Showing posts with label Advisory. Show all posts
Showing posts with label Advisory. Show all posts

Saturday, May 2, 2015

Phishing Target: Oregon Health and Science University

Over the past week we have been seeing indications on our system that Oregon Health and Science University may have been the target of a targeted phishing campaign.

Sensors on an upstream ISP network captured the following:
April 28th 2015, 23:21:55.219 iocs-phishing
April 28th 2015, 23:21:51.528 iocs-phishing
April 28th 2015, 23:21:46.435 iocs-phishing
April 28th 2015, 23:21:46.407 iocs-phishing
April 28th 2015, 23:21:45.290 iocs-phishing
April 28th 2015, 23:21:44.085 iocs-phishing
April 28th 2015, 23:21:43.850 iocs-phishing
April 28th 2015, 23:21:40.513 iocs-phishing
April 28th 2015, 23:21:39.931 iocs-phishing
April 28th 2015, 23:21:39.581 iocs-phishing
April 28th 2015, 23:21:37.889 iocs-phishing
April 28th 2015, 23:21:37.877 iocs-phishing
April 28th 2015, 23:21:37.866 iocs-phishing
April 28th 2015, 23:21:35.422 iocs-phishing
April 28th 2015, 23:21:34.757 iocs-phishing
April 28th 2015, 23:21:34.163 iocs-phishing
April 28th 2015, 23:21:32.817 iocs-phishing
April 28th 2015, 23:21:32.813 iocs-phishing
April 28th 2015, 23:21:32.292 iocs-phishing
April 28th 2015, 23:21:31.954 iocs-phishing
April 28th 2015, 23:21:29.227 iocs-phishing
April 28th 2015, 23:21:27.985 iocs-phishing
April 28th 2015, 23:21:25.912 iocs-phishing
April 28th 2015, 23:21:25.370 iocs-phishing
April 28th 2015, 23:21:24.252 iocs-phishing
April 28th 2015, 23:21:16.234 iocs-phishing
April 28th 2015, 23:21:16.223 iocs-phishing
April 27th 2015, 14:18:54.410 iocs-phishing
April 27th 2015, 14:18:51.617 iocs-phishing
April 27th 2015, 14:18:51.601 iocs-phishing
April 27th 2015, 14:18:50.170 iocs-phishing
April 27th 2015, 14:18:49.845 iocs-phishing
April 27th 2015, 14:18:49.483 iocs-phishing
April 27th 2015, 14:18:47.442 iocs-phishing
April 27th 2015, 14:18:46.466 iocs-phishing
April 27th 2015, 14:18:46.004 iocs-phishing
April 27th 2015, 14:18:45.447 iocs-phishing
April 27th 2015, 14:18:45.418 iocs-phishing
April 27th 2015, 14:18:45.385 iocs-phishing
April 27th 2015, 14:18:43.473 iocs-phishing
April 27th 2015, 14:18:43.006 iocs-phishing
April 27th 2015, 14:18:42.687 iocs-phishing
April 27th 2015, 14:18:41.553 iocs-phishing
April 27th 2015, 14:18:41.552 iocs-phishing
April 27th 2015, 14:18:41.400 iocs-phishing
April 27th 2015, 14:18:41.299 iocs-phishing
April 27th 2015, 14:18:40.634 iocs-phishing
April 27th 2015, 14:18:40.509 iocs-phishing
April 27th 2015, 14:18:39.393 iocs-phishing
April 27th 2015, 14:18:39.310 iocs-phishing
April 27th 2015, 14:18:39.185 iocs-phishing
April 27th 2015, 14:18:38.294 iocs-phishing
April 27th 2015, 14:18:38.293 iocs-phishing
