So just to be explicit about our research @ThreatConnect, we initially came across the cubenergy-my-sharepoint[.]com by exploiting some consistencies that we've seen in previous Fancy Bear infrastructure.
Remember to change ur folder names before you compile. Assuming a binary is compiled with debug info enabled, one could look for bins that are "probs based" on downloaded Github repos based on -master\ in the PDB path.
Quick #dailyyara rule for this
https://t.co/9O75Bjmluf