Files
spl/yara/Bifrost-yara-20250112.yar

13 lines
322 B
Plaintext

Bifrost_IOCs {
meta:
creator = "Cpl Iverson"
date = "2025-01-12"
description = "Suspicious IPs, Hashes, and Domains"
apt_group = "BlackTech"
strings:
$ip_107_191_61_247 = "107.191.61.247"
$md5_8fd3925dadf37bebcc8844214f2bcd18 = "8fd3925dadf37bebcc8844214f2bcd18"
condition:
any of them
}