April 27th 2015, 14:18:37.323 iocs-phishing
April 27th 2015, 14:18:34.208 iocs-phishing
April 27th 2015, 14:18:34.191 iocs-phishing
April 27th 2015, 14:18:33.046 iocs-phishing
April 27th 2015, 14:18:32.771 iocs-phishing
April 27th 2015, 14:18:31.819 iocs-phishing
April 27th 2015, 14:18:29.084 iocs-phishing
April 27th 2015, 14:18:28.786 iocs-phishing
April 27th 2015, 14:18:28.276 iocs-phishing
April 27th 2015, 14:18:26.891 iocs-phishing
April 27th 2015, 14:18:26.880 iocs-phishing
April 27th 2015, 14:18:26.870 iocs-phishing
April 27th 2015, 14:18:25.522 iocs-phishing
April 27th 2015, 14:18:24.364 iocs-phishing
April 27th 2015, 14:18:24.010 iocs-phishing
April 27th 2015, 14:18:23.471 iocs-phishing
April 27th 2015, 14:18:23.470 iocs-phishing
April 27th 2015, 14:18:23.333 iocs-phishing
April 27th 2015, 14:18:23.244 iocs-phishing
April 27th 2015, 14:18:21.945 iocs-phishing
April 27th 2015, 14:18:21.795 iocs-phishing
April 27th 2015, 14:18:21.525 iocs-phishing
April 27th 2015, 14:18:21.337 iocs-phishing
April 27th 2015, 14:18:21.195 iocs-phishing
April 27th 2015, 14:18:19.650 iocs-phishing
April 27th 2015, 14:18:19.649 iocs-phishing
April 27th 2015, 14:18:19.170 iocs-phishing
April 27th 2015, 14:18:16.608 iocs-phishing
April 27th 2015, 14:18:16.592 iocs-phishing
April 27th 2015, 14:18:16.534 iocs-phishing
April 27th 2015, 14:18:13.092 iocs-phishing
April 27th 2015, 14:18:13.076 iocs-phishing
April 27th 2015, 14:18:11.484 iocs-phishing
April 27th 2015, 14:18:11.217 iocs-phishing
April 27th 2015, 14:18:11.020 iocs-phishing
April 27th 2015, 14:18:08.989 iocs-phishing
April 27th 2015, 14:18:08.820 iocs-phishing
April 27th 2015, 14:18:08.513 iocs-phishing
April 27th 2015, 14:18:07.109 iocs-phishing
April 27th 2015, 14:18:07.097 iocs-phishing
April 27th 2015, 14:18:07.081 iocs-phishing
April 27th 2015, 14:18:05.093 iocs-phishing
April 27th 2015, 14:18:04.694 iocs-phishing
April 27th 2015, 14:18:04.384 iocs-phishing
April 27th 2015, 14:18:03.954 iocs-phishing
April 27th 2015, 14:18:03.953 iocs-phishing
April 27th 2015, 14:18:02.962 iocs-phishing
April 27th 2015, 14:18:02.871 iocs-phishing
April 27th 2015, 14:18:02.312 iocs-phishing
April 27th 2015, 14:18:02.188 iocs-phishing
April 27th 2015, 14:18:01.959 iocs-phishing
April 27th 2015, 14:18:00.890 iocs-phishing
April 27th 2015, 14:18:00.755 iocs-phishing
April 27th 2015, 14:17:59.922 iocs-phishing
April 27th 2015, 14:17:59.919 iocs-phishing
April 27th 2015, 14:17:59.226 iocs-phishing
April 27th 2015, 14:17:55.680 iocs-phishing
April 27th 2015, 14:17:55.663 iocs-phishing
April 27th 2015, 14:17:54.580 iocs-phishing
April 27th 2015, 14:17:54.310 iocs-phishing
April 27th 2015, 14:17:52.798 iocs-phishing
April 27th 2015, 14:17:50.545 iocs-phishing
April 27th 2015, 14:17:50.379 iocs-phishing
