← CatalogINDICATORPUBLIC INTELLIGENCE
URL https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html
Indicator published by the cited source.
Reference details
- Source context
turla/misp-turla-powershell-event.json- First reported
- Not reported
- Last reported
- Not reported
- Catalog updated
- 2026-10-08 08:01 UTC
Published indicators
Network addresses are displayed in defanged form.
URLhxxps://www[.]fireeye[.]com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique[.]html
Source observations
- Evidence class
- published ioc
- Source family label
- Not reported
- Source confidence
- Not reported
- Observed
- Not reported
- Retrieved
- 2026-10-08 08:01 UTC
- Evidence class
- published ioc
- Source family label
- Not reported
- Source confidence
- Not reported
- Observed
- Not reported
- Retrieved
- 2026-10-08 06:21 UTC