pan-unit42 / iocs

Indicators from Unit 42 Public Reports
MIT License
696 stars 150 forks source link

How? Did You Scan That? #2

Closed Pentoman closed 7 years ago

Pentoman commented 7 years ago

Hey there ,

i would like to know , how u scanned the CNC servers? do you have a Tool for it? would be nice .....:-) or are they just from an internal scan ?

Would like to make a scan server searching for those CNC´s

karttoon commented 7 years ago

Hey Pentoman - what folder are you referring to?

Pentoman commented 7 years ago

Does not really matter i mean how do u get these Adresses ? of the Servers ? like ispy or diamondfox would like to also set up a scanner .... ;-)

karttoon commented 7 years ago

They are pulled from the Palo Alto Networks AutoFocus system daily and auto-pushed to GitHub for people to use as indicators.

https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/autofocus