From 074c595586e8e7d5b2ab985cf6937138cabcefe7 Mon Sep 17 00:00:00 2001 From: Gi7w0rm <89871181+Gi7w0rm@users.noreply.github.com> Date: Sun, 10 Sep 2023 02:49:54 +0200 Subject: [PATCH] Update and rename IoC_DDGroup_sinkholing.csv to IoC_DDGroup_sh.csv --- DDGroup/{IoC_DDGroup_sinkholing.csv => IoC_DDGroup_sh.csv} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename DDGroup/{IoC_DDGroup_sinkholing.csv => IoC_DDGroup_sh.csv} (98%) diff --git a/DDGroup/IoC_DDGroup_sinkholing.csv b/DDGroup/IoC_DDGroup_sh.csv similarity index 98% rename from DDGroup/IoC_DDGroup_sinkholing.csv rename to DDGroup/IoC_DDGroup_sh.csv index ff2a035..d354507 100644 --- a/DDGroup/IoC_DDGroup_sinkholing.csv +++ b/DDGroup/IoC_DDGroup_sh.csv @@ -41,4 +41,4 @@ rem1666.hopto.org,RemcosRAT,tcp,2404,(no proof as ModiLoader payload is taken do sunwap1.ddns.net,RemcosRAT,tcp,2404,(no proof as ModiLoader payload is taken down however several indicators) wormxwar.ddns.net,XWorm,tcp,7000,https://tria.ge/230909-z3tl3aea2t/behavioral1 febrem.ddns.net,Remcos,,2404,https://www.vmray.com/analyses/50365c827bd7/report/network.html -febrem1.ddns.net,AveMaria/WarZone,tcp,5200,https://tria.ge/220928-2ss9naadap \ No newline at end of file +febrem1.ddns.net,AveMaria/WarZone,tcp,5200,https://tria.ge/220928-2ss9naadap