chartingshow / crypto-firewall

🎁 Blocks browser-based crypto mining, cryptojacking, banking and crypto malware and phishing websites, apps and hackers command-and-control (C2) servers.
GNU General Public License v3.0
7 stars 0 forks source link

Block new `Agent Racoon` malware campaign #394

Closed summercms closed 7 months ago

summercms commented 7 months ago

Enhancement idea

Description

We assess with medium confidence that this threat activity cluster aligns to nation-state related threat actors due to the nature of the organizations that were compromised, the TTPs observed and the customization of the tool set. We have not confirmed a particular nation-state or threat group.

Links

https://unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa/

IOC

I2P websites

n/a

IPFS websites

n/a

Tor2web websites

n/a

TOR websites

n/a

URL's

n/a

Folders

n/a

Sub-Domains

n/a

Domains

geostatcdn.com
geoinfocdn.com

IP's

n/a

Emails

n/a

Wallet addresses

n/a

Mining pool addresses

n/a