April 27th 2015, 14:17:50.057 iocs-phishing
April 27th 2015, 14:17:48.507 iocs-phishing
April 27th 2015, 14:17:48.492 iocs-phishing
April 27th 2015, 14:17:48.482 iocs-phishing
April 27th 2015, 14:17:47.323 iocs-phishing
April 27th 2015, 14:17:46.003 iocs-phishing
April 27th 2015, 14:17:45.691 iocs-phishing
April 27th 2015, 14:17:45.162 iocs-phishing
April 27th 2015, 14:17:45.161 iocs-phishing
April 27th 2015, 14:17:44.919 iocs-phishing
April 27th 2015, 14:17:44.742 iocs-phishing
April 27th 2015, 14:17:43.081 iocs-phishing
April 27th 2015, 14:17:42.565 iocs-phishing
April 27th 2015, 14:17:41.451 iocs-phishing
April 27th 2015, 14:17:40.054 iocs-phishing
April 27th 2015, 14:17:35.364 iocs-phishing
April 27th 2015, 14:17:35.362 iocs-phishing
April 27th 2015, 13:40:17.303 iocs-REDACTED
April 27th 2015, 13:40:16.083 iocs-REDACTED
April 23rd 2015, 03:27:02.867 iocs-phishing
April 23rd 2015, 03:27:00.073 iocs-phishing
April 23rd 2015, 03:27:00.056 iocs-phishing
April 23rd 2015, 03:26:58.395 iocs-phishing
April 23rd 2015, 03:26:58.125 iocs-phishing
April 23rd 2015, 03:26:57.698 iocs-phishing
April 23rd 2015, 03:26:55.767 iocs-phishing
April 23rd 2015, 03:26:55.464 iocs-phishing
April 23rd 2015, 03:26:55.163 iocs-phishing
April 23rd 2015, 03:26:53.844 iocs-phishing
April 23rd 2015, 03:26:53.834 iocs-phishing
April 23rd 2015, 03:26:53.824 iocs-phishing
April 23rd 2015, 03:26:52.639 iocs-phishing
April 23rd 2015, 03:26:51.413 iocs-phishing
April 23rd 2015, 03:26:51.100 iocs-phishing
April 23rd 2015, 03:26:50.634 iocs-phishing
April 23rd 2015, 03:26:50.633 iocs-phishing
April 23rd 2015, 03:26:49.722 iocs-phishing
April 23rd 2015, 03:26:49.634 iocs-phishing
April 23rd 2015, 03:26:48.117 iocs-phishing
April 23rd 2015, 03:26:47.993 iocs-phishing
April 23rd 2015, 03:26:47.755 iocs-phishing
April 23rd 2015, 03:26:47.546 iocs-phishing
April 23rd 2015, 03:26:46.296 iocs-phishing
April 23rd 2015, 03:26:46.264 iocs-phishing
April 23rd 2015, 01:15:22.229 iocs-phishing
April 23rd 2015, 01:15:19.192 iocs-phishing
April 23rd 2015, 01:15:11.223 iocs-phishing
April 23rd 2015, 01:15:11.128 iocs-phishing
April 23rd 2015, 01:15:09.295 iocs-phishing
April 23rd 2015, 01:15:08.315 iocs-phishing
April 23rd 2015, 01:15:06.993 iocs-phishing
April 23rd 2015, 01:15:00.362 iocs-phishing
April 23rd 2015, 01:14:59.399 iocs-phishing
April 23rd 2015, 01:14:58.780 iocs-phishing
April 23rd 2015, 01:14:57.684 iocs-phishing
April 23rd 2015, 01:14:57.598 iocs-phishing
April 23rd 2015, 01:14:57.551 iocs-phishing
April 23rd 2015, 01:14:53.843 iocs-phishing
April 23rd 2015, 01:14:51.402 iocs-phishing
April 23rd 2015, 01:14:49.773 iocs-phishing
April 23rd 2015, 01:14:46.749 iocs-phishing
April 23rd 2015, 01:14:46.747 iocs-phishing
