├── IOCs ├── Readme.md ├── misp.event.2443.5a79b8fc-4460-4a3a-a6e6-2232c0a8a8de.xml ├── Gootkit_2018-03-21_misp.event.2619.5ab28984-869c-434a-9a54-0d0fc0a8a8de.json ├── misp.event.2834.5b22c1bd-1ab8-4506-b4a6-1746c0a8a8de.json └── misp.event.2879.5b3544f7-1e20-4f39-8713-055ec0a8a8de.json ├── README.md ├── Sundown-N ├── ScriptJS.md ├── Fallout_EK_Pattern.md ├── Astrum_drop_2016-12-07.md ├── RIG_Pattern.md └── Nebula_URI /IOCs/Readme.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | Public share of DriveBy related Data 2 | -------------------------------------------------------------------------------- /Sundown-N: -------------------------------------------------------------------------------- 1 | actressheight.knowledgedrugsaturday.club 2 | advantagelamp.numberdeficitc-clamp.site 3 | advertiselaura.bubblecomparisonwar.top 4 | afforddrill.xzv4rzuctndfo.club 5 | agendawedge.shoemakerzippersuccess.stream 6 | agesword.alvdxq1l6n0o.stream 7 | api.beps.io 8 | apologycattle.gramsunshinesupply.club 9 | apologycold.shearssuccessberry.club 10 | applywholesaler.tboapfmsyu.stream 11 | approvepeak.knowledgedrugsaturday.club 12 | approveriver.jsffu2zkt5va.trade 13 | authorisationmessage.casdfble.stream 14 | authorizationmale.foundationspadeinventory.club 15 | authorparticle.390a20778a68d056c40908025df2fc4e.site 16 | bakermagician.alvdxq1l6n0o.stream 17 | birthdayexperience.foundationspadeinventory.club 18 | bombclick.alvdxq1l6n0o.stream 19 | borrowfield.77e1084e.pro 20 | boydescription.356020817786fb76e9361441800132c9.win 21 | budgetdegree.maskobjectivebiplane.trade 22 | buglecommand.textfatherfont.info 23 | burglarsatin.jsffu2zkt5va.trade 24 | buysummer.77e1084e.pro 25 | captaincertification.77e1084e.pro 26 | certificationplanet.87692f31beea22522f1488df044e1dad.top 27 | chargerule.textfatherfont.info 28 | chooseravioli.87692f31beea22522f1488df044e1dad.top 29 | cityacoustic.textfatherfont.info 30 | clausmessage.nationweekretailer.club 31 | clickbarber.356020817786fb76e9361441800132c9.win 32 | coachadvantage.reportattackconifer.site 33 | competitionseason.numberdeficitc-clamp.site 34 | confirmationaustralian.retaileraugustplier.club 35 | cowchange.distributionstatementdiploma.site 36 | customergazelle.cyclonesoybeanpossibility.bid 37 | dancerretailer.shearssuccessberry.club 38 | databasesilver.reportattackconifer.site 39 | date-of-birthtrout.87692f31beea22522f1488df044e1dad.top 40 | decembercommission.divingfuelsalary.trade 41 | deficitshoulder.lossicedeficit.pw 42 | departmentant.distributionstatementdiploma.site 43 | dependentswhorl.jsffu2zkt5va.trade 44 | derpenquiry.87692f31beea22522f1488df044e1dad.top 45 | disadvantageproduction.brassreductionquill.site 46 | disadvantageproduction.casdfble.stream 47 | distributionfile.edgetaxprice.site 48 | distributionjaw.hockeyopiniondust.club 49 | domainconsider.mxkznekruoays.trade 50 | employergoods.deliverycutadvantage.info 51 | equipmentparticle.shockadvantagewilderness.club 52 | equipmentwitness.maskobjectivebiplane.trade 53 | europin.pedestrianpathexplanation.info 54 | explanationlier.asiadeliveryarmenian.pro 55 | fallhippopotamus.deliverycutadvantage.info 56 | goallicense.shearssuccessberry.club 57 | goalpanda.retaileraugustplier.club 58 | goodswinter.retailersproutalto.pro 59 | holidayagenda.retaileraugustplier.club 60 | hygienicreduction.brassreductionquill.site 61 | hygienicreduction.casdfble.stream 62 | instructionscomposition.pheasantmillisecondenvironment.stream 63 | instructionssaudiarabia.retailersproutalto.pro 64 | invoiceburst.cyclonesoybeanpossibility.bid 65 | invoicegosling.edgetaxprice.site 66 | jailreduction.edgetaxprice.site 67 | jobhate.pedestrianpathexplanation.info 68 | limitsphere.pheasantmillisecondenvironment.stream 69 | lipprice.edgetaxprice.site 70 | marginswiss.divingfuelsalary.trade 71 | marketsunday.deliverycutadvantage.info 72 | outputfruit.divingfuelsalary.trade 73 | paymentceramic.pheasantmillisecondenvironment.stream 74 | penaltydrug.exhaustamusementsuggestion.pw 75 | penaltyinternet.asiadeliveryarmenian.pro 76 | phonefall.asiadeliveryarmenian.pro 77 | printeroutput.pheasantmillisecondenvironment.stream 78 | purposeguarantee.shearssuccessberry.club 79 | rainstormpromotion.gramsunshinesupply.club 80 | redrepairs.distributionstatementdiploma.site 81 | reindeerprofit.divingfuelsalary.trade 82 | reminderdonna.divingfuelsalary.trade 83 | rollinterest.asiadeliveryarmenian.pro 84 | salaryfang.shockadvantagewilderness.club 