PULSE NAME
Rubella and Dryad Office Macro Builder
WHITE AlienVault 2019-07-18 Modified: 2019-07-18
17
IOCs
MEDIUM VOLUME
Rubella Macro Builder is such a toolkit and was offered by an actor by the same nickname “Rubella”. The toolkit was marketed with colorful banners on different underground forums. For the price of 500 US Dollars per month you could use his toolkit to weaponize Office documents that bypass end-point security systems and deliver a malicious payload or run a PowerShell Code of your choice.
Indicators of Compromise (17)
All domain FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
domain tailoredtaboo.com 2019-07-18
FileHash-SHA256 c777012abe224126dca004561619cb0791096611257099058ece1b8d001277d0 2019-07-18
FileHash-SHA256 3c55e54f726758f5cb0d8ef81be47c6612dba5a73e3a29f82b73a4c773e691a3 2019-07-18
FileHash-SHA256 388ee9bc0acaeec139bc17bceb19a94071aa6ae43af4ec526518b5e1f1f38f07 2019-07-18
FileHash-SHA256 93db479835802dc22ba5e55a7915bd25f1f765737d1efab72bde11e132ff165a 2019-07-18
FileHash-SHA256 b7a86965f22ed73de180a9f98243dc5dcfb6ee30533d44365bac36124b9a1541 2019-07-18
FileHash-SHA256 a17e3c2271a94450a7a7c6fcd936f177fc40ea156de4deafdfc14fd5aadfe503 2019-07-18
FileHash-SHA256 08694ad23cafe45495fa790bfdc411ab5c81cc2412370633a236c688b07d26aa 2019-07-18
FileHash-SHA256 7d1603f815715a062e18ae56ca53efbaecc499d4193ea44a8aef5145a4699984 2019-07-18
FileHash-SHA256 74c8389f20e50ae3a9b7d7e69f6ae7ed1a625ccc8bb6a52b3cc435cf94e6e2d3 2019-07-18
FileHash-SHA256 2a20d3d9ac4dc74e184676710a4165c359a56051c7196ca120fcf8716b7c21b9 2019-07-18
FileHash-SHA256 c2c2fdcc36569f6866e19fcda702c823e7bf73d5ca394652ac3a0ccc6ff9c905 2019-07-18
FileHash-SHA256 ad2f9ef7142a43094161eae9b9a55bfbb6dff85d890d1823e77fc4254f29ef17 2019-07-18
FileHash-SHA256 5b773acad7da2f33d86286df6b5e95ae355ac50d143171a5b7ee61d6b3cad6d5 2019-07-18
FileHash-SHA256 428a30b8787d2ba441dba1dbc3acbfd40cf7f2fc143131a87a93f27db96b7a75 2019-07-18
FileHash-SHA256 1de0ebc0c375332ec60104060eecad77e0732fa2ec934f483f330110a23b46e1 2019-07-18
URL https://tailoredtaboo.com/auth/check.php 2019-07-18