Commit Graph

158 Commits

Author SHA1 Message Date
Florian Roth
51f7b978a1 FinFisher IOCs 2018-03-02 17:04:34 +01:00
Florian Roth
e9eac4fdc6
Merge pull request #25 from jantdm/patch-1
Link broken
2018-03-02 13:46:54 +01:00
Florian Roth
4bdcf3c64b Sofacy IOCs and YARA signature 2018-03-01 09:29:57 +01:00
Florian Roth
c6807a024d Dumper False Positive Reduction 2018-03-01 09:29:35 +01:00
Jan Tiedemann
786fe0bffb
Link broken
Link to DCSO Apache Struts Vulns was broken (https://goo.gl/t4FKT5). Fixed that for you (https://goo.gl/7jGkpV).
2018-02-28 20:44:59 +01:00
Florian Roth
9fca4d3b9c Fixed OTX IOCs / getall() retrieved IOCs from authors I wasn't subscribed to 2018-02-28 08:25:05 +01:00
Florian Roth
3ed59d8f58 False Positive WinPcap 2018-02-24 21:41:10 +01:00
Florian Roth
8c2e553b72 Turla Mosquito Filename IOCs 2018-02-23 09:08:45 +01:00
Florian Roth
41e27b5786 False Positive 2018-02-22 10:35:09 +01:00
Florian Roth
4bc10e04b4 False Posiitives 2018-02-19 14:40:39 +01:00
Florian Roth
2a46ed46e6 False Positives 2018-02-19 14:36:50 +01:00
Florian Roth
1cd914cb2b New format not yet ready 2018-02-15 20:53:15 +01:00
Florian Roth
3d116ff009 False Positive Reduction 2018-02-15 17:08:17 +01:00
Florian Roth
3001100959 OTX update with new whitelist 2018-02-13 12:07:33 +01:00
Florian Roth
c95a25cc72 Removed 0 byte file hashes 2018-02-13 11:36:21 +01:00
Florian Roth
1a0e093f37 OTX update 2018-02-13 08:30:41 +01:00
Florian Roth
36f88a932f Removed filename IOC that caused problem 2018-02-12 22:03:15 +01:00
Florian Roth
c7f3f6ff41 OTX Feed Update 2018-02-12 18:22:06 +01:00
Florian Roth
308861a508 Middle Eastern Campaign - Talos Report - Filename IOCs 2018-02-08 22:58:53 +01:00
Florian Roth
f51713750c False Positive Reduction 2018-02-07 14:39:28 +01:00
Florian Roth
e162741318 Fixed FP on 1 byte file containing a new line
https://github.com/Neo23x0/Loki/issues/99 OTX https://otx.alienvault.com/pulse/57e928543f5d465dafc74a78
2018-02-02 08:55:05 +01:00
Florian Roth
fad626c7e2 Elise backdoor filename IOCs 2018-01-31 23:32:10 +01:00
Florian Roth
8d8b5a5b33 Suspicious Script or Executable in Public Users Folder
https://twitter.com/JohnLaTwC/status/957703902039691265
2018-01-29 09:01:39 +01:00
Florian Roth
9b5176b38b Dark Caracal Hashes 2018-01-23 17:06:18 +01:00
Florian Roth
a1627b46f2 False Positive Reduction 2018-01-22 08:44:49 +01:00
Florian Roth
b958e733f3 False positive as report by @elvisghost
https://github.com/Neo23x0/Loki/issues/96
2018-01-12 08:21:17 +01:00
Florian Roth
e486ade31a Removed Cylance notepad.exe false positive hash 2018-01-03 00:19:06 +01:00
Florian Roth
cadbe73482 Hidden Cobra Hash IOCs
https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity
2017-12-26 01:09:29 +01:00
Florian Roth
f0312d6a9d Mimikatz output file 2017-12-20 15:47:45 +01:00
Florian Roth
e7020d1e59 Lazarus Group Hashes
https://www.proofpoint.com/us/threat-insight/post/north-korea-bitten-bitcoin-bug-financially-motivated-campaigns-reveal-new
2017-12-20 09:47:24 +01:00
Florian Roth
1f17d1f284 False Positive Reduction 2017-12-19 16:47:49 +01:00
Florian Roth
6ac7eff3ce Triton ICS malware hashes
https://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html
2017-12-19 01:44:56 +01:00
Florian Roth
0d4043a273 OTX filename and hash IOC update Dec 17 1 2017-12-16 13:22:06 +01:00
Florian Roth
201c5e55c3 OTX C2 IOC update - extracted IPv4 and IPv6 IOCs from default file 2017-12-16 13:21:38 +01:00
Florian Roth
142e856eca Lazarus group malware hash IOCs 2017-12-16 13:17:33 +01:00
Florian Roth
8d7ae7128b OTX Hash IOCs: Update and False Positives removed 2017-12-15 14:30:00 +01:00
Florian Roth
c13e07a8b5 False Positive Reduction 2017-12-12 00:59:36 +01:00
Florian Roth
14137908cc False Positive Reduction 2017-12-07 15:23:59 +01:00
Florian Roth
2c1e768adc Charming Kitten Hash IOCs 2017-12-06 22:37:12 +01:00
Florian Roth
4c893df291 Carbanak Hash IOCs 2017-12-06 22:37:01 +01:00
Florian Roth
500e6c2da2 ROKRAT Update
http://blog.talosintelligence.com/2017/11/ROKRAT-Reloaded.html
2017-11-29 16:04:36 +01:00
Florian Roth
10607e7268 Updated Hash IOCs 2017-11-23 21:48:56 +01:00
Florian Roth
c0ab6f8453 False Positives 2017-11-12 18:35:04 +01:00
Florian Roth
b08dc91116 OTX IOCs Update Nov 17 2017-11-02 09:08:22 +01:00
Florian Roth
85c8608499 False Positive Reduction 2017-10-25 23:43:56 +02:00
Florian Roth
04825e634c Sofacy Campaign IOCs 2017-10-23 19:10:44 +02:00
Florian Roth
81e2977704 False Positive Reduction 2017-10-23 16:54:34 +02:00
Florian Roth
4755027693 US-CERT TA17-293A - Part 1 - Filename, Hash, C2 IOCs
https://www.us-cert.gov/ncas/alerts/TA17-293A
2017-10-21 16:26:07 +02:00
Florian Roth
cda2de3d94 HKDoor report IOCs 2017-10-19 12:01:37 +02:00
Florian Roth
bd33c27075 OilRig filename IOCs 2017-10-19 12:01:23 +02:00