April 23rd 2015, 01:14:46.074 iocs-phishing
April 23rd 2015, 01:14:45.726 iocs-phishing
April 23rd 2015, 01:14:43.551 iocs-phishing
April 23rd 2015, 01:14:42.273 iocs-phishing
April 23rd 2015, 01:14:41.242 iocs-phishing
April 23rd 2015, 01:14:39.119 iocs-phishing
April 23rd 2015, 01:14:32.108 iocs-phishing
April 23rd 2015, 01:14:32.076 iocs-phishing
April 23rd 2015, 01:14:27.795 iocs-phishing
April 23rd 2015, 01:13:58.054 iocs-phishing
April 23rd 2015, 01:13:57.450 iocs-phishing
April 23rd 2015, 01:13:34.367 iocs-phishing
April 21st 2015, 17:02:14.810 iocs-phishing
April 21st 2015, 17:02:13.211 iocs-phishing
April 21st 2015, 17:02:07.059 iocs-phishing
April 21st 2015, 17:02:07.015 iocs-phishing
April 21st 2015, 17:02:05.108 iocs-phishing
April 21st 2015, 17:02:04.261 iocs-phishing
April 21st 2015, 17:02:03.133 iocs-phishing
April 21st 2015, 17:01:57.851 iocs-phishing
April 21st 2015, 17:01:57.689 iocs-phishing
April 21st 2015, 17:01:57.059 iocs-phishing
April 21st 2015, 17:01:54.100 iocs-phishing
April 21st 2015, 17:01:54.081 iocs-phishing
April 21st 2015, 17:01:54.053 iocs-phishing
April 21st 2015, 17:01:45.697 iocs-phishing
April 21st 2015, 17:01:44.394 iocs-phishing
April 21st 2015, 17:01:42.733 iocs-phishing
April 21st 2015, 17:01:41.648 iocs-phishing
April 21st 2015, 17:01:41.643 iocs-phishing
April 21st 2015, 17:01:41.343 iocs-phishing
April 21st 2015, 17:01:41.053 iocs-phishing
April 21st 2015, 17:01:37.309 iocs-phishing
April 21st 2015, 17:01:36.619 iocs-phishing
April 21st 2015, 17:01:36.213 iocs-phishing
April 21st 2015, 17:01:35.790 iocs-phishing
April 21st 2015, 17:01:32.737 iocs-phishing
April 21st 2015, 17:01:32.737 iocs-phishing
April 21st 2015, 17:01:28.544 iocs-phishing
April 21st 2015, 17:01:23.326 iocs-phishing
April 21st 2015, 17:01:05.381 iocs-phishing
April 21st 2015, 17:01:05.050 iocs-phishing
April 21st 2015, 17:00:48.680 iocs-phishing
April 21st 2015, 17:00:43.925 iocs-phishing
April 21st 2015, 17:00:40.598 iocs-phishing
April 21st 2015, 17:00:24.375 iocs-phishing
April 21st 2015, 17:00:22.686 iocs-phishing
April 21st 2015, 17:00:19.869 iocs-phishing
April 21st 2015, 17:00:15.241 iocs-phishing
April 21st 2015, 17:00:15.040 iocs-phishing
April 21st 2015, 17:00:14.924 iocs-phishing
April 21st 2015, 17:00:05.801 iocs-phishing
April 21st 2015, 17:00:01.596 iocs-phishing
April 21st 2015, 16:59:58.323 iocs-phishing
April 21st 2015, 16:59:53.245 iocs-phishing
April 21st 2015, 16:59:53.243 iocs-phishing
April 21st 2015, 16:59:52.242 iocs-phishing
April 21st 2015, 16:59:51.274 iocs-phishing
April 21st 2015, 16:59:43.907 iocs-phishing
April 21st 2015, 16:59:41.274 iocs-phishing
April 21st 2015, 16:59:36.137 iocs-phishing
April 21st 2015, 16:59:30.816 iocs-phishing
