PULSE NAME
Rattling the cage of a Sidewinder
WHITE Sidewinder AlienVault 2024-04-05 Modified: 2024-04-08
193
IOCs
HIGH VOLUME
This detailed analysis delves into the techniques employed by the cybersecurity researchers to track and detect infrastructure associated with the Sidewinder threat group. It outlines a comprehensive framework involving multiple search queries across various data sources, aimed at identifying indicators and artifacts related to the adversary's operations. The approach encompasses scanning for specific strings, encoded payloads, network fingerprints, and leveraging intelligence feeds to uncover new domains, IPs, and potential command-and-control infrastructure utilized by the group.
Indicators of Compromise (17 / 193 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 056d1dc3032d04d7638c02056d5146c9 2024-04-05
FileHash-MD5 15e0ac5a80a5849fab40cfac221c4ce4 2024-04-05
FileHash-MD5 251ff44ae978e2140dd02f00b3f093a0 2024-04-05
FileHash-MD5 356f30ba570428a6d0896e3960de8b70 2024-04-05
FileHash-MD5 43d35b5b20f491be219ab2eaa172ec55 2024-04-05
FileHash-MD5 54b1157ce8045f2e83340dc5d756f412 2024-04-05
FileHash-MD5 5efddbdcf40ba01f1571140bad72dccb 2024-04-05
FileHash-MD5 6af17fdbf7974c1a9a08a38b755d363b 2024-04-05
FileHash-MD5 6c7d24b90f3c6b4383bd7d08374a0c6f 2024-04-05
FileHash-MD5 9b1d0537d0734f1ddb53c5567f5d7ab5 2024-04-05
FileHash-MD5 b67bbb2a9fdfc3e89e2ed4c32ef9eb54 2024-04-05
FileHash-MD5 b7e63b7247be18cdfb36c1f3200c1dba 2024-04-05
FileHash-MD5 d37e71880beb8f453553c778aa07718a 2024-04-05
FileHash-MD5 d576cebe9f6cfd1d6e238e3540120dca 2024-04-05
FileHash-MD5 eb029e7b6d75ba082d539a4646efa55d 2024-04-05
FileHash-MD5 ef00004a1ebc262ffe0fb89aa5524d42 2024-04-05
FileHash-MD5 ef8cd5327c3cedb8a5ad8fb6b4706851 2024-04-05