Florian Roth
86de943e70
False Positive Reduced
2016-11-29 17:50:21 +01:00
Florian Roth
ad1adfb497
APT29 Post-Election Activity
2016-11-11 11:01:17 +01:00
Florian Roth
cb0c06d4b5
Removed PHP in images sections - FPs
...
[ALERT] File Name IOC matched PATTERN:
\\(images|img|js|fonts|css|swf)\\[^\\]{,20}\.(php|jsp|jspx|asp|aspx)
MATCH:
G:\Part2\Joomla_3.3.6-Stable-Full\administrator\components\com_media\vie
ws\images\view.html.php
2016-09-16 09:26:41 +02:00
Florian Roth
eca1aacf8c
File Name Characteristics Update
2016-09-16 08:53:24 +02:00
Florian Roth
dcd5367120
Webshell Name
2016-09-11 16:30:01 +02:00
Florian Roth
80849d2434
APT29 IOCs and Pirpi YARA Rules
2016-09-11 15:59:36 +02:00
Florian Roth
8b303b41e3
JSP Webshell Names by Cisco Talos
2016-08-30 19:41:19 +02:00
Florian Roth
f10ecb5929
Project Sauron IOCs
2016-08-08 17:29:28 +02:00
Florian Roth
09c01737cc
Filename IOCs
2016-07-16 11:19:40 +02:00
Florian Roth
669bb122ec
OTX Update
2016-07-02 19:31:25 +02:00
Florian Roth
a248f3d8a9
Bugfix in prikormka Rules
2016-06-17 17:24:28 +02:00
Florian Roth
a3323e83aa
Sofacy Samples June 2016
...
http://researchcenter.paloaltonetworks.com/2016/06/unit42-new-sofacy-att
acks-against-us-government-agency/
2016-06-15 06:54:30 +02:00
Florian Roth
bfdf1bba60
FireEye IronGate APT Yara Rules & File Name IOCs
2016-06-04 17:32:21 +02:00
Florian Roth
99a0bada53
Signature Update
...
- New PoisonIvy Rule
- ONHAT proxy tool (htran like)
- BeepService APT group hack tool
- Sofacy Adjustments
2016-05-13 06:06:18 -06:00
Florian Roth
3215f8285a
Removed False Positive
2016-02-23 19:18:31 +01:00
Florian Roth
4d17221b65
First Signature Set
2016-02-15 10:22:28 +01:00