Read-only mirror of https://github.com/govcert-ch/CTI — GovCERT.ch. Issues & pull requests at the source.
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-08-10 11:44:51 +02:00
20240627_macOS_PoseidonStealer Add files via upload 2024-07-11 19:24:03 +02:00
20241010_GorillaBot Rename GorillaBot-C2-IPs.txt to GorillaBot-C2-proxy-IPs.txt 2024-10-10 11:30:01 +02:00
20241202_LummaStealer Add files via upload 2024-12-02 08:56:14 +01:00
images Delete images/test.txt 2024-06-15 18:05:47 +02:00
OffensiveCIDRs Update Bruteforce.csv 2025-01-29 16:18:12 +01:00
20240117_NoName057-DDoS-CH.csv Update 20240117_NoName057-DDoS-CH.csv 2024-01-17 15:06:10 +01:00
20240615_NoName057-attacking-ips.csv Add files via upload 2024-06-15 17:56:58 +02:00
20240615_NoName057-controller-ips.csv Add files via upload 2024-06-15 17:56:58 +02:00
20250120_NoName057-DDoS-CH_CIDR-only.csv Update 20250120_NoName057-DDoS-CH_CIDR-only.csv 2025-01-24 15:30:58 +01:00
20250120_NoName057-DDoS-CH_CIDR-with-info.csv Update 20250120_NoName057-DDoS-CH_CIDR-with-info.csv 2025-01-24 15:43:51 +01:00
20260810_ClickFix-RPC-Providers.txt Create 20260810_ClickFix-RPC-Providers.txt 2026-08-10 11:42:13 +02:00
NoName057-DDoS-CH-CIDRs-only-merged.txt Fresh CIDRs used by NoName057 for ongoing DDoS attacks 2026-06-17 11:34:58 +02:00
README.md Update README.md 2026-08-10 11:44:51 +02:00

GovCERT.ch Cyber Threat Intelligence

In this directory we post technical cyber threat Intelligence and provide it as is under TLP:CLEAR.

📗 Table of Contents

  • 20260810_ClickFix-RPC-Providers.txt: List of legitimate RPC Providers commonly used by ClickFix.
  • NoName057-DDoS-CH-CIDRs-only-merged.txt: This is a merged CSV of 20250120_NoName057-DDoS-CH_CIDR-only.csv and IPv4 CIDRs recently used by NoName057(16) in L7 DDoS attacks. If you want to stay updated with IPv4 CIDRs used by NoName057, use this CSV file. We will keep updating it whenever possible.
  • OffensiveCIDRs/Bruteforce.csv: Contains top CIDRs (/24) involved in bruteforce attacks against O365 and edge devices (such as SSL-VPNs). You may not expect any legitimate traffic from these sources towards any internal ressources.
  • OffensiveCIDRs/Bruteforce_CIDR-only: This list contains the same data as OffensiveCIDRs/Bruteforce.csv but just the CIDRs (no additional information such as ASN on geo location). You may want to use this list in an automated manner for mitigating bruteforce attacks against O365 and edge devices (such as SSL-VPns).
  • 20250120_NoName057-DDoS-CH_CIDR-with-info.csv: Contains top CIDRs (/24) that participated in DDoS attacks in the week of 2025-01-20 (week #4) against Swiss targets. These attacks were allegedly conducted by hacktivist group NoName057(16), using L7 attacks (HTTP/s GET flood). GovCERT.ch has contacted the abuse desks of the relevant network owners (AS) and asked them to take the appropriate actions to prevent further abuse of their service.
  • 20250120_NoName057-DDoS-CH_CIDR-only.csv: This list contains the same data as 20250120_NoName057-DDoS-CH_CIDR-with-info.csv but just the CIDRs (no additional information such as ASN on geo location). You may want to use this list in an automated manner for temporarily blocking and mitigating NoName057(16) L7 DDoS attacks. Please consider that blocking CIDRs will probably cause false positives. We therefore recommend you to only block those if you are under attack and as a temporary measure.
  • 20241010_GorillaBot: Contains a report and IoCs from the analysis of the GorillaBot DDoS-as-a-Service Malware and Infrastructure.
  • 20240627_macOS_PoseidonStealer: Contains information about a Poseidon Stealer malspam campaign targeting Swiss macOS users and the related MISP Event.
  • 20240615_NoName057-attacking-ips.csv: Contains IPv4 addresses that allegedly participated in DDoS attacks on 2024-06-14 and 2024-06-15 against Swiss targets. These attacks were conducted by hacktivist group NoName057(16), using L7 attacks (HTTP/s GET flood). The majority of the IP addresses belong to VPN service providers that got misused by NoName057(16) for launching DDoS attacks.
  • 20240615_NoName057-controller-ips.csv: Contains IPv4 addresses that allegedly were used in June 2024 by NoName057(16) to command and control their DDoS tool called "DDoSia".
  • 20240117_NoName057-DDoS-CH.csv: Contains IPv4 addresses that participated in DDoS attacks on 2024-01-17 against Swiss targets. These attacks were allegedly conducted by hacktivist group NoName057(16), using L7 attacks (HTTP/s GET flood). GovCERT.ch has contacted the abuse desks of the relevant network owners (AS) and asked them to take the appropriate actions to prevent further abuse of their service.

Disclaimer:

  • Data published here is provided "as it is" without any warranty or liability
  • AS number, AS name and country code for published IP addresses has been provided by Team Cymru's IP to ASN Mapping Service