211976 additions and 921 deletions

View File

@@ -0,0 +1,26 @@
119-tim.info
133-tre.info
146-fastweb.info
155-wind.info
159-windtre.info
amex-co.info
apps.fb-techsupport.com
business.wind-h3g.info
cloud-apple.info
comtencentmobileqq-6ffb5.appspot.com
comxdjajxclient.appspot.com
fb-techsupport.com
fintur-a111a.appspot.com
ho-mobile.online
iliad.info
kena-mobile.info
milf.house
mobdemo.info
mobilepays.info
my190.info
poste-it.info
project1-c094e.appspot.com
rojavanetwork.info
safekeyservice-972cd.appspot.com
store-apple.info
wind-h3g.info

View File

@@ -0,0 +1,5 @@
com.androidservices.support
com.vodaservices
com.fintur.support
com.xdja.safekeyservice
com.xdja.jxclient

View File

@@ -0,0 +1,975 @@
{
"type": "bundle",
"id": "bundle--8fe0fa1c-a385-4539-9a3f-22c8e4d0d635",
"objects": [
{
"type": "malware",
"spec_version": "2.1",
"id": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0",
"created": "2022-06-24T13:12:26.333305Z",
"modified": "2022-06-24T13:12:26.333305Z",
"name": "RCSLab",
"is_family": true
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7c6b4d6d-a2eb-41ba-9be8-1793a9b2ed9d",
"created": "2022-06-24T13:12:26.333619Z",
"modified": "2022-06-24T13:12:26.333619Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='119-tim.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.333619Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--92d3f95d-f580-45a6-9692-6827ec325966",
"created": "2022-06-24T13:12:26.339881Z",
"modified": "2022-06-24T13:12:26.339881Z",
"relationship_type": "indicates",
"source_ref": "indicator--7c6b4d6d-a2eb-41ba-9be8-1793a9b2ed9d",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--8a69c42b-6c5b-4351-a8f1-b8896460dd3b",
"created": "2022-06-24T13:12:26.34046Z",
"modified": "2022-06-24T13:12:26.34046Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='133-tre.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.34046Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1a6b73c1-8047-4a86-8a0f-dc3057745902",
"created": "2022-06-24T13:12:26.341296Z",
"modified": "2022-06-24T13:12:26.341296Z",
"relationship_type": "indicates",
"source_ref": "indicator--8a69c42b-6c5b-4351-a8f1-b8896460dd3b",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5d1797b5-5aa0-4aa9-8153-82f1de10da25",
"created": "2022-06-24T13:12:26.341518Z",
"modified": "2022-06-24T13:12:26.341518Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='146-fastweb.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.341518Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4770dc39-d90a-4347-b305-4cedb5028dc8",
"created": "2022-06-24T13:12:26.342472Z",
"modified": "2022-06-24T13:12:26.342472Z",
"relationship_type": "indicates",
"source_ref": "indicator--5d1797b5-5aa0-4aa9-8153-82f1de10da25",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--324552fc-2fa9-45b7-a813-fb9033caf2eb",
"created": "2022-06-24T13:12:26.342693Z",
"modified": "2022-06-24T13:12:26.342693Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='155-wind.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.342693Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b97ace08-1734-4ef5-b686-f17f20ecaed2",
"created": "2022-06-24T13:12:26.343472Z",
"modified": "2022-06-24T13:12:26.343472Z",
"relationship_type": "indicates",
"source_ref": "indicator--324552fc-2fa9-45b7-a813-fb9033caf2eb",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--923369af-e465-4787-a235-80198057ee11",
"created": "2022-06-24T13:12:26.343693Z",
"modified": "2022-06-24T13:12:26.343693Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='159-windtre.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.343693Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a67f1ffb-79ca-43d3-a185-d2fba4b1f217",
"created": "2022-06-24T13:12:26.344322Z",
"modified": "2022-06-24T13:12:26.344322Z",
"relationship_type": "indicates",
"source_ref": "indicator--923369af-e465-4787-a235-80198057ee11",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--8b1dab2a-ee94-4d9a-aa52-180baeed3be1",
"created": "2022-06-24T13:12:26.34454Z",
"modified": "2022-06-24T13:12:26.34454Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='amex-co.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.34454Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6f202350-8ca0-4a9f-8360-60c764dc28c4",
"created": "2022-06-24T13:12:26.345345Z",
"modified": "2022-06-24T13:12:26.345345Z",
"relationship_type": "indicates",
"source_ref": "indicator--8b1dab2a-ee94-4d9a-aa52-180baeed3be1",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c3d4e132-1311-4eeb-a293-f9ed98f623c4",
"created": "2022-06-24T13:12:26.345566Z",
"modified": "2022-06-24T13:12:26.345566Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='apps.fb-techsupport.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.345566Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--d2a418aa-e75f-444a-835c-5bcb7f9f58b3",
"created": "2022-06-24T13:12:26.346385Z",
"modified": "2022-06-24T13:12:26.346385Z",
"relationship_type": "indicates",
"source_ref": "indicator--c3d4e132-1311-4eeb-a293-f9ed98f623c4",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5daf9871-e1d5-456e-b3a4-4b3d6f7431fd",
"created": "2022-06-24T13:12:26.346605Z",
"modified": "2022-06-24T13:12:26.346605Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='business.wind-h3g.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.346605Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6110248d-6c73-45b1-ae9d-236cad2a474e",
"created": "2022-06-24T13:12:26.347419Z",
"modified": "2022-06-24T13:12:26.347419Z",
"relationship_type": "indicates",
"source_ref": "indicator--5daf9871-e1d5-456e-b3a4-4b3d6f7431fd",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--188342a3-2ed0-42ea-aa6e-5e41d473604d",
"created": "2022-06-24T13:12:26.347656Z",
"modified": "2022-06-24T13:12:26.347656Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='cloud-apple.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.347656Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--cc5927ba-6c8b-44f8-8eb7-83993c5828b8",
"created": "2022-06-24T13:12:26.348513Z",
"modified": "2022-06-24T13:12:26.348513Z",
"relationship_type": "indicates",
"source_ref": "indicator--188342a3-2ed0-42ea-aa6e-5e41d473604d",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7a4ea108-4d57-48c0-8d83-1243521dbc90",
"created": "2022-06-24T13:12:26.348737Z",
"modified": "2022-06-24T13:12:26.348737Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='comtencentmobileqq-6ffb5.appspot.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.348737Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5b39695f-b470-489e-89d9-7f033bc8bc39",
"created": "2022-06-24T13:12:26.349462Z",
"modified": "2022-06-24T13:12:26.349462Z",
"relationship_type": "indicates",
"source_ref": "indicator--7a4ea108-4d57-48c0-8d83-1243521dbc90",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9f6af5b5-3c50-47e5-b259-70ff4c260db2",
"created": "2022-06-24T13:12:26.349682Z",
"modified": "2022-06-24T13:12:26.349682Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='comxdjajxclient.appspot.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.349682Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6a0b7b23-c8fd-499f-8306-e0f6da3e681f",
"created": "2022-06-24T13:12:26.350392Z",
"modified": "2022-06-24T13:12:26.350392Z",
"relationship_type": "indicates",
"source_ref": "indicator--9f6af5b5-3c50-47e5-b259-70ff4c260db2",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--58132773-47e3-4e94-a314-e03f2815cdf1",
"created": "2022-06-24T13:12:26.350609Z",
"modified": "2022-06-24T13:12:26.350609Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='fb-techsupport.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.350609Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--31f08a85-6930-44ac-88d6-6b7b94d92c33",
"created": "2022-06-24T13:12:26.351318Z",
"modified": "2022-06-24T13:12:26.351318Z",
"relationship_type": "indicates",
"source_ref": "indicator--58132773-47e3-4e94-a314-e03f2815cdf1",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f54d7d64-5e92-470f-aa06-dc7507230e86",
"created": "2022-06-24T13:12:26.351538Z",
"modified": "2022-06-24T13:12:26.351538Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='fintur-a111a.appspot.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.351538Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7c217cf0-f45f-4dd3-8ce4-e844c38d4c5c",
