From 814616b379835a7a1976c5e46794d241d12cf46d Mon Sep 17 00:00:00 2001 From: Gi7w0rm <89871181+Gi7w0rm@users.noreply.github.com> Date: Fri, 8 Sep 2023 08:14:13 +0200 Subject: [PATCH] Update Additional_IoC.txt --- DDGroup/Additional_IoC.txt | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/DDGroup/Additional_IoC.txt b/DDGroup/Additional_IoC.txt index 688938e..870bc78 100644 --- a/DDGroup/Additional_IoC.txt +++ b/DDGroup/Additional_IoC.txt @@ -107,6 +107,13 @@ fcfc72e7b57a95e9a438c7e3efd5378c78dc0c471addbeebc3acfc4c1eee376c ## Used to host malware: stickerpix.co.uk https://stickerpix.co.uk/4.exe +https://stickerpix.co.uk/18.exe + +GitHub: +https://github.com/Doowe166/45/raw/main/11.exe +https://github.com/Foa12/aq/raw/main/12.exe +https://github.com/Doowe166/y/raw/main/112.exe + ## As per Microsoft Threat Intel the actor is connected to the following domains: