From b29038f16a5719e9ad3899d536cb78440c327c42 Mon Sep 17 00:00:00 2001 From: StrangerealIntel <54320855+StrangerealIntel@users.noreply.github.com> Date: Mon, 26 Aug 2019 22:53:27 +0200 Subject: [PATCH] Update Malware analysis 25-08-19.md --- Pakistan/APT/Gorgon/23-08-19/Malware analysis 25-08-19.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/Pakistan/APT/Gorgon/23-08-19/Malware analysis 25-08-19.md b/Pakistan/APT/Gorgon/23-08-19/Malware analysis 25-08-19.md index fdd2ed5..f3e2dbe 100644 --- a/Pakistan/APT/Gorgon/23-08-19/Malware analysis 25-08-19.md +++ b/Pakistan/APT/Gorgon/23-08-19/Malware analysis 25-08-19.md @@ -10,7 +10,7 @@ + [Bitly link](#bitly) + [C2 domains](#C2) + [The troubling case of the Hagga account](#Hagga) -* [IOC](#IOC) +* [Indicators Of Compromise (IOC)](#IOC) * [References MITRE ATT&CK Matrix](#Ref-MITRE-ATTACK) * [Links](#Links) + [Original Tweet](#Original-Tweet) @@ -136,6 +136,7 @@ | Indicator | Description| | ------------- |:-------------| |IMG76329797.xls|e66181155a9cd827def409135334ecf173459e001e79853e1b38f2b8e5d8cc59| +|Inj.dll|84833991F1705A01A11149C9D037C8379A9C2D463DC30A2FEC27BFA52D218FA6| |mse60dc.exe|de314d038d9b0f8ff32cfe3391c4eec53a3e453297978e46c9b90df2542ed592| |bitly.com|domain requested| |xaasxasxasx.blogspot.com|domain requested| @@ -165,9 +166,9 @@ |210.188.195.164|IP C2| |23.20.239.12|IP C2| |185.68.16.122|IP C2| -|199.192.23.220|IP C2v +|199.192.23.220|IP C2| -###### This can be exported as JSON format [Export in JSON]() +###### This can be exported as JSON format [Export in JSON](https://raw.githubusercontent.com/StrangerealIntel/CyberThreatIntel/master/Pakistan/APT/Gorgon/23-08-19/IOC_Gorgon_25-08-19.json) ## Links