85 | soldierprice.distributionstatementdiploma.site 86 | startguarantee.gramsunshinesupply.club 87 | stationdeadline.improvementdeadlinemillisecond.club 88 | suggestionburn.distributionstatementdiploma.site 89 | supplyheaven.gramsunshinesupply.club 90 | swissfacilities.gumimprovementitalian.stream 91 | transportbomb.gramsunshinesupply.club 92 | transportdrill.facilitiesturkishdipstick.info 93 | -------------------------------------------------------------------------------- /ScriptJS.md: -------------------------------------------------------------------------------- 1 | #ScriptJS/AfraidGate 2 | 3 | ## __Publications:__ 4 | | Title | Date Here | Source |Comment| 5 | |---|---|---|---| 6 | |[Dridex Actors Get In the Ransomware Game With "Locky"](https://www.proofpoint.com/us/threat-insight/post/Dridex-Actors-Get-In-the-Ransomware-Game-With-Locky)| 2016-02-16 |Proofpoint|| 7 | |[Locky Ransomware Installed Through Nuclear EK](http://researchcenter.paloaltonetworks.com/2016/03/locky-ransomware-installed-through-nuclear-ek/)| 2016-03-21 |PaloAlto|| 8 | |[Threat Spotlight: Exploit Kit Goes International Hits 150+ Countries](http://blog.talosintel.com/2016/04/nuclear-exposed.html)| 2016-04-20 |Talos|| 9 | |[Highly Popular Anime Site Jkanime Compromised](https://blogs.forcepoint.com/security-labs/highly-popular-anime-site-jkanime-compromised-redirecting-users-neutrino-ek)| 2016-06-21 |Forcepoint|| 10 | |[Neutrino EK’s Afraidgate pushed in malvertising attack](https://blog.malwarebytes.com/cybercrime/exploits/2016/09/neutrino-eks-afraidgate-pushed-in-malvertising-attack/)| 2016-09-13 |Malwarebytes|*Payload is Godzilla here. Locky is in fact a 2ndStage*| 11 | |[Fox stealer: another Pony Fork](http://malware.dontneedcoffee.com/2016/09/fox-stealer-another-pony-fork.html)| 2016-09-26 |MalwareDontNeedCoffee|| 12 | ---- 13 | 14 | | Date |Domain| IP | 15 | | :------- | :---- | :---| 16 | |170206|tandem.florenciaespineira.cl|192.241.246.34| 17 | |170204|torneonis.cattcval.com.ve|138.197.222.151| 18 | |170203|longtrim.datatestserver.com|159.203.30.60| 19 | |170201|kithole.seanconnor.com|159.203.30.60| 20 | |170122|cuprum.poemar.es|146.185.151.179| 21 | |170122|bombarda.mkoussa.com|146.185.151.179| 22 | |170121|pistole.1stclassmunitions.com|146.185.151.179| 23 | |170118|team.motivaplan.com.br|45.55.10.142| 24 | |170110|malina.cfdiweb.mx|178.62.242.179| 25 | |161214|alfio.brasilperfectcity.com|188.166.17.115| 26 | |161209|stylesheet.bittitle.com|138.68.144.43| 27 | |161203|aquarius.away.es|138.68.144.43| 28 | |161127|mikkie.thejwfnet.co.uk|188.166.4.51| 29 | |161124|max.nasasi.com.ar|159.203.18.229| 30 | |161120|parameter.miafp.cl|159.203.18.229| 31 | |161023|club.panduan-ngeblog.com|138.68.135.94| 32 | |161015|round.luc-hariman.com|159.203.2.200| 33 | |161015|alexa.lorea.io|159.203.2.200| 34 | |161011|monte.aguero.com.au|82.196.10.194| 35 | |161003|sp.gridjunky.com|95.85.46.182| 36 | |160930|spower.gogohen.com|95.85.46.182| 37 | |160928|aug.nightrelay.co.za|139.59.171.176| 38 | |160927|monro.nillaraujo.com|139.59.171.176| 39 | |160926|lesley.portcoquitlamweather.ca|188.166.66.191| 40 | |160923|mouse.redvos.com|188.166.66.191| 41 | |160922|rouse.haslhome.com|46.101.93.53| 42 | |160920|test.linonsa.com|146.185.158.150| 43 | |160919|van.readytogo.club|178.62.23.109| 44 | |160918|van.readytogo.club|178.62.23.109| 45 | |160918|knight.manex.us|178.62.23.109| 46 | |160915|vk.manex.us|178.62.23.109| 47 | |160908|note.followthebrowns.com|159.203.3.186| 48 | |160906|ono.bienestando.cl|159.203.3.186| 49 | |160901|murphy.tahubaxoku.com|146.185.172.147| 50 | |160828|ops.latokaski.fi|138.68.18.73| 51 | |160828|nonna.culturizartechillan.cl|138.68.18.73| 52 | |160818|font.enriquemonsalve.cl|178.62.77.103| 53 | |160814|way.minadepreco.com.br|188.166.54.203| 54 | |160814|make.kankerblogger.com|188.166.54.203| 55 | |160811|global.platinoviajes.com.ve|188.166.54.203| 56 | |160801|one.hiiragihoo.com|139.59.160.138| 57 | |160730|temp.blog-sandltnst.co|139.59.160.138| 58 | |160726|leon.stmaryschooldmt.com|46.101.26.161| 59 | |160722|long.revistashine.com.ar|46.101.26.161| 60 | |160713|stown.katieprallphotography.com|188.166.38.125| 61 | |160629|dance.jmestudiocontable.com.ar|139.59.191.79| 62 | |160626|onno.motorgear.com.au|188.166.38.125| 63 | |160626|dron.transportemorelli.com.ar|146.185.173.25| 64 | 65 | ---- 66 | Script example : 67 | 68 | ```javascript 69 | document.write('
strong