Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update cobaltstrike-1.txt #19132

Open
wants to merge 10 commits into
base: master
Choose a base branch
from

Conversation

conexioninversa
Copy link

@MikhailKasimov
Copy link
Collaborator

MikhailKasimov commented Nov 28, 2022

omg... this will take some time for me. Will re-work your records.

@MikhailKasimov MikhailKasimov self-assigned this Nov 29, 2022
@conexioninversa
Copy link
Author

If you want I can leave only IP and port.
The idea is to make a pull request weekly. as long as it sounds good.

@MikhailKasimov
Copy link
Collaborator

Usually I parse https://github.com/conexioninversa/C2Intel/blob/main/C2Domain.csv once a week. If I lucky today to have stable electricity in the evening, I would proceed your PR.

@MikhailKasimov
Copy link
Collaborator

MikhailKasimov commented Nov 29, 2022

All is done for now. No need to create these trails:

image

they do live in malicious folder:

image

I have refactored detections you've proposed for merging and put them to respective trails minus some FPs.

Quesion: https://github.com/conexioninversa/MalwareIntel/blob/main/C2_Panda.txt <-- what is it in your case? Because some vendors put name Panda for multiple Zeus banking trojan variations. And I'm little bit confused of C2_Panda name. Thanks!

@conexioninversa
Copy link
Author

All is done for now. No need to create these trails:

image

they do live in malicious folder:

image

I have refactored detections you've proposed for merging and put them to respective trails minus some FPs.

Quesion: https://github.com/conexioninversa/MalwareIntel/blob/main/C2_Panda.txt <-- what is it in your case? Because some vendors put name Panda for multiple Zeus banking trojan variations. And I'm little bit confused of C2_Panda name. Thanks!

Basically it is from various reversing performed on various samples obtained.
I'm going to check though that these signatures are ok.
At the moment do not add these IPs that I have provided you on PANDA
Thanks

@MikhailKasimov
Copy link
Collaborator

Basically it is from various reversing performed on various samples obtained. I'm going to check though that these signatures are ok. At the moment do not add these IPs that I have provided you on PANDA Thanks

OK, expecting info from you. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants