-
Notifications
You must be signed in to change notification settings - Fork 84
/
2021-09-14 Griffon IOCs
62 lines (52 loc) · 1.87 KB
/
2021-09-14 Griffon IOCs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
THREAT IDENTIFICATION: GRIFFON (aka Harpy)
SUBJECTS OBSERVED
Bill for mobile service
Bill for subscribing Premium
Obligations of vaccination companies
Premium subscription
SENDERS OBSERVED
IMPERSONATED SENDERS
HealthResources&[email protected]
GRIFFON ZIP FILE HASH
Employees list 09.2021.zip
802dc9f2905991dee611ab6afb098afd
Bill 09.13.2021.zip
89b76cb2372ab40df840c8f1a347ed7e
GRIFFON JAVASCRIPT FILE HASH PAYLOAD
current list of employees who were included to the vaccine schedule.txt.js
f1680aa55c88220bcf83e24d89628cc9
Tinder Bill #12340098709..13.2021 - To view successfully open on Windows.txt.js
f1680aa55c88220bcf83e24d89628cc9
GRIFFON C2
https://civilizationidium.com/
ADDITIONAL C2 URLS
https://civilizationidium.com/info/add?type=name
https://civilizationidium.com/info/delete?type=name
https://civilizationidium.com/new/hide?type=name
https://civilizationidium.com/new/new?type=name
https://civilizationidium.com/new/renew?type=name
https://civilizationidium.com/new/show?type=name
SUPPORTING EVIDENCE
https://www.crowdstrike.com/blog/carbon-spider-embraces-big-game-hunting-part-1/
https://www.virustotal.com/gui/file/4e6914d95dc81000b1eaa82fc3d2162dd681ff4521c6f79204d65a0884906ea8
https://www.virustotal.com/gui/file/caa7667bfdbcb04ceb9d81df93fe805dfe4ac8a04b9dd3eaab7b5f7c87c4fc9c