Skip to content

Commit

Permalink
Update filename-iocs.txt
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Nov 1, 2024
1 parent d45db71 commit 2a74799
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion iocs/filename-iocs.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4421,6 +4421,6 @@ C:\\perflogs\\RunSchedulerTaskOnce\.ps1;85

# Suspicioius *.rdp files in Outlook temporary folders https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files/
\\AppData\\Local\\Microsoft\\Windows\\(INetCache|Temporary Internet Files)\\Content\.Outlook\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp$;70
\\AppData\\Local\\Packages\\Microsoft\.Outlook_[a-zA-Z0-9]+\\LocalCache\\OlkDownloads\\[^\\]{1,255}\.rdp$;70
\\AppData\\Local\\Packages\\Microsoft\.Outlook_[a-zA-Z0-9]{1,50}\\.{0,120}\\[^\\]{1,80}\.rdp$;70

# End

0 comments on commit 2a74799

Please sign in to comment.