Public entries tagged #ioc

RE: mastodon.social/@campuscodi/11

Security firm Bitdefender has an in-depth report on the latest TTPs and ‘s used by an APT group, shared by Catalin below. You may not be targeted by this group, but they use the very common technique of Living off Trusted Services. One highlighted in this report is Discord. I strongly agree with Bitdefender’s advice of controlling or blocking access to Discord. Another service mentioned is the file-sharing service tmpfiles.org — limit or block access to that too.

Continue reading →

Wow, now I'm getting malware URLs via reverb.com - way to hand over a long-time threat intel person the IoC's

nothing on VT yet virustotal.com/gui/url/3086617
Zero detections:
urlvoid.com/scan/matyshkazemly
scan failed 403 forbidden: sitecheck.sucuri.net/results/w

urlquery.net/report/7840c1b4-7 redirect and is sinkholed via DNS4EU
Submitted to Pulsedive: pulsedive.com/indicator/?ioc=d

Showing a redirect to Google on checkphish (LOL)
app.checkphish.ai/public/insig

IoC:
www.matyshkazemlya [DOT] com

Message on Reverb.com:
Hey, I've been trying to buy your listing but keep getting a payment error. The site gave me a link with some info for the seller to check — www.matyshkazemlya [DOT] com Could you take a look? Mia Brown


Continue reading →

Subscribe to #ioc entries via RSS feed