"created": "2022-06-24T13:12:26.352165Z",
"modified": "2022-06-24T13:12:26.352165Z",
"relationship_type": "indicates",
"source_ref": "indicator--f54d7d64-5e92-470f-aa06-dc7507230e86",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c02b7f2f-0583-475a-a6c5-fe7b88ed4768",
"created": "2022-06-24T13:12:26.352382Z",
"modified": "2022-06-24T13:12:26.352382Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='ho-mobile.online']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.352382Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ac5c41a1-891c-4930-a22f-c709a9d41040",
"created": "2022-06-24T13:12:26.353073Z",
"modified": "2022-06-24T13:12:26.353073Z",
"relationship_type": "indicates",
"source_ref": "indicator--c02b7f2f-0583-475a-a6c5-fe7b88ed4768",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--8a7a2752-0176-43c3-b6e9-a552cd370535",
"created": "2022-06-24T13:12:26.353292Z",
"modified": "2022-06-24T13:12:26.353292Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='iliad.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.353292Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--74d9da1b-0a11-4a09-82fc-7b357a407e20",
"created": "2022-06-24T13:12:26.353975Z",
"modified": "2022-06-24T13:12:26.353975Z",
"relationship_type": "indicates",
"source_ref": "indicator--8a7a2752-0176-43c3-b6e9-a552cd370535",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--06930171-82b7-4d74-b3f0-a6f0150c7157",
"created": "2022-06-24T13:12:26.354193Z",
"modified": "2022-06-24T13:12:26.354193Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='kena-mobile.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.354193Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--fc304f5c-ad2f-49d7-be95-7b0914691e6b",
"created": "2022-06-24T13:12:26.354884Z",
"modified": "2022-06-24T13:12:26.354884Z",
"relationship_type": "indicates",
"source_ref": "indicator--06930171-82b7-4d74-b3f0-a6f0150c7157",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6d48fc99-2480-408a-9bc2-0121f26828af",
"created": "2022-06-24T13:12:26.3551Z",
"modified": "2022-06-24T13:12:26.3551Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='milf.house']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.3551Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b5a8821b-a640-4c2c-951d-3d14312eeccc",
"created": "2022-06-24T13:12:26.355797Z",
"modified": "2022-06-24T13:12:26.355797Z",
"relationship_type": "indicates",
"source_ref": "indicator--6d48fc99-2480-408a-9bc2-0121f26828af",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--8061b446-98aa-4a24-be04-49acbc0a3c90",
"created": "2022-06-24T13:12:26.356014Z",
"modified": "2022-06-24T13:12:26.356014Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='mobdemo.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.356014Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a99c0527-c20d-435b-a759-e5a9bcb4dd07",
"created": "2022-06-24T13:12:26.356627Z",
"modified": "2022-06-24T13:12:26.356627Z",
"relationship_type": "indicates",
"source_ref": "indicator--8061b446-98aa-4a24-be04-49acbc0a3c90",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7f5f2d9d-3430-42db-9dd5-8fc2dacc06ba",
"created": "2022-06-24T13:12:26.356848Z",
"modified": "2022-06-24T13:12:26.356848Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='mobilepays.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.356848Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--64598bb4-f1b6-4c3e-a39a-d2c48aa5b05d",
"created": "2022-06-24T13:12:26.358088Z",
"modified": "2022-06-24T13:12:26.358088Z",
"relationship_type": "indicates",
"source_ref": "indicator--7f5f2d9d-3430-42db-9dd5-8fc2dacc06ba",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--03dee9cd-b168-450a-919a-7e79b6c84a63",
"created": "2022-06-24T13:12:26.358312Z",
"modified": "2022-06-24T13:12:26.358312Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='my190.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.358312Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5af0f57f-9b7f-4a15-87fe-b9aed31286d2",
"created": "2022-06-24T13:12:26.358992Z",
"modified": "2022-06-24T13:12:26.358992Z",
"relationship_type": "indicates",
"source_ref": "indicator--03dee9cd-b168-450a-919a-7e79b6c84a63",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c9f2bb6a-0dd0-4f74-ae0e-b2ed16dcf601",
"created": "2022-06-24T13:12:26.359217Z",
"modified": "2022-06-24T13:12:26.359217Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='poste-it.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.359217Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--dc6a2c67-1408-492d-a9a7-dda6be484f09",
"created": "2022-06-24T13:12:26.359902Z",
"modified": "2022-06-24T13:12:26.359902Z",
"relationship_type": "indicates",
"source_ref": "indicator--c9f2bb6a-0dd0-4f74-ae0e-b2ed16dcf601",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7cb6e051-ef82-4a97-b469-81ec8aeee676",
"created": "2022-06-24T13:12:26.360119Z",
"modified": "2022-06-24T13:12:26.360119Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='project1-c094e.appspot.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.360119Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--47271d88-afac-417e-9420-4d03dcbf4c91",
"created": "2022-06-24T13:12:26.360764Z",
"modified": "2022-06-24T13:12:26.360764Z",
"relationship_type": "indicates",
"source_ref": "indicator--7cb6e051-ef82-4a97-b469-81ec8aeee676",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3f972bc5-0465-40d7-9435-43bc0943a849",
"created": "2022-06-24T13:12:26.360981Z",
"modified": "2022-06-24T13:12:26.360981Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='rojavanetwork.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.360981Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--764d101c-e77e-413d-9472-903ae2b49bb4",
"created": "2022-06-24T13:12:26.36179Z",
"modified": "2022-06-24T13:12:26.36179Z",
"relationship_type": "indicates",
"source_ref": "indicator--3f972bc5-0465-40d7-9435-43bc0943a849",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f8d4f1ae-856e-4d77-9019-d96ce0234133",
"created": "2022-06-24T13:12:26.362009Z",
"modified": "2022-06-24T13:12:26.362009Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='safekeyservice-972cd.appspot.com']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.362009Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8293f9ae-efc9-41c2-babb-47f53ae28da0",
"created": "2022-06-24T13:12:26.362831Z",
"modified": "2022-06-24T13:12:26.362831Z",
"relationship_type": "indicates",
"source_ref": "indicator--f8d4f1ae-856e-4d77-9019-d96ce0234133",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9f94055e-37af-4f64-8143-0acdc305e246",
"created": "2022-06-24T13:12:26.363048Z",
"modified": "2022-06-24T13:12:26.363048Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='store-apple.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.363048Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--173b7391-2d03-4671-b186-3b3c995fc591",
"created": "2022-06-24T13:12:26.363666Z",
"modified": "2022-06-24T13:12:26.363666Z",
"relationship_type": "indicates",
"source_ref": "indicator--9f94055e-37af-4f64-8143-0acdc305e246",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b61779d9-d458-4ee3-aec0-617240a7b6f8",
"created": "2022-06-24T13:12:26.363883Z",
"modified": "2022-06-24T13:12:26.363883Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='wind-h3g.info']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.363883Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--404cb59c-8579-4700-874c-df0de66a752c",
"created": "2022-06-24T13:12:26.364618Z",
"modified": "2022-06-24T13:12:26.364618Z",
"relationship_type": "indicates",
"source_ref": "indicator--b61779d9-d458-4ee3-aec0-617240a7b6f8",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e45361fc-f23f-4964-9c52-126298268a37",
"created": "2022-06-24T13:12:26.364805Z",
"modified": "2022-06-24T13:12:26.364805Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='e38d7ba21a48ad32963bfe6cb0203afe0839eca9a73268a67422109da282eae3']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.364805Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--f0c32e7b-2b2b-46aa-a908-fefdf4bf3845",
