From 99b23e31a3c6c232d98a04a8404cfee3cd3a99e0 Mon Sep 17 00:00:00 2001 From: Daniel Plohmann Date: Mon, 13 Nov 2023 14:43:08 +0100 Subject: [PATCH] adding Prolific Puma --- clusters/threat-actor.json | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 8ad97eb..7343e5d 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -12966,7 +12966,17 @@ }, "uuid": "b9128c29-8941-48a8-a5be-8076dde03a08", "value": "DarkCasino" + }, + { + "description": "Prolific Puma provides an underground link shortening service to criminals. Infoblox states that during analysis, no legitimate content was observed being served through their shortener. For operation they use a registered domain generation algorithm (RDGA), based upon which they registered between 35k-75k domain names.", + "meta": { + "refs": [ + "https://blogs.infoblox.com/cyber-threat-intelligence/prolific-puma-shadowy-link-shortening-service-enables-cybercrime/" + ] + }, + "uuid": "c8782e46-447c-4c6e-90c0-82f3bf49d64b", + "value": "Prolific Puma" } ], - "version": 293 + "version": 294 }