Benign go Download

github.com/hackingmess/hive-indicadores-de-compromiso-iocs v0.0.0-20220602155146-d668091c7a65

Agent skill offensive tool referenceMarkdown references a remote image

Evidence

HTTP URL targets an image file lines 1–6
1![GitHub Light](https://i.ytimg.com/vi/QO96zU4cZSc/maxresdefault.jpg)
2
3
4# HIVE-INDICADORES-DE-COMPROMISO-IOCs
5
6Indicadores de compromiso del grupo cibercriminal HIVE, relacionado al reciente ataqu
English function-word token "and" lines 21–23
21:875/exchange-team-blog/proxyshell-vulnerabilities-and-your-exchange-server/ba-p/2684705)
22
23[Cobalt Strike](https://www.cobaltstrike.com/) La herramien
References a public code-forge URL lines 23–27
23:292n acceso remoto persistente a los dispositivos comprometidos.
24
25[Mimikatz](https://github.com/ParrotSec/mimikatz) es una aplicación de código abierto que permite a los usuarios ver y guardar credenciales de autenticación, como tickets de Kerberos
26
27# Vulnerabilidades mas comunes explotadas
Path has long Base64-like segment lines 194–196
194:21.]143[.]85
195- hXXp://159[.]223[.]143[.]85/fdkjghdfjkgvutereryecfc/kdfjhgskdjgheterererwfkcbswcfe/dsfkjdgsttrrererwbdk776653ncfkbvge[.]php
196- hXXp://www[.]epoolsoft[.]com/PCHunter_StandardV1.55=658897218D38F45E324FC79A562BC8CB2
Privacy provider email domain suffix lines 233–239
233:94no_de_Costa_Rica)
234
235
236# Preguntas o colaboraciones
237
238- [hackingmess@protonmail.com](mailto:[email protected]?subject=HIVE-INDICADORES-DE-COMPROMISO-IOCs)
239- [randy@atticyber.com](mailto:randy@atticyber.

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.