April 21st 2015, 16:59:09.740 iocs-phishing
April 21st 2015, 16:59:09.724 iocs-phishing
April 20th 2015, 10:18:29.559 iocs-phishing
April 20th 2015, 10:18:28.220 iocs-phishing
April 20th 2015, 10:18:25.483 iocs-phishing
April 20th 2015, 10:18:25.464 iocs-phishing
April 20th 2015, 10:18:23.755 iocs-phishing
April 20th 2015, 10:18:23.316 iocs-phishing
April 20th 2015, 10:18:22.742 iocs-phishing
April 20th 2015, 10:18:18.217 iocs-phishing
April 20th 2015, 10:18:17.660 iocs-phishing
April 20th 2015, 10:18:15.014 iocs-phishing
April 20th 2015, 10:18:13.012 iocs-phishing
April 20th 2015, 10:18:12.992 iocs-phishing
April 20th 2015, 10:18:12.979 iocs-phishing
April 20th 2015, 10:18:07.924 iocs-phishing
April 20th 2015, 10:18:06.096 iocs-phishing
April 20th 2015, 10:18:03.338 iocs-phishing
April 20th 2015, 10:18:02.131 iocs-phishing
April 20th 2015, 10:18:02.124 iocs-phishing
April 20th 2015, 10:18:01.531 iocs-phishing
April 20th 2015, 10:18:01.131 iocs-phishing
April 20th 2015, 10:17:58.025 iocs-phishing
April 20th 2015, 10:17:57.393 iocs-phishing
April 20th 2015, 10:17:56.176 iocs-phishing
April 20th 2015, 10:17:55.491 iocs-phishing
April 20th 2015, 10:17:51.421 iocs-phishing
April 20th 2015, 10:17:51.412 iocs-phishing
April 20th 2015, 10:17:48.697 iocs-phishing
April 20th 2015, 10:17:43.425 iocs-phishing
April 20th 2015, 10:17:43.378 iocs-phishing
April 20th 2015, 10:17:39.386 iocs-phishing
April 20th 2015, 10:17:37.899 iocs-phishing
April 20th 2015, 10:17:37.286 iocs-phishing
April 20th 2015, 10:17:25.099 iocs-phishing
April 20th 2015, 10:17:23.902 iocs-phishing
April 20th 2015, 10:17:21.439 iocs-phishing
April 20th 2015, 10:17:19.354 iocs-phishing
April 20th 2015, 10:17:19.316 iocs-phishing
April 20th 2015, 10:17:19.196 iocs-phishing
April 20th 2015, 10:17:14.045 iocs-phishing
April 20th 2015, 10:17:11.563 iocs-phishing
April 20th 2015, 10:17:09.678 iocs-phishing
April 20th 2015, 10:17:05.783 iocs-phishing
April 20th 2015, 10:17:05.780 iocs-phishing
April 20th 2015, 10:17:05.472 iocs-phishing
April 20th 2015, 10:17:05.010 iocs-phishing
April 20th 2015, 10:16:58.499 iocs-phishing
April 20th 2015, 10:16:57.521 iocs-phishing
April 20th 2015, 10:16:55.436 iocs-phishing
April 20th 2015, 10:16:53.135 iocs-phishing
April 20th 2015, 10:16:37.603 iocs-phishing
April 20th 2015, 10:16:37.524 iocs-phishing
April 20th 2015, 10:10:01.341 iocs-REDACTED
April 20th 2015, 10:09:58.109 iocs-REDACTED
April 18th 2015, 12:47:14.934 iocs-phishing
April 18th 2015, 12:47:09.531 iocs-phishing
April 18th 2015, 12:46:58.774 iocs-phishing
April 18th 2015, 12:46:58.728 iocs-phishing
April 18th 2015, 12:46:52.673 iocs-phishing
April 18th 2015, 12:46:49.185 iocs-phishing
April 18th 2015, 12:46:46.284 iocs-phishing
April 18th 2015, 12:46:33.325 iocs-phishing
