Files
ShadowShells/iocs.csv
Joseph Goydish II af82be6e26 Add files via upload
2025-12-10 18:20:47 -05:00

1.4 KiB

1typevaluefirst_seenconfidencenotes
2domaingithub.stormbreaker.pro2025-12-07HighRepeatedly observed as C2 candidate in analyzed telemetry
3domainstormbreaker.pro2025-12-07HighVariant of primary C2
4domainkaylees.site2025-12-09HighSecondary C2 / proxy domain observed
5domainpir.kaylees.site2025-12-09HighRelay/variant observed
6domainspple.cf2025-12-09MediumTyposquat / possible phishing domain
7domainapple.cf2025-12-09MediumTyposquat / impersonation risk
8domainpstack.cf2025-12-09HighDNS queries observed in telemetry
9domaine.zip2025-12-09HighDownload host / payload reference observed
10domaincom.apple.pro2025-12-09MediumImpersonation-like domain
11domaincom.apple.online2025-12-09MediumImpersonation-like domain
12domainmodes.ga2025-12-09MediumObserved in related telemetry
13domainquikit.ru2025-12-09MediumPossible typosquat
14domaincs.cf2025-12-09MediumSuspicious free-TLD domain
15domainauthoriz.gq2025-12-09MediumSuspect domain
16uuidA124B30D-1DA8-4A28-9086-C7F485678DCB2025-12-09HighSystem-proxy/tunnel UUID observed in telemetry (high-value pivot)
17processsshd2025-12-09HighSSH daemon referenced in multiple artifacts — investigate SSH-related logs
18process/bin/bash2025-12-09HighShell invocation / command execution patterns observed
19stringpayload 105676170917754192072025-12-09HighUnique payload identifier observed in artifacts