Skip to content

Commit 4e200ff

Browse files
committed
fix: new IOC, missing score
1 parent b09da86 commit 4e200ff

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

iocs/filename-iocs.txt

+2-1
Original file line numberDiff line numberDiff line change
@@ -4420,6 +4420,7 @@ C:\\perflogs\\RunSchedulerTaskOnce\.ps1;85
44204420
/tmp/.xdiag/tordata/state.tmp;85
44214421

44224422
# *.rdp files in Outlook temporary folders https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files/
4423-
\\AppData\\Local\\Microsoft\\Windows\\(INetCache|Temporary Internet Files)\\Content\.Outlook\\\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp$
4423+
\\AppData\\Local\\Microsoft\\Windows\\(INetCache|Temporary Internet Files)\\Content\.Outlook\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp$;70
4424+
\\AppData\\Local\\Packages\\Microsoft\.Outlook_[a-zA-Z0-9]+\\LocalCache\\OlkDownloads\\[^\\]{1,255}\.rdp$;70
44244425

44254426
# End

0 commit comments

Comments
 (0)