"created": "2022-06-24T13:12:26.367888Z",
"modified": "2022-06-24T13:12:26.367888Z",
"relationship_type": "indicates",
"source_ref": "indicator--e45361fc-f23f-4964-9c52-126298268a37",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e61c0dde-1826-482e-831e-f7382ae5f6ba",
"created": "2022-06-24T13:12:26.368076Z",
"modified": "2022-06-24T13:12:26.368076Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='fe95855691cada4493641bc4f01eb00c670c002166d6591fe38073dd0ea1d001']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.368076Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c7d9f0ab-faf1-46f6-a912-6d4c21f2abad",
"created": "2022-06-24T13:12:26.368803Z",
"modified": "2022-06-24T13:12:26.368803Z",
"relationship_type": "indicates",
"source_ref": "indicator--e61c0dde-1826-482e-831e-f7382ae5f6ba",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0d246a65-89b3-4eff-a3d7-95897e1ae977",
"created": "2022-06-24T13:12:26.368983Z",
"modified": "2022-06-24T13:12:26.368983Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='243ea96b2f8f70abc127c8bc1759929e3ad9efc1dec5b51f5788e9896b6d516e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.368983Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--20c01422-bee6-4835-94be-709d5ad6c07e",
"created": "2022-06-24T13:12:26.369783Z",
"modified": "2022-06-24T13:12:26.369783Z",
"relationship_type": "indicates",
"source_ref": "indicator--0d246a65-89b3-4eff-a3d7-95897e1ae977",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--304b0611-d914-4d68-bc3c-cd2807ed668e",
"created": "2022-06-24T13:12:26.369965Z",
"modified": "2022-06-24T13:12:26.369965Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='a98a224b644d3d88eed27aa05548a41e0178dba93ed9145250f61912e924b3e9']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.369965Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--65da7ae0-f343-4c65-9976-6cef7aabee0a",
"created": "2022-06-24T13:12:26.370688Z",
"modified": "2022-06-24T13:12:26.370688Z",
"relationship_type": "indicates",
"source_ref": "indicator--304b0611-d914-4d68-bc3c-cd2807ed668e",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--03041d38-2e4d-410d-ae3f-39306840313f",
"created": "2022-06-24T13:12:26.37087Z",
"modified": "2022-06-24T13:12:26.37087Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='c26220c9177c146d6ce21e2f964de47b3dbbab85824e93908d66fa080e13286f']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.37087Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--734b230c-a3f3-457c-8ec6-27c49869aff4",
"created": "2022-06-24T13:12:26.371603Z",
"modified": "2022-06-24T13:12:26.371603Z",
"relationship_type": "indicates",
"source_ref": "indicator--03041d38-2e4d-410d-ae3f-39306840313f",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--98f7c1b0-629c-447a-abb3-9c99c78ef69d",
"created": "2022-06-24T13:12:26.371788Z",
"modified": "2022-06-24T13:12:26.371788Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='0759a60e09710321dfc42b09518516398785f60e150012d15be88bbb2ea788db']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.371788Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--eadab579-17b1-4cb3-a161-69d63f447030",
"created": "2022-06-24T13:12:26.372585Z",
"modified": "2022-06-24T13:12:26.372585Z",
"relationship_type": "indicates",
"source_ref": "indicator--98f7c1b0-629c-447a-abb3-9c99c78ef69d",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--945c8790-e28d-4e3f-87bf-bf69b74a6331",
"created": "2022-06-24T13:12:26.372769Z",
"modified": "2022-06-24T13:12:26.372769Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='8ef40f13c6192bd8defa7ac0b54ce2454e71b55867bdafc51ecb714d02abfd1a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.372769Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e15ba27f-ea46-4803-b1e1-e4756503530d",
"created": "2022-06-24T13:12:26.373569Z",
"modified": "2022-06-24T13:12:26.373569Z",
"relationship_type": "indicates",
"source_ref": "indicator--945c8790-e28d-4e3f-87bf-bf69b74a6331",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--57bc1215-e991-4831-9a75-fc19c5840cf4",
"created": "2022-06-24T13:12:26.373751Z",
"modified": "2022-06-24T13:12:26.373751Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='9146e0ede1c0e9014341ef0859ca62d230bea5d6535d800591a796e8dfe1dff9']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.373751Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a4fd3ba7-d574-44b3-b2c3-1499b1c9cf40",
"created": "2022-06-24T13:12:26.374665Z",
"modified": "2022-06-24T13:12:26.374665Z",
"relationship_type": "indicates",
"source_ref": "indicator--57bc1215-e991-4831-9a75-fc19c5840cf4",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c6335115-b47a-4212-bda2-3d3ac12b18ee",
"created": "2022-06-24T13:12:26.374849Z",
"modified": "2022-06-24T13:12:26.374849Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='6eeb683ee4674fd5553fdc2ca32d77ee733de0e654c6f230f881abf5752696ba']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.374849Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ff242d23-bab1-4faa-b668-1ae72fa969a1",
"created": "2022-06-24T13:12:26.375662Z",
"modified": "2022-06-24T13:12:26.375662Z",
"relationship_type": "indicates",
"source_ref": "indicator--c6335115-b47a-4212-bda2-3d3ac12b18ee",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--dfedbd26-0d3e-4e66-b428-9990c435c31a",
"created": "2022-06-24T13:12:26.37586Z",
"modified": "2022-06-24T13:12:26.37586Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.androidservices.support']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.37586Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--d2ad1b53-111e-4bf1-bd97-34cd17dec9ff",
"created": "2022-06-24T13:12:26.37681Z",
"modified": "2022-06-24T13:12:26.37681Z",
"relationship_type": "indicates",
"source_ref": "indicator--dfedbd26-0d3e-4e66-b428-9990c435c31a",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--2b781c83-df99-4875-aa6e-8e6bee322e0e",
"created": "2022-06-24T13:12:26.376992Z",
"modified": "2022-06-24T13:12:26.376992Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.vodaservices']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.376992Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e066f24b-4ba4-4797-b807-6e0522311c03",
"created": "2022-06-24T13:12:26.377573Z",
"modified": "2022-06-24T13:12:26.377573Z",
"relationship_type": "indicates",
"source_ref": "indicator--2b781c83-df99-4875-aa6e-8e6bee322e0e",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f51f2f24-f14a-4e86-adca-28ef6aa2f66f",
"created": "2022-06-24T13:12:26.377748Z",
"modified": "2022-06-24T13:12:26.377748Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.fintur.support']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.377748Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--d50eca5a-0e18-4000-acb1-7869f1b8a1cc",
"created": "2022-06-24T13:12:26.378323Z",
"modified": "2022-06-24T13:12:26.378323Z",
"relationship_type": "indicates",
"source_ref": "indicator--f51f2f24-f14a-4e86-adca-28ef6aa2f66f",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--786a496f-a543-4505-b1c6-d06b563424cd",
"created": "2022-06-24T13:12:26.378497Z",
"modified": "2022-06-24T13:12:26.378497Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.xdja.safekeyservice']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.378497Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b28150db-88ac-465b-ad89-43145e327247",
"created": "2022-06-24T13:12:26.379086Z",
"modified": "2022-06-24T13:12:26.379086Z",
"relationship_type": "indicates",
"source_ref": "indicator--786a496f-a543-4505-b1c6-d06b563424cd",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--bbbed2fa-aa2d-405b-9bb2-a1dd7fc43da2",
"created": "2022-06-24T13:12:26.379267Z",
"modified": "2022-06-24T13:12:26.379267Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.xdja.jxclient']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2022-06-24T13:12:26.379267Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b8f9eb1a-55ee-4c17-8dc7-a631e6d42f64",
"created": "2022-06-24T13:12:26.379843Z",
"modified": "2022-06-24T13:12:26.379843Z",
"relationship_type": "indicates",
"source_ref": "indicator--bbbed2fa-aa2d-405b-9bb2-a1dd7fc43da2",
"target_ref": "malware--7983fdbf-1766-4549-9d5b-a78fff3e44f0"
}
]
}

