Skip to content

Instantly share code, notes, and snippets.

@jmconway
Created February 24, 2022 20:36
Show Gist options
  • Save jmconway/f656c2e083eb2257fdc7d2a07cf0eeea to your computer and use it in GitHub Desktop.
Save jmconway/f656c2e083eb2257fdc7d2a07cf0eeea to your computer and use it in GitHub Desktop.
Custom IOCs for CrowdStrike of Wiper Malware detailed by Symantec: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia
[{"id":"200074e5620e35537d603e650752542ab291caa0dd7fe454505153b8108c1fb6","cid":"dc674dd858a84b689924ad92032d57be","type":"sha256","value":"4dc13bb83a16d4ff9865a51b3e4d24112327c526c1392e14d56f20d6f4eaf382","action":"prevent","mobile_action":"no_action","severity":"critical","severity_number":"90","description":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia","metadata":{"filename":"Trojan.Killdisk","signed":false,"av_hits":5},"platforms":["windows"],"expired":false,"applied_globally":true,"deleted":false,"created_on":"2022-02-24T20:25:32.052764249Z","modified_on":"2022-02-24T20:27:31.151955481Z"},{"id":"8a86f9ab6cdf26120b3040f75c2a31ee5ac3680b79ae8e1147daab198bca473c","cid":"dc674dd858a84b689924ad92032d57be","type":"sha256","value":"a64c3e0522fad787b95bfb6a30c3aed1b5786e69e88e023c062ec7e5cebf4d3e","action":"prevent","mobile_action":"no_action","severity":"critical","severity_number":"90","description":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia","metadata":{"filename":"Trojan.Killdisk","signed":false,"av_hits":-1},"platforms":["windows"],"expired":false,"applied_globally":true,"deleted":false,"created_on":"2022-02-24T20:25:32.052764249Z","modified_on":"2022-02-24T20:27:31.151955481Z"},{"id":"ccdbc89f1cfbdb53586c6ff9c7704e381368d20c8eb990a95d334ab113a6210d","cid":"dc674dd858a84b689924ad92032d57be","type":"sha256","value":"1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591","action":"prevent","mobile_action":"no_action","severity":"critical","severity_number":"90","description":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia","metadata":{"filename":"Trojan.Killdisk","signed":false,"av_hits":8},"platforms":["windows"],"expired":false,"applied_globally":true,"deleted":false,"created_on":"2022-02-24T20:25:32.052764249Z","modified_on":"2022-02-24T20:27:31.151955481Z"},{"id":"ec758b830c81e3a89a5590063282529e5465fd5fd5532ed247ea902fef4a9a56","cid":"dc674dd858a84b689924ad92032d57be","type":"sha256","value":"0385eeab00e946a302b24a91dea4187c1210597b8e17cd9e2230450f5ece21da","action":"prevent","mobile_action":"no_action","severity":"critical","severity_number":"90","description":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia","metadata":{"filename":"Trojan.Killdisk","signed":false,"av_hits":21},"platforms":["windows"],"expired":false,"applied_globally":true,"deleted":false,"created_on":"2022-02-24T20:25:32.052764249Z","modified_on":"2022-02-24T20:27:31.151955481Z"}]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment