PULSE NAME
Rattling the cage of a Sidewinder
WHITE Sidewinder AlienVault 2024-04-05 Modified: 2024-04-08
193
IOCs
HIGH VOLUME
This detailed analysis delves into the techniques employed by the cybersecurity researchers to track and detect infrastructure associated with the Sidewinder threat group. It outlines a comprehensive framework involving multiple search queries across various data sources, aimed at identifying indicators and artifacts related to the adversary's operations. The approach encompasses scanning for specific strings, encoded payloads, network fingerprints, and leveraging intelligence feeds to uncover new domains, IPs, and potential command-and-control infrastructure utilized by the group.
Indicators of Compromise (16 / 193 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 05ebfd620475269c1228f87048c237a276745f1f 2024-04-05
FileHash-SHA1 1327f20512762a533c22fe181be3fcdd29ab76fe 2024-04-05
FileHash-SHA1 230911dbeaab0631c9df32fdfd8b726977866fd9 2024-04-05
FileHash-SHA1 33657ac7b0b7793c21a5a1ea6a78c72fa48857e1 2024-04-05
FileHash-SHA1 45ecc1c56886dd29cdc7557dd8f5954f999f56a8 2024-04-05
FileHash-SHA1 48b9d48847ad58a55f1a8dfc5872962358dedc6e 2024-04-05
FileHash-SHA1 5120621ec0a2eecb692f8042d1f6789a8bb182d8 2024-04-05
FileHash-SHA1 53a1b84d67b8be077f6d1dd244159262f7d1a0f9 2024-04-05
FileHash-SHA1 59f1d4657244353a156ef8899b817404fd7fedad 2024-04-05
FileHash-SHA1 832b42c85c885f66d32a02114ada50c24926f3a2 2024-04-05
FileHash-SHA1 8e650ecbbcd710f32b859aa34feb340768ea04cb 2024-04-05
FileHash-SHA1 c9a9160e6c03a5debc9f1947a74215d52c7a1af6 2024-04-05
FileHash-SHA1 cc59e275491ab440577079d555fa215895845e8e 2024-04-05
FileHash-SHA1 df0a9f12a51c88171ad1b65a462b83b2ef44c236 2024-04-05
FileHash-SHA1 e127a783870701cdd20a7fc750cad4dae775d362 2024-04-05
FileHash-SHA1 e4a8e4673ebfba0cea2d9755535bc93896b44183 2024-04-05