Skip to content

Commit

Permalink
*.rdp files in Outlook temp folders
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Oct 31, 2024
1 parent d31123f commit b09da86
Showing 1 changed file with 4 additions and 1 deletion.
5 changes: 4 additions & 1 deletion iocs/filename-iocs.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4419,4 +4419,7 @@ C:\\perflogs\\RunSchedulerTaskOnce\.ps1;85
/tmp/.xdiag/tordata/cached-microdesc-consensus.tmp;85
/tmp/.xdiag/tordata/state.tmp;85

# End
# *.rdp files in Outlook temporary folders https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files/
\\AppData\\Local\\Microsoft\\Windows\\(INetCache|Temporary Internet Files)\\Content\.Outlook\\\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp$

# End

0 comments on commit b09da86

Please sign in to comment.