SteelFox Trojan IOCs - SEC-1275-1
Tags
attack-pattern: | Dns - T1071.004 Dns - T1590.002 Ssl Pinning - T1521.003 |
Common Information
Type | Value |
---|---|
UUID | bb1f9d8c-a104-477c-9b1a-782014551ae8 |
Fingerprint | f749ed0397fec55b |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Nov. 8, 2024, midnight |
Added to db | Nov. 8, 2024, 10:29 a.m. |
Last updated | Nov. 17, 2024, 7:44 p.m. |
Headline | SteelFox Trojan IOCs |
Title | SteelFox Trojan IOCs - SEC-1275-1 |
Detected Hints/Tags/Attributes | 8/1/50 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://1275.ru/ioc/7939/steelfox-trojan-iocs/?mtm_campaign=rss |
URL Provider
Details | Provider | Source level domain |
---|---|---|
Details | 1275.ru | 1275.ru |
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 8 | ✔ | Архивы IOC - SEC-1275-1 | https://1275.ru/ioc/feed | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 3 | ankjdans.xyz |
|
Details | Domain | 194 | drive.google.com |
|
Details | Domain | 4127 | github.com |
|
Details | Domain | 291 | raw.githubusercontent.com |
|
Details | Domain | 3 | squarecircle.ru |
|
Details | Domain | 3 | www.cloudstaymoon.com |
|
Details | File | 16 | winring0.sys |
|
Details | File | 3 | jetbrains-activator.exe |
|
Details | Github username | 1 | cppdev-123 |
|
Details | Github username | 1 | davidnguyen67 |
|
Details | Github username | 1 | taronsargsyan123 |
|
Details | Github username | 1 | tranquanghuy-09 |
|
Details | Github username | 1 | trungga123 |
|
Details | md5 | 1 | 015595d7f868e249bbc1914be26ae81f |
|
Details | md5 | 1 | 040dede78bc1999ea62d1d044ea5e763 |
|
Details | md5 | 1 | 051269b1573f72a2355867a65979b485 |
|
Details | md5 | 1 | 08fa6ebc263001658473f6a968d8785b |
|
Details | md5 | 1 | 0947cca1b5509f1363da20a0a3640700 |
|
Details | md5 | 1 | 0ce3775fbfbe8f96e769822538c9804c |
|
Details | md5 | 1 | 0f2f104dcc4a6c7e3c258857745d70fb |
|
Details | md5 | 1 | 11caf769c0fb642bbb3daa63e516ca54 |
|
Details | md5 | 1 | 5029b1db994cd17f2669e73ce0a0b71a |
|
Details | md5 | 1 | 69a74c90d0298d2db34b48fa6c51e77d |
|
Details | md5 | 1 | 84b29b171541c8251651cabe1364b7b6 |
|
Details | md5 | 3 | 9dff2cdb371334619b15372aa3f6085c |
|
Details | md5 | 3 | c20e1226782abdb120e814ee592bff1a |
|
Details | md5 | 3 | c6e7c8c76c7fb05776a0b64699cdf6e7 |
|
Details | md5 | 1 | d5290ba0cd8529032849ae567faba1ce |
|
Details | md5 | 1 | d715507131bbf4ca1fe7bc4a5ddfeb19 |
|
Details | md5 | 1 | dc8c18e4b729fdbf746252b2fc1decc5 |
|
Details | md5 | 1 | dc9d42902bda8d63e5858b2a062aecc1 |
|
Details | md5 | 1 | e7c4e02e1da5afb56a2df0996784a9d5 |
|
Details | md5 | 1 | e9a14ae0f7eb81346eac9d039138a7d8 |
|
Details | md5 | 1 | f3690f597c725553b8ced0179f4f032e |
|
Details | md5 | 1 | f8f6c7d65b28b978e4f2a40158973a0c |
|
Details | md5 | 3 | fb94950342360aa1656805f6dc23a1a0 |
|
Details | IPv4 | 3 | 205.185.115.5 |
|
Details | Url | 3 | https://ankjdans.xyz |
|
Details | Url | 3 | https://drive.google.com/file/d/1bhdbvmywfg2551ommpo3_5vaeynj7pe5/view?usp=sharing |
|
Details | Url | 3 | https://github.com/cppdev-123 |
|
Details | Url | 3 | https://github.com/davidnguyen67/crackjetbrains |
|
Details | Url | 3 | https://github.com/taronsargsyan123/scarasimulation |
|
Details | Url | 3 | https://github.com/tranquanghuy-09/activate-intellij-idea-ultimate |
|
Details | Url | 3 | https://github.com/trungga123/active-all-app-jetbrains |
|
Details | Url | 3 | https://raw.githubusercontent.com/davidnguyen67/crackjetbrains/main/jetbrains-activator.exe |
|
Details | Url | 3 | https://raw.githubusercontent.com/taronsargsyan123/scarasimulation/main/jetbrains-activator.exe |
|
Details | Url | 3 | https://raw.githubusercontent.com/tranquanghuy-09/activate-intellij-idea-ultimate/main/jetbrains-activator.exe |
|
Details | Url | 3 | https://raw.githubusercontent.com/trungga123/active-all-app-jetbrains/main/jetbrains-activator.exe |
|
Details | Url | 3 | https://squarecircle.ru/intelij/jetbrains-activator.exe |
|
Details | Url | 3 | https://www.cloudstaymoon.com/2024/05/06/tools-1 |