April 18th 2015, 12:46:31.587 iocs-phishing
April 18th 2015, 12:46:28.002 iocs-phishing
April 18th 2015, 12:46:23.507 iocs-phishing
April 18th 2015, 12:46:23.392 iocs-phishing
April 18th 2015, 12:46:23.227 iocs-phishing
April 18th 2015, 12:46:09.755 iocs-phishing
April 18th 2015, 12:46:06.014 iocs-phishing
April 18th 2015, 12:46:02.776 iocs-phishing
April 18th 2015, 12:45:57.440 iocs-phishing
April 18th 2015, 12:45:57.435 iocs-phishing
April 18th 2015, 12:45:56.039 iocs-phishing
April 18th 2015, 12:45:55.198 iocs-phishing
April 18th 2015, 12:45:43.674 iocs-phishing
April 18th 2015, 12:45:40.719 iocs-phishing
April 18th 2015, 12:45:34.053 iocs-phishing
April 18th 2015, 12:45:27.953 iocs-phishing
April 18th 2015, 12:45:03.562 iocs-phishing
April 18th 2015, 12:45:03.541 iocs-phishing
April 17th 2015, 12:42:24.010 iocs-phishing
April 17th 2015, 12:42:20.044 iocs-phishing
April 17th 2015, 12:42:19.018 iocs-phishing
April 17th 2015, 12:42:13.416 iocs-phishing
April 17th 2015, 12:42:13.390 iocs-phishing
April 17th 2015, 12:42:10.828 iocs-phishing
April 17th 2015, 12:42:10.361 iocs-phishing
April 17th 2015, 12:42:10.152 iocs-phishing
April 17th 2015, 12:42:06.901 iocs-phishing
April 17th 2015, 12:42:06.569 iocs-phishing
April 17th 2015, 12:42:05.323 iocs-phishing
April 17th 2015, 12:42:03.745 iocs-phishing
April 17th 2015, 12:42:03.715 iocs-phishing
April 17th 2015, 12:42:03.686 iocs-phishing
April 17th 2015, 12:42:00.112 iocs-phishing
April 17th 2015, 12:41:58.801 iocs-phishing
April 17th 2015, 12:41:57.160 iocs-phishing
April 17th 2015, 12:41:55.086 iocs-phishing
April 17th 2015, 12:41:55.085 iocs-phishing
April 17th 2015, 12:41:54.809 iocs-phishing
April 17th 2015, 12:41:54.658 iocs-phishing
April 17th 2015, 12:41:52.653 iocs-phishing
April 17th 2015, 12:41:52.316 iocs-phishing
April 17th 2015, 12:41:51.756 iocs-phishing
April 17th 2015, 12:41:50.875 iocs-phishing
April 17th 2015, 12:41:48.130 iocs-phishing
April 17th 2015, 12:41:48.127 iocs-phishing
April 17th 2015, 12:41:45.998 iocs-phishing
April 17th 2015, 12:41:41.377 iocs-phishing
April 17th 2015, 12:41:41.356 iocs-phishing
April 17th 2015, 12:41:39.354 iocs-phishing
April 17th 2015, 12:41:37.594 iocs-phishing
April 17th 2015, 12:41:37.056 iocs-phishing
April 17th 2015, 12:41:33.623 iocs-phishing
April 17th 2015, 12:41:33.218 iocs-phishing
April 17th 2015, 12:41:31.984 iocs-phishing
April 17th 2015, 12:41:29.848 iocs-phishing
April 17th 2015, 12:41:29.835 iocs-phishing
April 17th 2015, 12:41:29.820 iocs-phishing
April 17th 2015, 12:41:27.070 iocs-phishing
April 17th 2015, 12:41:25.205 iocs-phishing
April 17th 2015, 12:41:24.201 iocs-phishing
April 17th 2015, 12:41:22.811 iocs-phishing
April 17th 2015, 12:41:22.809 iocs-phishing
