<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with gamaredon]]></title><description><![CDATA[A list of topics that have been tagged with gamaredon]]></description><link>https://board.circlewithadot.net/tags/gamaredon</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 23:09:10 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/tags/gamaredon.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[Wave-2 Pterodo beacon URL pattern (n=14 samples since 2026-02):]]></title><description><![CDATA[Wave-2 Pterodo beacon URL pattern (n=14 samples since 2026-02):  /(Svvr|SSsr|Akad|Akk|Gpps|Mouuds)(Htm|Ua|U)?-DD-MM → 212.193.20.1105 of 6 verbs carry double-letter alliteration (vv/Ss/kk/pp/uu) — same operator habit as the 2022-23 `j-j-j` URL generator + the alliterative *orious.ru / *mucoris.ru apex naming Talos/Symantec documented years ago. Three years later, same fingerprint.Bare-IP + plain HTTP + no TLS = SNI inspection won't catch it. Block 212.193.20.110 directly.Suricata draft rules: github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-wave2-beacon.rules#Pterodo #UAC0010 #Gamaredon #ThreatIntel]]></description><link>https://board.circlewithadot.net/topic/7727b7ee-2185-4f39-a214-7f73be8be2b4/wave-2-pterodo-beacon-url-pattern-n-14-samples-since-2026-02</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/7727b7ee-2185-4f39-a214-7f73be8be2b4/wave-2-pterodo-beacon-url-pattern-n-14-samples-since-2026-02</guid><dc:creator><![CDATA[palianytsia_200@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>