View File

@@ -0,0 +1,9 @@
e38d7ba21a48ad32963bfe6cb0203afe0839eca9a73268a67422109da282eae3
fe95855691cada4493641bc4f01eb00c670c002166d6591fe38073dd0ea1d001
243ea96b2f8f70abc127c8bc1759929e3ad9efc1dec5b51f5788e9896b6d516e
a98a224b644d3d88eed27aa05548a41e0178dba93ed9145250f61912e924b3e9
c26220c9177c146d6ce21e2f964de47b3dbbab85824e93908d66fa080e13286f
0759a60e09710321dfc42b09518516398785f60e150012d15be88bbb2ea788db
8ef40f13c6192bd8defa7ac0b54ce2454e71b55867bdafc51ecb714d02abfd1a
9146e0ede1c0e9014341ef0859ca62d230bea5d6535d800591a796e8dfe1dff9
6eeb683ee4674fd5553fdc2ca32d77ee733de0e654c6f230f881abf5752696ba

View File

@@ -0,0 +1,3 @@
# Quadream KingSpawn indicators
Quadream indicators from [Citizen Lab](https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/) and [Microsoft](https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/) reports.

View File

@@ -0,0 +1,164 @@
addictmetui.com
adeptary.com
agronomsdoc.com
allplaces.online
aniarchit.com
aqualizas.com
bcarental.com
beendos.com
bestteamlife.com
betterstime.com
bgnews-bg.com
bikersrental.com
biznomex.com
brushyourteeth.online
careerhub4u.com
careers4ad.com
choccoline.com
classiccolor.live
cleanitgo.info
climatestews.com
codinerom.com
codingstudies.com
comeandpet.me
countshops.com
ctbgameson.com
datacentertime.com
deliverystorz.com
designaroo.org
designspacing.org
digital-mar.com
dressuse.com
dsudro.com
earthyouwantiis.com
eccocredit.com
ecologitics.com
eedloversra.online
e-gaming.online
elektrozi.com
elvacream.com
enrollering.com
foodyplates.com
forestaaa.com
fosterunch.com
foundurycolletive.com
fullaniimal.com
fullmoongreyparty.org
fullstorelife.com
furiamoc.com
gameboysess.com
gameizes.com
gamezess.com
gamingcolonys.com
gardenearthis.com
garilc.com
globepayinfo.com
goodsforuw.com
goshopeerz.com
gosport24.com
greenrunners.org
healthcovid19.com
hinterfy.com
homeigardens.com
homelosite.com
hopsite.online
hotalsextra.com
hoteliqo.com
hoteluxurysm.com
incollegely.org
inneture.com
i-reality.online
iwoodstor.xyz
job4uhunt.com
jungelfruitime.com
jyfa.xyz
kidsfunland.org
kidzalnd.org
kidzlande.com
kikocruize.com
koraliowe.com
lateparties.com
linestrip.online
localtallk.store
londonistory.com
luxario.org
meehealth.org
mikontravels.com
monvesting.com
motorgamings.com
mwww.ro
naturemeter.org
navadatime.com
newsandlocalupdates.com
newsbuiltin.online
newslocalupdates.com
newz-globe.com
noraplant.com
nordmanetime.com
novinite.biz
nutureheus.com
pachadesert.com
pennywines.com
planetosgame.com
planningly.org
playozas.com
powercodings.com
projectoid.org
razzodev.com
recover-your-body.xyz
recovery-plan.org
redanddred.com
reloadyourbrowser.info
rentalproct.com
retailmark.net
runningandbeyond.org
setclass.live
sevensdfe.com
shoeszise.xyz
shoplifys.com
shoppingeos.com
sidelot.org
skyphotogreen.com
space-moon.com
sseamb.com
stayle.co
stockstiming.org
studiesutshifts.com
studyreaserch.com
study-search.com
studyshifts.com
studysliii.com
styleanature.com
stylelifees.com
subcloud.online
sunclub.site
sunnyweek.site
sunsandlights.com
takebreak.io
takestox.com
teachlearning.org
techpowerlight.com
thegreenlight.xyz
thenewsfill.com
thepila.com
thetimespress.com
timeeforsports.com
tokenberries.com
topuprr.com
transformaition.com
treerroots.com
unitedyears.com
vinoneros.com
wellnessjane.org
whiteandpiink.com
white-rhino.online
wikipedoptions.com
wilddog.site
wildhour.store
wombatcash.com
womnbling.com
youristores.com
zebra-arts.com
zedforme.com
zeebefg.com
zooloow.com

View File

@@ -0,0 +1,2 @@
/private/var/db/com.apple.xpc.roleaccountd.staging/subridged
/private/var/db/com.apple.xpc.roleaccountd.staging/PlugIns/fud.appex/

View File

@@ -0,0 +1,40 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
if os.path.isfile("kingspawn.stix2"):
os.remove("kingspawn.stix2")
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("file_paths.txt") as f:
filepaths = list(set([a.strip() for a in f.read().split()]))
with open("processes.txt") as f:
processes = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name="KingSpawn", is_family=False, description="IOCs related to Quadream KingsPawn or Reign spyware")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for f in filepaths:
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:path='{}']".format(f), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for p in processes:
i = Indicator(indicator_types=["malicious-activity"], pattern="[process:name='{}']".format(p), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open("kingspawn.stix2", "w+") as f:
f.write(bundle.serialize(indent=4))
print("kingspawn.stix2 file created")

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1 @@
com.apple.avcapture

View File

@@ -0,0 +1,76 @@
8181data.com
adcreatorfree.net
addatamarket.net
adsfreetracking.com
adsspacefree.com
adtreks.net
ans7tv.net
anstv.net
baba8861.com
backuprabbit.com
balancedcistern.com
beifang6688.com
bestnewsfeed.net
bestonlineads.net
businessvideonews.com
click-farm.net
cloudsponcer.com
cloudyundat.com
crowd-tracking.com
cruxness.com
datamarketplace.net
dreamshoppingphoto.com
edgeserverapi.com
fastads4free.com
fastfindads.net
floranewstoday.net
freeaddelivery.com
freeadvertisementsonline.com
futebolnoticia.net
globalpromonet.com
growthtransport.com
haidishabu.com
healthymarshmellow.com
improvingfitness.net
kickoffortea.com
koppercables.com
mechanicsfoundry.com
mediaclickers.net
mediumgates.com
mobilegamerstats.com
mysyncs.com
networkaccessory.com
nimbulusdrifting.net
onlineadvalue.com
pandabeachmetrics.com
papershopclip.com
perksync.com
pleekerion.com
qinggang26.com
quickdatafeed.com
regionalcdn.net
scoreclicks.com
senlin83.com
smartsavingmarketing.com
snoweeanalytics.com
statherder.com
static3video.com
stretchingnoun.com
swimporchingnow.com
tagclick-cdn.com
tangpingzy.com
tempoinformacao.net
tenvmms.cloud
titanhound.com
topographyupdates.com
tradeadvantages.com
unlimitedteacup.com
updateads.net
updatedadsfree.com
virtuallaughing.com
weathercasting.net
web-trackers.com
wheelgroupmarketing.com
windpoweredalgae.com
yuxbaozh1.com

View File

@@ -0,0 +1,36 @@
travislong544@yahoo.com
norsarall87@outlook.com
jesteristhebestband@gmail.com
christineashleysmith@gmail.com
homicidalwombat@yahoo.com
nigelmlevy@gmail.com
supercatman15@hotmail.com
shannonkelly404@gmail.com
superhugger21@gmail.com
parkourdiva@yahoo.com
naturelover1972@outlook.com
sasquatchdreams@outlook.com
trunkfullofbeans@yahoo.com
danielhbarnes2@gmail.com
patriotsman121@gmail.com
wheelsordoors@yahoo.com
janahodges324@gmail.com
mibarham@outlook.com
tinyjax89@gmail.com
nonbaguette@yahoo.com
slbrimms96@outlook.com
costamaria91@outlook.com
hyechink97@gmail.com
greatoleg9393@mail.com
popanddangle@outlook.com
maxjar90@mail.com
chongwonnam@gmail.com
wopperplopper1@aol.com
bajablaster101@gmail.com
carlson31773@outlook.com
fsozgur@outlook.com
soccerchk835@gmail.com
stephamartinez122@gmail.com
popcornkerner@gmail.com
pupperoni1989@outlook.com
biglesterjames5@gmail.com

View File

@@ -0,0 +1,42 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
malware_name = "OperationTriangulation"
stix_name = "operation_triangulation.stix2"
if os.path.isfile(stix_name):
os.remove(stix_name)
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("processes.txt") as f:
processes = list(set([a.strip() for a in f.read().split()]))
with open("emails.txt") as f:
emails = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name=malware_name, is_family=False, description="IOCs related to Operation Triangulation iOS spyware documented by Kaspersky Labs.")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for p in processes:
i = Indicator(indicator_types=["malicious-activity"], pattern="[process:name='{}']".format(p), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for e in emails:
i = Indicator(indicator_types=["malicious-activity"], pattern="[email-addr:value='{}']".format(e), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open(stix_name, "w+") as f:
f.write(bundle.serialize(indent=4))
print("{} file created".format(stix_name))

View File

@@ -0,0 +1 @@
BackupAgent

View File

@@ -0,0 +1,7 @@
dns.win10micros0ft.com
www.andropwn.xyz
update.umisen.com
alxc.tbtianyan.com
yxwasec.com
smiss.imwork.net
huaxin-bantian.duckdns.org

View File

@@ -0,0 +1,51 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
malware_name = "WyrmSpy_DragonEgg"
stix_name = "wyrmspy_dragonegg.stix2"
if os.path.isfile(stix_name):
os.remove(stix_name)
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("ip-addresses.txt") as f:
ips = list(set([a.strip() for a in f.read().split()]))
with open("sha256.txt") as f:
sha256 = list(set([a.strip() for a in f.read().split()]))
with open("package_names.txt") as f:
package_names = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name=malware_name, is_family=False, description="IOCs related to WyrmSpy and DragonEgg Android spyware documented by Lookout.")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for ip in ips:
i = Indicator(indicator_types=["malicious-activity"], pattern="[ipv4-addr:value='{}']".format(ip),
pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for s in sha256:
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:hashes.sha256='{}']".format(s), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for p in package_names:
i = Indicator(indicator_types=["malicious-activity"], pattern="[app:id='{}']".format(p), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open(stix_name, "w+") as f:
f.write(bundle.serialize(indent=4))
print("{} file created".format(stix_name))

View File

@@ -0,0 +1,5 @@
116.205.4.18
121.42.149.52
118.193.39.165
121.201.109.98
103.43.17.99

View File

@@ -0,0 +1,7 @@
com.android.system.configs.service
com.hx.rootwifi
com.adobe.flash.listen.beta
com.adobe.flash.jni
com.adobe.flash.dex
remote.google.rt.googleservice
xx.an

