Update threat-actor.json

OilRig
This commit is contained in:
StefanKelm 2020-07-23 11:07:22 +02:00 committed by GitHub
parent c174f613c5
commit 86c54cbd8c
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -3828,8 +3828,8 @@
"cfr-type-of-incident": "Espionage", "cfr-type-of-incident": "Espionage",
"country": "IR", "country": "IR",
"refs": [ "refs": [
"http://www.clearskysec.com/oilrig/", "https://www.clearskysec.com/oilrig/",
"http://blog.morphisec.com/iranian-fileless-cyberattack-on-israel-word-vulnerability", "https://blog.morphisec.com/iranian-fileless-cyberattack-on-israel-word-vulnerability",
"https://unit42.paloaltonetworks.com/unit42-striking-oil-closer-look-adversary-infrastructure/", "https://unit42.paloaltonetworks.com/unit42-striking-oil-closer-look-adversary-infrastructure/",
"https://unit42.paloaltonetworks.com/unit42-introducing-the-adversary-playbook-first-up-oilrig/", "https://unit42.paloaltonetworks.com/unit42-introducing-the-adversary-playbook-first-up-oilrig/",
"https://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/", "https://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/",
@ -3856,6 +3856,7 @@
"https://www.clearskysec.com/oilrig/", "https://www.clearskysec.com/oilrig/",
"https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/", "https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/",
"https://attack.mitre.org/groups/G0049/", "https://attack.mitre.org/groups/G0049/",
"https://unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/",
"https://www.secureworks.com/research/threat-profiles/cobalt-gypsy" "https://www.secureworks.com/research/threat-profiles/cobalt-gypsy"
], ],
"synonyms": [ "synonyms": [
@ -8311,5 +8312,5 @@
"value": "GALLIUM" "value": "GALLIUM"
} }
], ],
"version": 169 "version": 170
} }