IoC Extractor

This IoC extractor identifies Indicators of Compromise (IoCs) by matching patterns, without analyzing the context of the surrounding text. Manual Review and Validation of the extracted IoCs are essential before any action is used.

Decoding RomCom: Behaviors and Opportunities for Detection

DATE : 2023-07-26T07:00:00
SOURCE : blackberry.com

CVE:
cve-2023-36884

FILE_HASH_MD5:
9B2231506B2A97692F6B9683460880A0
8507116E3D0E7E02E36E7DC5B8AA1AF8
EF3179D498793BF4234F708D3BE28633
4DB27267734D1576D75C991DC70F68AC
FFDCAE3B31803A83E3818714D343A975
E569E6F445D32BA23766AD67D1E3787F
69072084FCAD54DCDC386F6B8B591BC8
86CC27A0EA4356B958B6D5F4AB5F5A4D
0a22cbe43691487a5a19354b8f3d1555
66e28348b345dc60b01f4077076018b2

FILE_HASH_SHA1:
226F72DCEA4F8C3BFB0BB3DEC4E63C2725170568
DD399AE46303343F9F0DA189AEE11C67BD868222
B52678A98201BE08C5CE65C181A56F1959C8698C
6c847937c5a836e2ce2fe2b915f213c345a3c389
cb22598bb70651f88e0285abc8d835757d2cb596
E267E26DB077A72F6CA8322993A55038B147C408

FILE_HASH_SHA256:
6d3ab9e729bb03ae8ae3fcd824474c5052a165de6cb4c27334969a542c7b261d
B1B015F3762B4B9BFCE928401A3B13BEEE5FB70C989B97A03D57545FC00A1978
B53F3C0CD32D7F20849850768DA6431E5F876B7BFA61DB0AA0700B02873393FA
C94E889A6C9F4C37F34F75BF54E6D1B2CD7EE654CD397DF348D46ABE0B0F6CA3
65778E3AFC448F89680E8DE9791500D21A22E2279759D8D93E2ECE2BC8DAE04D
a61b2eafcf39715031357df6b01e85e0d1ea2e8ee1dfec241b114e18f7a1163f
e7cfeb023c3160a7366f209a16a6f6ea5a0bc9a3ddc16c6cba758114dfe6b539
3a3138c5add59d2172ad33bc6761f2f82ba344f3d03a2269c623f22c1a35df97
1a7bb878c826fe0ca9a0677ed072ee9a57a228a09ee02b3c5bd00f54f354930f

Domain:
redcanary.com
thedfirreport.com
secureworks.com
crowdstrike.com
strontic.github.io
finformservice.com

Url:
https://redcanary.com/blog/raspberry-robin/
https://thedfirreport.com/2022/09/26/bumblebee-round-two/author
https://www.secureworks.com/research/bronze-butler-targets-japanese-businesse
https://www.crowdstrike.com/resources/reports/2019-crowdstrike-global-threat-report/
https://strontic.github.io/xcyclopedia/library/clsid_C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6.html