From 1256b73f26be8c87568f06b646afc888b48440c5 Mon Sep 17 00:00:00 2001 From: StrangerealIntel <54320855+StrangerealIntel@users.noreply.github.com> Date: Mon, 14 Oct 2019 23:01:41 +0200 Subject: [PATCH] Create IOC-SideWinder-14-10-19.json --- .../11-10-2019/IOC-SideWinder-14-10-19.json | 30 +++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 Indian/APT/SideWinder/11-10-2019/IOC-SideWinder-14-10-19.json diff --git a/Indian/APT/SideWinder/11-10-2019/IOC-SideWinder-14-10-19.json b/Indian/APT/SideWinder/11-10-2019/IOC-SideWinder-14-10-19.json new file mode 100644 index 0000000..04e4a2e --- /dev/null +++ b/Indian/APT/SideWinder/11-10-2019/IOC-SideWinder-14-10-19.json @@ -0,0 +1,30 @@ +[ + { + "Indicator": "zhengce.doc", + "Description": "b1417d7ee62878ef75381e4a3a4f388ac08ac4d4bbd9999b126345691e82b0c2" + }, + { + "Indicator": "C:\\ProgramData\\AuthyFiles\\PROPSYS.dll\r", + "Description": "4e12d1bf1a631b8045e267671c0340b8da61777480692c4ce396f932f6bd4023" + }, + { + "Indicator": "C:\\ProgramData\\AuthyFiles\\write.exe\r", + "Description": "45BD87A5803916409A0D824BEEFAFB1FAF49D52E0BA9C0E8014E82EAA17E7659" + }, + { + "Indicator": "1.a", + "Description": "c5feee527bb90926949c572bfe3fceb862727a9f5cee1fc580a11558253d624e" + }, + { + "Indicator": "Authy", + "Description": "99542270c355bdaef251fefeaf88c5ff747e3837501735887e7b2b7b54e2e2f2" + }, + { + "Indicator": "178.62.190.33", + "Description": "IP C2" + }, + { + "Indicator": "trans-can.net", + "Description": "Domain C2" + } +]