Skip to content

Resources for DFIR Professionals Responding to the Whispergate

Notifications You must be signed in to change notification settings

cado-security/DFIR_Resources_Whispergate

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 

Repository files navigation

DFIR_Resources_Whispergate

On Saturday January 15th 2022, Microsoft released a blog titled “Destructive malware targeting Ukrainian organizations”. Microsoft’s blog outlines an ongoing attack against organisations in Ukraine by a currently-unknown threat actor and provides a detailed analysis of the malware samples involved.

We have provided additional resources below that may be of use to those responding or investigating the attacks:

  • Yara Rules
  • Copies of malware samples for detections. Do not run these unless you know how to safely analyse malware in a Virtual Machine!
  • Decompiled Source code, via RetDec and ILSpy

About

Resources for DFIR Professionals Responding to the Whispergate

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published