PULSE NAME
Don't get BITTER about being targeted -- fight back with the help of the community.
WHITE BITTER AlienVault 2024-03-01 Modified: 2024-03-01
173
IOCs
HIGH VOLUME
When enterprise security operations centers receive alerts about obvious true positive detections, they want to quickly understand the severity to determine if it is a critical threat that needs immediate containment. Threat intelligence analysts can provide context about whether the attack is part of a bigger campaign. Although some victim and vendor analysis is still closely held, there has been a clear increase in sharing of threat intelligence within the TLP-white community. Analysts often cannot submit samples to services like VirusTotal due to privacy restrictions, so they cannot take advantage of crowdsourced threat intel. The CARA platform guides analysts through investigative steps without compromising controls. By pivoting on domains, behaviors and code similarities, analysts can connect alerts to related attacks, like BITTER campaigns, to inform response priorities.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
DarkWatchman - S0673 Backdoor.Oldrea - S0093 Havex
Indicators of Compromise (25 / 173 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 16696b82884de21b3ef5a3b27872d53c 2024-03-01
FileHash-MD5 1fa66d93db415a90e1ba6b09a53cc694 2024-03-01
FileHash-MD5 26c59bd3fd3d6680c1c1e86dc34716fd 2024-03-01
FileHash-MD5 2fb6ffb8bd8861943893127d2956749b 2024-03-01
FileHash-MD5 3018798bc32f02fb392197c4731095f9 2024-03-01
FileHash-MD5 313bee67ac85d0aed3fbd049f9d2b0e3 2024-03-01
FileHash-MD5 338240093510cdb40897901e1cc4e619 2024-03-01
FileHash-MD5 34104f2ee58f629d7222cce339a24db5 2024-03-01
FileHash-MD5 46545bb03e5359262a125133a91632dc 2024-03-01
FileHash-MD5 485b6e2bef303251789827d7829e3a3e 2024-03-01
FileHash-MD5 59d03e432dfa160afa906a216180a1bc 2024-03-01
FileHash-MD5 85b2457b9f851247072cff5d9c5c829e 2024-03-01
FileHash-MD5 86b57b0ec360f45331fc5e4eb5c99611 2024-03-01
FileHash-MD5 9cee927ab9dbfcee1105f6164d4c517e 2024-03-01
FileHash-MD5 a23ed54ce55c04307a5c6df0325bd9a7 2024-03-01
FileHash-MD5 a28f1762aff9d3538efd3c2e58244e76 2024-03-01
FileHash-MD5 adb2e4e332efacee1c3a0a34f283331b 2024-03-01
FileHash-MD5 c42aafc41fa033643c7eb1c06d433ee1 2024-03-01
FileHash-MD5 ce4204e5f9bd17c030a14d4be543240c 2024-03-01
FileHash-MD5 e19dda58beebac867b334fe6bb3f9853 2024-03-01
FileHash-MD5 e2cbde3b921dc3f9d5786b0c9da5c578 2024-03-01
FileHash-MD5 e5e6de1b80ddc27f7bf0f3c643668359 2024-03-01
FileHash-MD5 ec19a61b8e8311dc5de96481a74f2afd 2024-03-01
FileHash-MD5 ee77f32d0932037760742b70dc2ec725 2024-03-01
FileHash-MD5 f70358c0f33c793ff763f36ab0f94d89 2024-03-01