Investigating SOC141 — Phishing URL Detected in Letsdefend SOC
Common Information
Type Value
UUID aa4e8332-8dda-4d46-a5a1-902e67c866bc
Fingerprint 780b9992836b689
Analysis status DONE
Considered CTI value 0
Text language
Published Sept. 30, 2024, 12:40 p.m.
Added to db Sept. 30, 2024, 2:40 p.m.
Last updated Nov. 17, 2024, 9:42 p.m.
Headline Investigating SOC141 — Phishing URL Detected in Letsdefend SOC
Title Investigating SOC141 — Phishing URL Detected in Letsdefend SOC
Detected Hints/Tags/Attributes 38/2/13
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 167 Cybersecurity on Medium https://medium.com/feed/tag/cybersecurity 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 2
mogagrocol.ru
Details Domain 47
letsdefend.io
Details Domain 2
ru-uid-507352920.pp.ru
Details Email 2
mogagrocol.ru/wp-content/plugins/akismet/fv/index.php?email=ellie@letsdefend.io
Details File 1205
index.php
Details File 3
kbdyak.exe
Details File 1018
rundll32.exe
Details md5 1
a4513379dad5233afa402cc56a8b9222
Details sha256 1
ccd380ea868ffad4f960d7455fecf88c2ac3550001bbb6c21c31ae70b3bbf4f6
Details IPv4 2
172.16.17.49
Details IPv4 2
91.189.114.8
Details Url 2
http://mogagrocol.ru/wp-content/plugins/akismet/fv/index.php?email=ellie@letsdefend.io
Details Url 2
http://ru-uid-507352920.pp.ru/kbdyak.exe