R3MRUM Profile picture
Professional lurker focused on reverse engineering. Built and led CIRT teams in a past life. I enjoy solving puzzles and punching miscreants.
Jul 5, 2021 12 tweets 2 min read
I've seen a few researchers publish the configured REvil C2 domain list for IOCs and just wanted to add some additional context that you may find useful... 1) The C2 domains configured may appear random across samples but if you sort the list and compare across history you will find that the domains are fairly static and that GOLD SOUTHFIELD has only produced 5 unique sets.