Skip to content

Commit

Permalink
Update filename-iocs.txt
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Nov 3, 2024
1 parent 34745c8 commit f47e69f
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion iocs/filename-iocs.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4421,6 +4421,6 @@ C:\\perflogs\\RunSchedulerTaskOnce\.ps1;85
# Suspicioius *.rdp files in Outlook temporary folders https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files/
\\AppData\\Local\\Microsoft\\Windows\\(INetCache|Temporary Internet Files)\\Content\.Outlook\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp$;70
\\AppData\\Local\\Packages\\Microsoft\.Outlook_[a-zA-Z0-9]{1,50}\\.{0,120}\\[^\\]{1,80}\.rdp$;70
\\AppData\\Local\\Microsoft\\Olk\\Attachments\\.{0,120}\\[^\\]{1,80}\.rdp$;70
\\AppData\\Local\\Microsoft\\Olk\\Attachments\\(?:[^\\]{1,50}\\){0,5}[^\\]{1,80}\.rdp$;70

# End

0 comments on commit f47e69f

Please sign in to comment.