PULSE NAME
New Ryuk infrastructure February 2021
WHITE UNC1878 AlienVault 2021-02-17 Modified: 2021-02-19
29
IOCs
MEDIUM VOLUME
New Ryuk infrastructure February 2021 based on domain registration, SSL certificate characteristics and Cobalt Strike patterns.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Cobalt Strike
Indicators of Compromise (29)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain bestampage.com 2021-02-17
domain bestserviceupdate.com 2021-02-17
domain boosterion.com 2021-02-17
domain cheeservice.com 2021-02-17
domain dresservice.com 2021-02-17
domain fast1arrival.com 2021-02-17
domain finderist.com 2021-02-17
domain finderout.com 2021-02-17
domain firstaholic.com 2021-02-17
domain firstient.com 2021-02-17
domain jobjean.com 2021-02-17
domain jobsmarc.com 2021-02-17
domain kolsunday.com 2021-02-17
domain lightingfastnetsolutions.com 2021-02-17
domain oldentistry.com 2021-02-17
domain otherfind.com 2021-02-17
domain owaoffice365.com 2021-02-17
domain servicenary.com 2021-02-17
domain sundize.com 2021-02-17
domain topother.com 2021-02-17
domain viewhuntly.com 2021-02-17
domain bestbookstore.org 2021-02-18
domain laboratorer.com 2021-02-18
domain viewcoaching.com 2021-02-18
domain anbackup.com 2021-02-19
domain first-makler.pro 2021-02-19
domain servicebeats.com 2021-02-19
domain showyoursysteminfosphe.xyz 2021-02-19
domain top1serviceboost.com 2021-02-19