Skip to content

Commit

Permalink
Updated 2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt
Browse files Browse the repository at this point in the history
  • Loading branch information
brad-duncan authored Jan 23, 2025
1 parent 001293e commit e627df9
Showing 1 changed file with 5 additions and 5 deletions.
10 changes: 5 additions & 5 deletions 2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt
Original file line number Diff line number Diff line change
Expand Up @@ -6,19 +6,19 @@ AUTHORS:

NOTES:

- Our telemetry revealed a recent malicious ad on Bing Search that led to a fake Microsoft Teams page.
- Our telemetry revealed a recent malicious Bing Search ad leading to a fake Microsoft Teams page.
- We were able to replicate the activity on Wednesday, 2025-01-22.
- We also found additional ads leading to sites impersonating other software programs.
- These ads are short-lived, and this example involves a root domain of burleson-appliance[.]net registered on 2025-01-20.
- These ads are short-lived, and recent examples involve a root domain of burleson-appliance[.]net registered on 2025-01-20.
- Examples of the sub-domains used by these ads are available at: https://urlscan.io/search/#burleson-appliance.net
- Files from this activity are often not malicious on their own, but rely on the other files for a succesful infection.
- IP addresses and domains frequently for this campaign frequently change, and this post is a snapshot from 2025-01-22 starting at 21:37 UTC.
- Files from this activity are often not malicious individually but rely on the other files for a successful infection.
- IP addresses and domains for this campaign frequently change, and this post is a snapshot from 2025-01-22 starting at 21:37 UTC.

DATE AND START TIME OF THIS TEST RUN:

- 2025-01-22 21:37 UTC

FROM MALICIOUS AD TO FAKE TEAMS SITE AND FILE DOWNLOAD:
FROM MALICIOUS AD FOR FAKE TEAMS WEBSITE AND ASSOCIATED FILE DOWNLOAD:

- hxxps[:]//www.bing[.]com/aclk?ld=e8PH8aLxSiJxjw4Si9lgLztzVUCUwCJ7LeV4z4DsU61Sx3HWK9X1fxNGVCWc4jKyspIeWPFeqVejCDavG1lRWD4Ukf127WLw1hUPnGntv_1Y1z30t5JNXJyKZ986BV2aP3kDwSnS0DDaXYX4hQcab6syHfzjtxZLUNJD5oG8MEhJwV-_N_vpfcrfaGeRQCbjbYwL3zeQ&u=aHR0cHMlM2ElMmYlMmZtaWNyb3NvZnQtdGVhbXMtZG93bmxvYWQuYnVybGVzb24tYXBwbGlhbmNlLm5ldCUzZm1zY2xraWQlM2Q5ZTYxNDgwMjZjMzIxNTJlM2ZkYzJmOTMwZDQ5MjNiYw&rlid=9e6148026c32152e3fdc2f930d4923bc&ntb=1

Expand Down

0 comments on commit e627df9

Please sign in to comment.