April 17th 2015, 12:41:22.503 iocs-phishing
April 17th 2015, 12:41:22.187 iocs-phishing
April 17th 2015, 12:41:18.811 iocs-phishing
April 17th 2015, 12:41:17.700 iocs-phishing
April 17th 2015, 12:41:15.381 iocs-phishing
April 17th 2015, 12:41:12.823 iocs-phishing
April 17th 2015, 12:41:06.318 iocs-phishing
April 17th 2015, 12:41:06.307 iocs-phishing
April 17th 2015, 02:24:11.263 iocs-phishing
April 17th 2015, 02:24:10.062 iocs-phishing
April 17th 2015, 02:24:04.908 iocs-phishing
April 17th 2015, 02:24:04.868 iocs-phishing
April 17th 2015, 02:24:01.659 iocs-phishing
April 17th 2015, 02:24:01.220 iocs-phishing
April 17th 2015, 02:24:00.796 iocs-phishing
April 17th 2015, 02:23:57.325 iocs-phishing
April 17th 2015, 02:23:56.847 iocs-phishing
April 17th 2015, 02:23:55.863 iocs-phishing
April 17th 2015, 02:23:53.581 iocs-phishing
April 17th 2015, 02:23:53.501 iocs-phishing
April 17th 2015, 02:23:53.453 iocs-phishing
April 17th 2015, 02:23:48.102 iocs-phishing
April 17th 2015, 02:23:46.442 iocs-phishing
April 17th 2015, 02:23:45.596 iocs-phishing
April 17th 2015, 02:23:43.982 iocs-phishing
April 17th 2015, 02:23:43.980 iocs-phishing
April 17th 2015, 02:23:43.455 iocs-phishing
April 17th 2015, 02:23:42.589 iocs-phishing
April 17th 2015, 02:23:40.460 iocs-phishing
April 17th 2015, 02:23:39.601 iocs-phishing
April 17th 2015, 02:23:38.820 iocs-phishing
April 17th 2015, 02:23:37.661 iocs-phishing
April 17th 2015, 02:23:34.679 iocs-phishing
April 17th 2015, 02:23:34.677 iocs-phishing
April 17th 2015, 02:23:32.243 iocs-phishing
April 17th 2015, 02:23:23.458 iocs-phishing
April 17th 2015, 02:23:23.418 iocs-phishing
April 17th 2015, 02:23:19.272 iocs-phishing
April 17th 2015, 02:23:17.163 iocs-phishing
April 17th 2015, 02:23:16.374 iocs-phishing
April 17th 2015, 02:23:10.324 iocs-phishing
April 17th 2015, 02:23:09.686 iocs-phishing
April 17th 2015, 02:23:08.307 iocs-phishing
April 17th 2015, 02:23:05.630 iocs-phishing
April 17th 2015, 02:23:05.591 iocs-phishing
April 17th 2015, 02:23:05.554 iocs-phishing
April 17th 2015, 02:23:00.293 iocs-phishing
April 17th 2015, 02:22:57.688 iocs-phishing
April 17th 2015, 02:22:55.637 iocs-phishing
April 17th 2015, 02:22:54.541 iocs-phishing
April 17th 2015, 02:22:54.540 iocs-phishing
April 17th 2015, 02:22:54.015 iocs-phishing
April 17th 2015, 02:22:53.109 iocs-phishing
April 17th 2015, 02:22:49.605 iocs-phishing
April 17th 2015, 02:22:49.108 iocs-phishing
April 17th 2015, 02:22:47.455 iocs-phishing
April 17th 2015, 02:22:46.470 iocs-phishing
April 17th 2015, 02:22:42.024 iocs-phishing
April 17th 2015, 02:22:42.022 iocs-phishing
April 17th 2015, 02:22:38.888 iocs-phishing
April 17th 2015, 02:22:27.403 iocs-phishing
April 17th 2015, 02:22:27.376 iocs-phishing
