We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
http://researchcenter.paloaltonetworks.com/2015/07/apt-group-ups-targets-us-government-with-hacking-team-flash-exploit/ http://blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used/
Indicators
UPS a2fe113cc13acac2bb79a375f692b8ba5cc2fa880272adc7ab0d01f839e877ff Domains rpt.perrydale[.]com report.perrydale[.]com IPs 194.44.130[.]179 URLs rpt.perrydale[.]com /en/show.swf report.perrydale[.]com /ema/show.swf rpt.perrydale[.]com /en/b.gif report.perrydale[.]com /ema/b,gif
PawnStorm 192[.]111[.]146[.]185 (direct to IP call) www[.]acledit[.]com www[.]biocpl[.]org
The text was updated successfully, but these errors were encountered:
i'm going to wait on this one. Will add it after a few more weeks.
Sorry, something went wrong.
Yeah good call - there are at least 5 distinct articles on different groups using these already
Another HT related article: https://www.fireeye.com/blog/threat-research/2015/07/demonstrating_hustle.html
@kbandla also add this one in, closing out the origin ticket: http://blog.shadowserver.org/2015/08/10/the-italian-connection-an-analysis-of-exploit-supply-chains-and-digital-quartermasters/
kbandla
No branches or pull requests
http://researchcenter.paloaltonetworks.com/2015/07/apt-group-ups-targets-us-government-with-hacking-team-flash-exploit/
http://blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used/
Indicators
UPS
a2fe113cc13acac2bb79a375f692b8ba5cc2fa880272adc7ab0d01f839e877ff
Domains
rpt.perrydale[.]com
report.perrydale[.]com
IPs
194.44.130[.]179
URLs
rpt.perrydale[.]com /en/show.swf
report.perrydale[.]com /ema/show.swf
rpt.perrydale[.]com /en/b.gif
report.perrydale[.]com /ema/b,gif
PawnStorm
192[.]111[.]146[.]185 (direct to IP call)
www[.]acledit[.]com
www[.]biocpl[.]org
The text was updated successfully, but these errors were encountered: