Echoes of Stargazer Goblin: Analyzing Shared TTPs from an Open Directory
ID: 0bc74fe5-86b1-5ba0-9b38-796d186ce367
STIX ID: report--0bc74fe5-86b1-5ba0-9b38-796d186ce367
Feed Name: Hunt.io Blog
Threat Score
This report describes the discovery and analysis of an open directory (52.156.24.251) that hosted malicious HTML/HTA files, obfuscated VBScript, PowerShell scripts, donut-generated shellcode, and Sliver C2 components used to deliver and execute malware and perform data exfiltration; the authors document network and host IoCs and note similarities to Stargazer Goblin techniques but do not conclusively attribute the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
