Coder Social home page Coder Social logo

threat-intelligence's Introduction

threat-intelligence

Infoblox's Threat Intelligence Group (TIG) detects, curates, and publishes threat intelligence data pertaining to relevant cyber campaigns. TIG is sharing indicators of compromise (IOCs) related to threats that are of high interest to the cyber security community through this public repository. The following contains descriptions about the contents of each dataset (i.e data folder). All files are csv formatted and MISP compatible.

This material is being provided by Infoblox under the Creative Commons CC BY 4.0 license. This license allows you to share and adapt the material, in particular to use it for both commercial and non-commercial security purposes, under the terms of: attribution to Infoblox and the license. For more details, see the LICENSE file in our repo or visit https://creativecommons.org/licenses/by/4.0/

ukraine

This folder contains IOCs related to the Russian invasion of Ukraine. The majority of the content is based on Infoblox internal analytics and validation analysis, though some OSINT is also included. Our references should clearly indicate indicators that originated in OSINT.

The file ukraine_russia_malicous_suspicious_iocs.csv contains malicious and suspicious IOCs that can cause harm to businesses and innocent users. Infoblox recommends blocking traffic from network indicators described in this file.

The ukraine_russia_legitimate_iocs.csv file contains confirmed indicators that, at the time of review, were not evidently associated with malicious activity. The related websites did not show indications of hosted malware or fraudulent behavior, but may host content that is not wanted by some users. This includes domains belonging to well-known donation sites providing support to Ukrainian civilians, or newly created support programs operated by entities positively acknowledged by the online community. Many of these are blocked by other vendors due to their new registration or other automated analytics.

ccb_indicators

This folder contains IOCs related to our Cyber Campaign Briefs (ccb)

cta_indicators

This folder contains IOCs related to our Cyber Threat Advisories (cta)

Schema Table
Field Description
type The data type of the IOC. Possible options: domain, ip, url, sha256, and email.
indicator Also known as an IOC, this analysis artifact is a piece of forensic data related to online activities regarding the Russia-Ukraine conflict.
classification Descriptive labels that explain the nature of the IOC.
references A web resource link that provides information related to the indicator and may have been a decision factor for the classification label.

Publications

The indicators in this repo include those relevant to our publications on the threat environment.

"Ukraine War" Malspam Delivers Remcos RAT

Ukraine Themed Malspam Delivers Agent Tesla

Ukraine Support Fraud

Additional Information

Infoblox customers can find additional detailed inforamtion about the decision criteria for a given indicator in the notes field within the Threat Intelligence Data Exchange (TIDE) database.

threat-intelligence's People

Contributors

chris-kim-agent1 avatar nsundvall avatar ashende-ib avatar mletouz avatar reneeburton avatar gpellegrino-infoblox avatar lsethi25 avatar cwright-ib avatar schatzistogias avatar cmitchelltudor avatar nullripper avatar tomcsu avatar japortal avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.