View File

@@ -0,0 +1,34 @@
b66847d571e471ac78ffa11a82dded5ac6d2f52b25304adbfab90716d22c0905
6caf068e1c0be245083aa6c3b92bd34909cb57d3d989cf509db18a8be4045fc5
43193e32872c589785ae720da875e5e20099a5fa36c8aee838034c91986ed34c
4355b4eb3d73b96577194cbd0ff319e0f4ff02d0cabdde8b15e1abd1840e6481
6b9a540801613a2abd15b5994def2ac4904a896e14e1ab364b032de5b3d1e098
8bf60e625d628e39320015de654933947b56621d8a4538f9be55c27ffc29a99c
db389366540d43ffa1451fae16e0ab34bf266b9c88aff65d919f474e9430d5d6
9bcaf637cfeab36e5f4301d4f018f7e6b8e9e30db108e7b7668bdb2250110407
8c01132a0c1c7799e44608247f93d4680935f36df3fc94d59c7da83afe375ff2
8d7fd7dcf5f0e144f3e3cc96ebf3ab8789d0d8edaeefa65e0f03dac67c1f046f
82c75b521fd03f6c4074494f0e3c46cc7aa8e5b88c28ebb08401a50109206668
7a618ac4a0fb2b68df540554ee99aa48caa148b3dd2800777a084a7322efe22f
36d72fedc17be9936f182b38ca98c40a0f9ba44cac170bd63cbded9568452d25
1d76df42d77080a96f885ed31ab8a83f4f985e071e715fd54297dab398c4be6b
6fc9a0881719ddfd1973f7ce62fa000279fda2ab5a03a4676e15c5e838b8c7ff
af139a04f314ccfb31a1d48ae9a434f26cb5fe1ca173acc479e7dc95a1f90260
d773c969c1be976410b9d8304fe6c07b142766f7bec2242e0eb5c18d3503eec1
38e18d79b83e7c0afbe1ac246a7a5fe6b2783adc085e9aeb2ec610e76f5ccaad
92ce9de120ebd88f0126644697e9840489b2c2497e5c99acfa7dd680d98cf075
c45a82123c985f2fd18e6763b76443ba6c49d12df3d7fe445a19c8fcdc6de846
4fd5f3c3e4bc4c354d0e4de0bebfdb85e1bab5e5f1ea24ce18b947377a7e2423
fa4a0aaa6b8f25e8f177ce2e3202c933c2358d4a45d94427dd54df83778a4225
79028b82a4715160db89bb6ea7d7e2961e0f0e084b8abc21bb4d677ec4cc8d5a
9ba0078a12f7cd515303aefdb151d65a2d3cb1188242e72e3bd9e629dc246582
017f30bf39d897d1b52c6d035dde5d2578d18d774b39fe76daf67f53d9a08ce9
b29cddc09cf65b4cda6b3898257f978265478af3ed3217c1be2c3fb729233739
77504bf799b9a35d493b2363e7665b3dc3b9db32f337f03db1aabe4b3c5a5e05
2594d654e4e820495392424e52c79d8ea89a8063ebb05bc6cf9f8547605db3a1
48cd527254084d5e80cd86155a9a23702bdbd586752d27c6e3b6260fa8a86eb4
79a316353747d11ca0ac00e6cbe1e1ce80061d067d9ff3274be33c40d12ca5de
0bdefeee83c758c45a54b20674208e1fa26a2d47c862abdffd2c39a345379e0a
68494cde4ee344cba80e8651c579418f2ce534018d88745797f030a3115ed19b
9ef830205b7cf0d59d495f722fc61cc3a9f938972e24bae05fa8620b43ed264a
ee90d36b384d92a0c9609eab0a3fe0f2af245c281473b4ff0cdd8caeed34fe97

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2022 MVT
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

View File

@@ -0,0 +1,9 @@
# mvt-indicators
This repository contains the index to known publicly available indicators of compromise comptable with MVT. It also contains indicators file created and contributed by the community, gathered from published research.
## How to contribute new indicators of compromise
To contribute new indicators of compromise you are invited to submit pull requests to this repository including a new folder in the format of `YYYY-MM-DD_short_description`, containing text files for each indicators category as well as a [STIX2](https://oasis-open.github.io/cti-documentation/stix/intro.html) file to be used with MVT. To generate a STIX2 file you can use the utility [stix2gen](https://github.com/botherder/stix2gen) (please refer to its repository for instructions on how to use).
When submitting a new pull request, please include the source of these indicators as well as any reference to related publicly available research and documentation.

View File

@@ -0,0 +1,87 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle)
from stix2 import CustomObservable
# @CustomObservable('x-new-observable-2', [
# ('a_property', properties.StringProperty(required=True)),
# ('property_2', properties.IntegerProperty()),
# ], [
# 'a_property'
# ])
# class NewObservable2():
# pass
def hash_format(hash):
if len(hash) == 32:
return "md5"
elif len(hash) == 40:
return "sha1"
elif len(hash) == 64:
return "sha256"
else:
return None
if __name__ == "__main__":
malware_name = "ResidentBat"
stix2_file_name = "residentbat.stix2"
if os.path.isfile(stix2_file_name):
os.remove(stix2_file_name)
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("ip-addresses.txt") as f:
ips = list(set([a.strip() for a in f.read().split()]))
with open("package_names.txt") as f:
package_names = list(set([a.strip() for a in f.read().split()]))
with open("package_cert_hashes.txt") as f:
package_cert_hashes = list(set([a.strip() for a in f.read().split()]))
with open("sha256.txt") as f:
sha256_hashes = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name=malware_name, is_family=False, description="IOCs for ResidentBat")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for ip in ips:
i = Indicator(indicator_types=["malicious-activity"], pattern="[ipv4-addr:value='{}']".format(ip),
pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for package_name in package_names:
i = Indicator(indicator_types=["malicious-activity"], pattern="[app:id='{}']".format(package_name), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for cert_hash in package_cert_hashes:
hash_type = hash_format(cert_hash)
if not hash_type:
raise ValueError("Unknown hash type for {}".format(cert_hash))
i = Indicator(indicator_types=["malicious-activity"], pattern=f"[app:cert.{hash_type}='{cert_hash}']", pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for sha256_hash in sha256_hashes:
if not hash_format(sha256_hash) == "sha256":
raise ValueError("File hash is not in SHA256 format: {}".format(sha256_hash))
i = Indicator(indicator_types=["malicious-activity"], pattern=f"[file:hashes.sha256='{sha256_hash}']", pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open(stix2_file_name, "w+") as f:
f.write(bundle.serialize(pretty=True, indent=4))
print("{} file created".format(stix2_file_name))

View File

@@ -0,0 +1,24 @@
62.109.26.144
91.107.122.180
5.129.230.104
82.146.35.54
62.109.12.75
79.132.136.191
83.220.169.120
5.129.213.114
5.253.63.176
62.109.11.98
62.109.19.123
185.248.103.85
5.129.231.158
185.18.54.246
91.240.87.211
185.248.103.128
185.248.103.247
188.120.230.46
37.46.133.87
5.253.61.156
79.132.141.31
37.46.128.62
91.228.152.4
91.192.102.69

View File

@@ -0,0 +1,8 @@
18afc5c6bfaee504a26291f6bf3e6f823dbedd54bba0c4acac2e7c2414b3e24d
c1884e617348ebbdfe7cfe5fc99945b37296d6ebc6059bb74fbaeea277d32941
e5016f3cfb937d502dabedc32ca3bdef3bbcce032fb3b1bff3b9c6482895f4fd
d12616542268d32329f1c4357b5d5a57e954e13d2338d27bb8439794291b8c6d
3e9f1192e33cb851b48479629c93d29770a4f76af00f1e42a3c6e7f97db62c79
6782039a81a85264acdc6af0973b225ada6009f76faae7f948a1de040bb32f0c
a6a067b0d899fb514b7b4597d4fe16fcd4d7e5c361f6c84b3d45ed7e394036c7
6d6278ffc80ad9dd1b1c6b445847ce108f3ea5ce349f232689e9b8c1fd10801e

View File

@@ -0,0 +1,8 @@
com.google.android.service
com.google.bat
com.huaweisettingsapp.mkz
com.linkedln.service
com.oneplussync.bat
cm.google.android.apps.assistant
com.android.framework.safety
com.hihonor.core.service

