mirror of https://github.com/MISP/misp-galaxy
adding ClearSky alias for Volatile Cedar
adding ClearSky report as source and alias to the VolatileCedar entry. As proof from the report: "We attributed the operation to Lebanese Cedar (also known as Volatile Cedar), mainly based on the code overlaps between the 2015 variants of Explosive RAT and Caterpillar WebShell, to the 2020 variants of these malicious files."pull/622/head
parent
815e5c4fe4
commit
d61e7d2fac
|
@ -3918,12 +3918,14 @@
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://blog.checkpoint.com/2015/03/31/volatilecedar/",
|
"https://blog.checkpoint.com/2015/03/31/volatilecedar/",
|
||||||
"https://blog.checkpoint.com/2015/06/09/new-data-volatile-cedar/",
|
"https://blog.checkpoint.com/2015/06/09/new-data-volatile-cedar/",
|
||||||
"https://securelist.com/sinkholing-volatile-cedar-dga-infrastructure/69421/"
|
"https://securelist.com/sinkholing-volatile-cedar-dga-infrastructure/69421/",
|
||||||
|
"https://www.clearskysec.com/wp-content/uploads/2021/01/Lebanese-Cedar-APT.pdf"
|
||||||
],
|
],
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"Reuse team",
|
"Reuse team",
|
||||||
"Malware reusers",
|
"Malware reusers",
|
||||||
"Dancing Salome"
|
"Dancing Salome",
|
||||||
|
"Lebanese Cedar"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "cf421ce6-ddfe-419a-bc65-6a9fc953232a",
|
"uuid": "cf421ce6-ddfe-419a-bc65-6a9fc953232a",
|
||||||
|
|
Loading…
Reference in New Issue