Skip to content

Commit

Permalink
Add files via upload
Browse files Browse the repository at this point in the history
IoCs related to the 10 November 2023 post
  • Loading branch information
thisisagunn authored Nov 11, 2023
1 parent 07deb6b commit 6b921ed
Showing 1 changed file with 29 additions and 0 deletions.
29 changes: 29 additions & 0 deletions 2311 Vice Society - Rhysida IoCs.csv
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
Indicator,Data,Note,
Description,https://news.sophos.com/en-us/2023/11/10/vice-society-and-rhysida-ransomware/,"Same threats, different ransomware: a threat cluster�s switch from Vice Society to Rhysida; 11 November 2023",
ip address ,5.39.222.67 ,C2 Server,
ip address ,5.255.99.59,C2 Server,
ip address ,51.77.102.106 ,C2 Server,
ip address ,108.62.118.136,C2 Server,
ip address ,108.62.141.161 ,C2 Server,
ip address ,108.62.141.161,C2 Server,
ip address ,146.70.104.249 ,C2 Server,
ip address ,156.96.62.58 ,C2 Server,
ip address ,157.154.194.6,C2 Server,
SHA256 hash,b25b87cfcedc69e27570afa1f4b1ca85aab07fd416c5d0228f1fe32886e0a9a6,PortStarter DLL,
filename,C:\ProgramData\temp_l0gs\,Credential Dumping ,
filename,C:\Users\Public\secretsdump.exe,Credential Dumping Tool,
filename,<domain>.LOCAL\s$\w.ps1,Data Collection Script,
filename,s$\p1.ps1,Data Collection Script,
filename,CriticalBreachDetected.pdf,Extortion Note,
filename,C:\Downloads\MEGAsyncSetup64.exe,Mega Sync lnstaller,
filename,C:\Downloads\Advanced_IP_Scanner_2.5.4594.1.exe,Network Scanner,
filename, C:\Users\Public\main.dll,PortStarter DLL,
filename,C:\ProgramData\schk.dll,PortStarter DLL,
filename,C:\Windows\Tasks\windows32u.dll,PortStarter DLL,
filename,C:\Windows\Tasks\windows32u.ps1,PortStarter Script,
filename,Invoke-ZeroLogon.ps1,Privledge Escalation Script,
filename,PsExec.exe,PsExec,
filename,C:\s$\PsExec.exe,PsExec,
filename,C:\Programdata\Veeam\svchost.ps1,SystemBC,
filename,WinSCP.exe,WinSCP,
filename,C:\ProgramData\AnyDesk.exe,Anydesk,

0 comments on commit 6b921ed

Please sign in to comment.