Skip to content

Commit b09da86

Browse files
committed
*.rdp files in Outlook temp folders
1 parent d31123f commit b09da86

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

iocs/filename-iocs.txt

+4-1
Original file line numberDiff line numberDiff line change
@@ -4419,4 +4419,7 @@ C:\\perflogs\\RunSchedulerTaskOnce\.ps1;85
44194419
/tmp/.xdiag/tordata/cached-microdesc-consensus.tmp;85
44204420
/tmp/.xdiag/tordata/state.tmp;85
44214421

4422-
# End
4422+
# *.rdp files in Outlook temporary folders https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files/
4423+
\\AppData\\Local\\Microsoft\\Windows\\(INetCache|Temporary Internet Files)\\Content\.Outlook\\\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp$
4424+
4425+
# End

0 commit comments

Comments
 (0)