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,9 @@
07d39205f9ba159236477a02cdb3350fac4f158e0dbf26576bb50604339b1f42
820c394b22b950335eb5cf21bc7df5c7a33081169f41440c74d67e7a8f196960
fe05ba40f2d4b15db83524c169d030d097abc6713139ce6068969d97a24aa195
77126e749a9c1144ae3cebb8deb0b72fc90d4eb73d1072a69a1248b4f518bb47
c3b92d05b105465881c0f68f5cf6c3edb24d2e5317ffd1256cb68c7921fe0721
0ed73428c7729806be57989f340a09a323af914f197cc0cbb5509316ca5baf7b
48e87bfcaa665bfbfcb027227384905878f090bbc19d02f74c41ade3cafb0950
02dc81ea172e45f0a6fd7241fffd1042f6925c52d2f91dee36085634207be4f1
0ed73428c7729806be57989f340a09a323af914f197cc0cbb5509316ca5baf7b

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,125 @@
ambiguouscommerce.com
antperspective.com
aperturebelt.com
asknapkin.com
barnsecret.com
baseagriculture.com
basicstraw.com
basinapposite.com
beneathbreadth.com
bizarreclassify.com
blockroster.net
bondmuscle.com
breadgroomer.com
bronzemonth.com
browniebell.com
bypassbirch.com
bypasscalculate.com
bypasscommerce.com
calmbase.org
cartoondrop.net
chickenstrawberry.com
citecivilization.com
closetmeat.com
commonclever.com
concretebottle.com
conquerconfess.com
containsnow.com
contradictionblindness.com
convincechaotic.com
cooperatedisinfect.net
cottonbread.com
cranberrybear.com
cropcritique.com
crossoverdue.com
damageconsider.com
deardrill.com
dediccatedconsideration.com
deducedefend.com
deliverconcern.net
densefoot.com
desireeclipse.com
detaincharity.net
deterdiffusion.com
devotionbelief.com
distractionfar.com
drivesplash.com
drummerjourney.com
dumplingbell.com
electric-prime.com
elifluousscintillam.com
eminententwine.com
exhibitexpanse.com
fallaciousessential.net
fearevolve.com
fileswaper.com
finalsalami.com
flexibleelevator.com
foamdirection.com
forecastgarden.com
goatsandals.com
golfconcert.com
groundbreakinginitative.com
guitarcalculate.com
hostilefauna.com
isolatelecture.com
jellybat.net
jobmarcher.com
journeyjest.net
kartingrumble.com
labyrinthextravagance.org
leafconfuse.net
lessonhandle.com
macrodrop.net
macromint.net
maturitygenesis.com
measurecabin.com
mushroompalm.com
notableexam.org
notionnowadays.com
outdooutcome.com
parkourbus.com
patternperiod.com
penslice.com
pepperdominate.com
prawnbasket.com
predictproper.com
pressaviation.com
profligatecensure.com
rollstrech.com
romancedrum.com
sacrificeprincipal.net
salmonpride.net
scoreparade.com
selectedpazzle.com
shareitwork.com
signifyslight.com
spongefruit.com
stablesurface.com
strangegarden.org
stylebrakedown.com
suggestutterly.com
sunsetpotential.com
tacticscheap.net
tidalscreen.com
tubeshape.com
ultimatematter.info
velvetpremier.com
windomination.com
noc-service-streamer.com
fbcdnads.live
hilocake.info
backxercise.com
winmslaf.xyz
service-deamon.com
online-affiliate-mon.com
codeingasmylife.com
kenoratravels.com
weathercheck.digital
colorpallatess.com
library-update.com
online-source-validate.com
grayhornet.com
johnshopkin.net
eulenformacion.com
pochtarossiy.info

View File

@@ -0,0 +1,26 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
malware_name = "Candiru"
stix_name = "candiru.stix2"
if os.path.isfile(stix_name):
os.remove(stix_name)
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name=malware_name, is_family=False, description="IOCs related to Candiru's DevilsTongue.")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open(stix_name, "w+") as f:
f.write(bundle.serialize(indent=4))
print("{} file created".format(stix_name))

View File

@@ -0,0 +1,6 @@
# Cellebrite
Indicators of compromise to detect Cellebrite on Android.
Sources:
* [From Protest to Peril - Cellebrite Used Against Jordanian Civil Society](https://citizenlab.ca/research/from-protest-to-peril-cellebrite-used-against-jordanian-civil-society/)

View File

@@ -0,0 +1,40 @@
{
"type": "bundle",
"id": "bundle--ce7cc5a8-fa53-4ff4-841b-cf526f3c8b07",
"objects": [
{
"type": "malware",
"spec_version": "2.1",
"id": "malware--afe324d5-5d65-4060-92f9-98a5012557d0",
"created": "2026-01-22T21:58:55.050482Z",
"modified": "2026-01-22T21:58:55.050482Z",
"name": "Cellebrite",
"description": "IOCs for Cellebrite",
"is_family": false
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--55319823-913e-4283-9454-156ef3bd285c",
"created": "2026-01-22T21:58:55.051167Z",
"modified": "2026-01-22T21:58:55.051167Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.client.appA']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2026-01-22T21:58:55.051167Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--2abc42e6-3375-4bd3-a746-6199e8af5ce8",
"created": "2026-01-22T21:58:55.063505Z",
"modified": "2026-01-22T21:58:55.063505Z",
"relationship_type": "indicates",
"source_ref": "indicator--55319823-913e-4283-9454-156ef3bd285c",
"target_ref": "malware--afe324d5-5d65-4060-92f9-98a5012557d0"
}
]
}

View File

@@ -0,0 +1,38 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle)
from stix2 import CustomObservable
def hash_format(hash):
if len(hash) == 32:
return "md5"
elif len(hash) == 40:
return "sha1"
elif len(hash) == 64:
return "sha256"
else:
return None
if __name__ == "__main__":
malware_name = "Cellebrite"
stix2_file_name = "cellebrite.stix2"
if os.path.isfile(stix2_file_name):
os.remove(stix2_file_name)
with open("package_names.txt") as f:
package_names = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name=malware_name, is_family=False, description="IOCs for Cellebrite")
res.append(malware)
for package_name in package_names:
i = Indicator(indicator_types=["malicious-activity"], pattern="[app:id='{}']".format(package_name), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open(stix2_file_name, "w+") as f:
f.write(bundle.serialize(pretty=True, indent=4))
print("{} file created".format(stix2_file_name))

View File

@@ -0,0 +1 @@
com.client.appA

View File

@@ -0,0 +1,188 @@
indicators:
-
type: github
name: NSO Group Pegasus Indicators of Compromise
sources:
- Amnesty International
references:
- https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/
github:
owner: AmnestyTech
repo: investigations
branch: master
path: 2021-07-18_nso/pegasus.stix2
-
type: github
name: Predator Spyware Indicators of Compromise
sources:
- Meta
- Amnesty International
- Citizen Lab
- Cisco
- Inside Story
- iVerify
references:
- https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/
- https://about.fb.com/news/2021/12/taking-action-against-surveillance-for-hire/
- https://blog.talosintelligence.com/mercenary-intellexa-predator/
- https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/
- https://insidestory.gr/article/predatorgate-ti-egrafan-ta-sms-pagida-poy-elavan-epiheirimaties-ypoyrgoi-kai-dimosiografoi
- https://iverify.io/blog/trust-broken-at-the-core
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: intellexa_predator/predator.stix2
-
type: github
name: RCS Lab Spyware Indicators of Compromise
sources:
- Google
- Lookout
references:
- https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan/
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: 2022-06-23_rcs_lab/rcs.stix2
-
type: github
name: Stalkerware Indicators of Compromise
sources:
- ECHAP
references:
- https://github.com/AssoEchap/stalkerware-indicators
github:
owner: AssoEchap
repo: stalkerware-indicators
branch: master
path: generated/stalkerware.stix2
-
type: github
name: Surveillance campaign linked to mercenary spyware company
sources:
- Amnesty International
- Google
references:
- https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
- https://www.amnesty.org/en/latest/news/2023/03/new-android-hacking-campaign-linked-to-mercenary-spyware-company/
github:
owner: AmnestyTech
repo: investigations
branch: master
path: 2023-03-29_android_campaign/malware.stix2
-
type: github
name: Quadream KingSpawn Indicators of Compromise
sources:
- Citizen Lab
- Microsoft
references:
- https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/
- https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: 2023-04-11_quadream/kingspawn.stix2
-
type: github
name: Operation Triangulation Indicators of Compromise
sources:
- Kaspersky Lab
references:
- https://securelist.com/operation-triangulation/109842/
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: 2023-06_01_operation_triangulation/operation_triangulation.stix2
-
type: github
name: WyrmSpy and DragonEgg Indicators of Compromise
sources:
- Lookout
references:
- https://www.lookout.com/threat-intelligence/article/wyrmspy-dragonegg-surveillanceware-apt41
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: 2023-07-25_wyrmspy_dragonegg/wyrmspy_dragonegg.stix2
-
type: github
name: Wintego Helios Indicators of Compromise
sources:
- Amnesty International
references:
- https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/
github:
owner: AmnestyTech
repo: investigations
branch: master
path: 2024-05-02_wintego_helios/wintego_helios.stix2
-
type: github
name: NoviSpy (Serbia) Indicators of Compromise
sources:
- Amnesty International
references:
- https://securitylab.amnesty.org/latest/2024/12/serbia-a-digital-prison-spyware-and-cellebrite-used-on-journalists-and-activists/
github:
owner: AmnestyTech
repo: investigations
branch: master
path: 2024-12-16_serbia_novispy/novispy.stix2
-
type: github
name: Candiru (DevilsTongue) Indicators of Compromise
sources:
- Microsoft
- Recorded Future
references:
- https://www.microsoft.com/en-us/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
- https://www.recordedfuture.com/research/tracking-candirus-devilstongue-spyware
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: candiru/candiru.stix2
-
type: github
name: ResidentBat Indicators of Compromise
sources:
- Reporters Without Borders
- RESIDENT.NGO
references:
- https://rsf.org/en/exclusive-rsf-uncovers-new-spyware-belarus
- https://rsf.org/sites/default/files/medias/file/2025/12/report.pdf
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: ResidentBat/residentbat.stix2
-
type: github
name: Cellebrite Indicators of Compromise
sources:
- Citizen Lab
references:
- https://citizenlab.ca/research/from-protest-to-peril-cellebrite-used-against-jordanian-civil-society/
github:
owner: mvt-project
repo: mvt-indicators
branch: main
path: cellebrite/cellebrite.stix2

View File

@@ -0,0 +1,22 @@
# Predator Spyware Indicators of Compromise
This repository contains network and device indicators of compromised (IoCs) related to the IOS and Android Predator spyware tools developed by the cyber-surveillance company Intellexa (formerly Cytrox). These indicators were extracted from multiple reports including:
* [Threat Report on the Surveillance-for-Hire Industry](https://about.fb.com/news/2021/12/taking-action-against-surveillance-for-hire/) by Meta
* ["Pegasus vs. Predator - Dissidents Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware"](https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/) report by the Citizen Lab
* ["Predator in the wires - Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions"](https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/) report by the Citizen Lab
* [Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware](https://blog.talosintelligence.com/mercenary-intellexa-predator/) by Cisco Talos
* [Predatorgate: Τι έγραφαν τα SMS-παγίδα που έλαβαν επιχειρηματίες, υπουργοί και δημοσιογράφοι](https://insidestory.gr/article/predatorgate-ti-egrafan-ta-sms-pagida-poy-elavan-epiheirimaties-ypoyrgoi-kai-dimosiografoi) by Inside Story
* [Active Lycantrox infrastructure illumination](https://blog.sekoia.io/active-lycantrox-infrastructure-illumination/) by Sekoia
* [Predator Spyware Operators Rebuild Multi-Tier Infrastructure to Target Mobile Devices](https://www.recordedfuture.com/predator-spyware-operators-rebuild-multi-tier-infrastructure-target-mobile-devices) by Recorded Future
* [The Predator spyware ecosystem is not dead](https://blog.sekoia.io/the-predator-spyware-ecosystem-is-not-dead/) by Sekoia
* [Trust Broken at the Core](https://iverify.io/blog/trust-broken-at-the-core) by iVerify
* Additional indicators of compromise were identified by the Amnesty Tech Security Lab as part of an independent investigation.
The STIX2 file can be used with the [Mobile Verification Toolkit](https://github.com/mvt-project/mvt) to look for potential signs of compromise on Android phones and iPhones.
It includes the following files:
* `config_profiles.txt`: UUID of suspicious configuration profiles dropped by the Predator spyware
* `predator.stix2`: [STIX2](https://oasis-open.github.io/cti-documentation/stix/intro.html) file containing all indicators
* `domains.txt`: list of Predator domains
* `file_paths.txt`: file paths for Predator payloads on disk in Android and iOS.

View File

@@ -0,0 +1 @@
76DAB334-7E17-475D-A5D6-0794EB5818A5

View File

@@ -0,0 +1,569 @@
02s.co
06g.co
09a.co
2-gis.kz
2y4nothing.xyz
5m5.io
9o.gg
actualite.emergence-mada.com
actumali.org
addons.news
adenuncia.com
adibjan.net
adservices.gr.com
adultpcz.xyz
advertsservices.com
advfb.xyz
affise.app
africa-confidentiel.fr
afrinew.net
air-shopping.net
allafrika.live
almal-news.com
almasryelyuom.com
almasrylayoum.com
alpineai.uk
alraeeenews.com
alraeesnews.net
altsantiri.news
amazing.lab
ancienthistory.xyz
android-apps.tech
angop.co
aoatlasescort.com
api-apple-buy.com
api-telecommunication.com
applepps.com
apps-ios.net
aramexegypt.com
astanapark.com
atheere.com
audit-pvv.com
bank-alahly.com
bbcsworld.com
bbitly.com
beroxe.com
bestwesternt.com
betly.me
bit-li.com
bitlinkin.xyz
bit-li.ws
bitlly.live
bi.tly.gr.com
bi.tly.link
bit-ly.link
bit-ly.org
bitlyrs.com
bitshort.info
bitt.fi
bityl.me
bity.ws
blacktrail.xyz
blitzmedia.live
blocoinformativo.com
bmw.gr.com
bni-madagascar.com
bookjob.club
breaknews.live
brkorage.live
browsercheck.services
btlin.life
buildneeds.net
bulk-ads.com
bumabara.bid
burgerprince.us
businesnews.net
businessafricaonline.org
bw-guardian.com
cabinet-salyk.kz
candidaturasminfin.info
candidaturassonangol.info
canyouc.xyz
carrefourmisr.com
cbbc01.xyz
c.betly.me
celebrnewz.xyz
cellconn.net
centent-management.net
charmander.xyz
chat-support.support
chatwithme.store
cibeg.online
citroen.gr.com
ckforward.one
clazc.com
clckbck.com
clcti.net
clockupdate.com
cloudstatistics.net
cloudtimesync.com
clubs-k.com
cnn.gr.com
cnn-portugal.com
coazoa.com
conlnk.one
connectivitychecker.com
connectivitycheck.live
connectivitycheck.online
conodeti.com
contents-domain.com
copy-note.net
corporatebusinesssolution.net
correiosdeangola.info
cosmote.center
covid19masks.shop
crashonline.site
culniks.info
cut.red
cyber.country
danas.bid
dealstransfer.net
despachantonline.com
despachosnegocios
dhll.live
distedc.com
download4you.xyz
dragonair.xyz
dw-news.co
dzhabarzan.com
eagerfox.xyz
ebill.cosmote.center
edolio5.com
efsyn.news
efsyn.online
eg-gov.org
egypt-post.com
egyqaz.com
ehudaldaa.com
e-kgd.kz
elpais.me
elwatnanews.com
emvolio-gov.gr
engine.ninja
enigmase.xyz
enikos.news
ereportaz.news
escortbabesluxo.com
espressonews.gr.com
etisalategypt.tech
etisalatgreen.com
eventes.org
eventnews.live
ewish.cards
exclusivo24h.com
factosdiarios.co
factosdiarios.online
fastdownload.me
fastnews.biz
fast-notify.com
fastuploads.xyz
fbc8213450838f7ae251d4519c195138.xyz
fdnews.info
ferrari.gr.com
ffoxnewz.com
fimes.gr.com
fireup.xyz
fisherman.engine.ninja
flash.gr.com
flexipagez.com
flowercafee.com
flytaps.com
folha8.net
folha9.info
folha-9.com
forwardeshoptt.com
fr-monde.com
gabzmus.com
geloraku.id
get-location.com
get-location.net
getsignalapps.com
getsignalapps.live
getupdatesnow.xyz
glbnews.live
goldenscent.net
goldenscint.com
goldescent.com
gorlovski.com
gorows.live
gosokm.com
gostosadeluxo.com
growebservice.com
grupohel.social
grvnews.live
guardian-tt.me
guardnew.live
guardnews.live
gulfsports.info
gulfsports.live
gulfweather.live
heaven.army
heiiasjournai.com
hellasjournal.company
hellasjournal.website
hellottec.art
hempower.shop
highclub.life
hopnope.xyz
icloudeu.com
icloudflair.com
iibt.xyz
ikea-egypt.net
ilnk.xyz
imparcialpress.com
inews.gr.com
informacao24.com
informationrank.net
informburo.info
infosms-a.site
in-politics.com
inservices.digital
insider.gr.com
instagam.click
instagam.in
instagam.photos
instegram.co
insurance.gr.com
intercontinentalhg.com
intnews.world
invoker.icu
ios-apps.store
iosmnbg.com
itcgr.live
itly.link
itter.me
jakalas.online
jofki.com
jornaldeangola.co
jornaldeangola.info
jornaldeangola.net
jornalf8.co
jornalf8.com
jquery-updater.xyz
jumia-egy.com
kalwaski.xyz
kapital-news.com
kathimerini.news
kejoranews.net
kinder.engine.ninja
koenigseggg.com
kohaicorp.com
kollesa.com
koora-egypt.com
kormoran.bid
kranos.gr.com
krisha-kz.com
kroal.com
kz-news.cc
kz-shops.me
ladiesclubhouse.com
lamborghini-s.shop
landingpge.xyz
landingpg.xyz
leanwithme.xyz
leefco.net
lexpress.me
lexpress-mg.xyz
lexpressmg.xyz
lifestyleshops.net
lilpastanews.co
limk.one
linkit.cloud
linkit.digital
link-m.xyz
link-protection.com
linktothisa.xyz
liponals.store
live24.gr.com
liveco.live
livingwithbadkidny.xyz
llinkedin.net
lnkedin.org
localegem.net
lttlnk.net
lubentv.com
lusofonia-mundo.com
lylink.online
mada.sahia-mijoro.com
magnum-kz.com
makeitshort.xyz
mastershop.biz
mb-ph.net
md-news-direct.com
midi-madgasikara.co
mifcbook.link
miniiosapps.xyz
mitube1.link
mlinks.ws
mmegi.co
mobnetlink1.com
mobnetlink2.com
mobnetlink3.com
moncn.co
mozillaupdate.xyz
msas.ws
msbsck.com
mujimbo.co
mujimbos.co
mujmbosnoticias.com
mulherevips.com
mult.icaixa.info
mundodenoticias.online
mycoffeeshop.shop
myfawry.net
myfcbk.net
mytrips.quest
myutbe.net
mywebsitevpstest.xyz
nabde.app
nabd.site
nassosblog.gr.com
nemshi.net
nemshi-news.live
nemshi-news.xyz
networkenterprise.net
newsbeast.gr.com
newslive2.xyz
newspool.net
newsreuter.com
newsworldsports.co
newzeto.xyz
newzgroup.xyz
niceonase.com
niceonesa.net
nikjol.xyz
nissan.gr.com
nm-weather.live
nospam.kz
notifications-sec.com
notify-kz.info
notify-service.biz
novojornal.co
novojornal.info
novosti.bid
nur-news.com
oilgy.xyz
olexegy.com
olimpbets.kz
olxeg.com
omanreal.net
omeega.xyz
ongs.life
ongsworld.com
onlineservices.gr.com
onlinewebinarmarketing.com
orangegypt.co
orchomenos.news
ordas-kz.com
otaupdatesios.com
paok-24.com
pastepast.net
pasteposta.com
pdfviewer.app
pelovkin.com
people-beeline.com
peticaonline.comv
plastictoysworld.com
platinalines.com
playestore.net
plinkypong.com
pocopoc.xyz
podcastnow.club
politika.bid
politique-koaci.info
popup-pw.info
portalxa.com
post-kz.info
post-notify.info
prmopromo.com
pronews.gr.com
protothema.live
proupload.xyz
ps1link.xyz
ps2link.xyz
qamqors.net
qazsporttv.com
quick-ads.com
quickupdates.xyz
qwert.xyz
qwxzyl.com
rcuples.com
redeitt.com
redirecting.live
redirecting.page
redirto.info
rozavetrovv.com
safelyredirecting.com
safelyredirecting.digital
schedulefestival.com
sdntribune.co
sec-flare.com
sepenet.gr.com
sephoragroup.com
servers-mobile.info
serviceupdaterequest.com
sextape225.me
shanam.org
shop-collect.com
shortely.xyz
shorten.fi
shortenurls.me
shortly.work
shortmee.one
shortwidgets.com
shortxyz.com
showsme.info
shoxtek.com
sicnoticia.com
simetricode.uk
sinai-new.com
sitepref.xyz
skollie.online
skranski.com
sky-news.live
smallme.net
smcu.me
smsuns.com
snapfire.xyz
sniper.pet
soccer-bw.com
solargoup.xyz
solargroup.xyz
soq.one
spacsaver.info
speedygonzales.xyz
speedymax.shop
speedy.sbs
sportnow.news
sports-mdg.xyz
sportsnewz.site
static-graph.com
stonisi.news
suarajubi.com
suarajubi.net
suarapapua.co
supportset.net
sustanbuild.com
suzuki.gr.com
svetovid.bid
symoty.com
syncservices.one
synctimestamp.com
syncupdate.site
sysly.sbs
sysnet.life
taagangola.co
t-bit.me
tclnk.live
telecomegy-ads.com
telenorconn.com
tengrinnews.live
teslali.com
teslal.shop
teslal.xyz
tesla-s.shop
tgrthgsrgwrthwrtgwr.xyz
thintank.co
tickets-kz.com
timestampsync.com
timeupdateservice.com
timeupdate.xyz
tiny.gr.com
tinylinks.live
tinyulrs.com
tinyurl.cloud
tiol.xyz
tly.gr.com
tly.link
tobupmi.com
tohna.net
tokoulouri.live
tovima.live
traffic-moi-eg.org
t-ready.me
trecvf.xyz
trecv.xyz
tribune-mg.xyz
trkc.online
truelocation.org
tsapp.me
tsrt.xyz
tupuca.co
tvxs.news
tw.itter.me
twtter.net
ube.gr.com
uberegypt.cn.com
ulstur.co
unitei.co
universedades.com
updates4you.xyz
updateservice.center
updatetime.zone
updatingnews.xyz
updete.xyz
url-promo.club
url-tiny.app
uservicescheck.com
uservicesforyou.com
utube.digital
utube.to
vaovao.soutien-a-rajoelina.com
vendaswebs.com
verifyurl.me
vestinfo.net
vestinfo.org
vestinfos.net
vinho-online.com
vinhosadega.com
visavfsglobal.co
viva.gr.com
vlast-news.com
vodafoneegypt.tech
vodafonegypt.com
vouliwatch.gr.com
vslojasvendas.com
wa-info.com
walatparez.com
wavekli.xyz
weathear.live
weather-live.com
weathernewz.xyz
weathersite.online
webaffise.com
weekendcool.com
wesalcity.net
we-site.net
wha.tsapp.me
whatssapp.co
worldnws.xyz
wtc1111.com
wtc2222.com
wtc3333.com
wts-app.info
xf.actor
xnxx-hub.com
xyvok.xyz
yallakora-egy.com
youarefired.xyz
yo-um7.com
youtub.app
yo.utube.digital
youtub-eg.com
yout.ube.gr.com
youtube.gr.live
youtu-be.net
youtubesyncapi.com
yo.utube.to
youtube.voto
youtubewatch.co
yuom7.net
z2a.digital
z2adigital.cloud
z2digital.cloud
zakorn.com
zikolo.net
zoometting.com
zougla.gr.com
zougla.news
ztb-news.com

View File

@@ -0,0 +1,16 @@
/private/var/tmp/UserEventAgent
/private/var/tmp/com.apple.WebKit.Networking
/private/var/tmp/hooker
/private/var/tmp/takePhoto
/private/var/logs/keybagd/
/private/var/tmp/kusama.txt
/private/var/tmp/etherium.txt
/private/var/tmp/helper.sock
/private/var/tmp/etherium.txt
/private/var/tmp/l/
/tmp/etherium.txt
/tmp/kusama.txt
/tmp/l/
/data/local/tmp/wd/pred.so
/data/local/tmp/wd/fs.db
/data/local/tmp/wd/

View File

@@ -0,0 +1,41 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
if os.path.isfile("predator.stix2"):
os.remove("predator.stix2")
with open("config_profiles.txt") as f:
configs = list(set([a.strip() for a in f.read().split()]))
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("file_paths.txt") as f:
filepaths = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name="Predator", is_family=False, description="IOCs for Intellexa Predator")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for f in filepaths:
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:path='{}']".format(f), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for c in configs:
i = Indicator(indicator_types=["malicious-activity"], pattern="[configuration-profile:id='{}']".format(c), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open("predator.stix2", "w+") as f:
f.write(bundle.serialize(indent=4))
print("predator.stix2 file created")

File diff suppressed because it is too large Load Diff