April 17th 2015, 02:22:24.490 iocs-phishing
April 17th 2015, 02:22:23.023 iocs-phishing
April 17th 2015, 02:22:21.924 iocs-phishing
April 17th 2015, 02:22:16.455 iocs-phishing
April 17th 2015, 02:22:15.606 iocs-phishing
April 17th 2015, 02:22:14.469 iocs-phishing
April 17th 2015, 02:22:11.718 iocs-phishing
April 17th 2015, 02:22:11.691 iocs-phishing
April 17th 2015, 02:22:11.667 iocs-phishing
April 17th 2015, 02:22:01.951 iocs-phishing
April 17th 2015, 02:21:58.485 iocs-phishing
April 17th 2015, 02:21:56.313 iocs-phishing
April 17th 2015, 02:21:53.767 iocs-phishing
April 17th 2015, 02:21:53.764 iocs-phishing
April 17th 2015, 02:21:52.248 iocs-phishing
April 17th 2015, 02:21:51.482 iocs-phishing
April 17th 2015, 02:21:47.088 iocs-phishing
April 17th 2015, 02:21:46.047 iocs-phishing
April 17th 2015, 02:21:45.237 iocs-phishing
April 17th 2015, 02:21:44.008 iocs-phishing
April 17th 2015, 02:21:38.428 iocs-phishing
April 17th 2015, 02:21:38.425 iocs-phishing
April 17th 2015, 02:21:32.649 iocs-phishing
April 17th 2015, 02:21:14.980 iocs-phishing
April 17th 2015, 02:21:14.921 iocs-phishing
April 17th 2015, 02:21:09.377 iocs-phishing
April 17th 2015, 02:21:07.338 iocs-phishing
April 17th 2015, 02:21:05.895 iocs-phishing
April 17th 2015, 02:20:52.442 iocs-phishing
April 17th 2015, 02:20:51.031 iocs-phishing
April 17th 2015, 02:20:45.585 iocs-phishing
April 17th 2015, 02:20:40.146 iocs-phishing
April 17th 2015, 02:20:40.081 iocs-phishing
April 17th 2015, 02:20:39.972 iocs-phishing
April 17th 2015, 02:20:30.182 iocs-phishing
April 17th 2015, 02:20:23.560 iocs-phishing
April 17th 2015, 02:20:13.307 iocs-phishing
April 17th 2015, 02:20:04.801 iocs-phishing
April 17th 2015, 02:20:04.781 iocs-phishing
April 17th 2015, 02:19:59.905 iocs-phishing
April 17th 2015, 02:19:57.242 iocs-phishing
April 17th 2015, 02:19:43.673 iocs-phishing
April 17th 2015, 02:19:38.763 iocs-phishing
April 17th 2015, 02:19:29.139 iocs-phishing
April 17th 2015, 02:19:20.502 iocs-phishing
April 16th 2015, 12:26:16.884 iocs-phishing
April 16th 2015, 12:26:16.848 iocs-phishing
April 14th 2015, 16:01:40.069 iocs-REDACTED
April 14th 2015, 16:00:30.342 iocs-REDACTED
April 14th 2015, 15:58:20.368 iocs-REDACTED
April 14th 2015, 15:54:52.206 iocs-REDACTED
April 14th 2015, 15:52:26.131 iocs-REDACTED
April 14th 2015, 15:50:51.527 iocs-REDACTED
April 14th 2015, 15:49:40.191 iocs-REDACTED
April 13th 2015, 18:46:50.362 iocs-phishing
April 13th 2015, 18:46:39.156 iocs-phishing
April 13th 2015, 18:46:38.954 iocs-phishing
April 13th 2015, 18:46:33.783 iocs-phishing
April 13th 2015, 18:46:31.639 iocs-phishing
April 13th 2015, 18:46:28.755 iocs-phishing
April 13th 2015, 18:46:20.368 iocs-phishing
April 13th 2015, 18:46:19.194 iocs-phishing
April 13th 2015, 18:46:15.986 iocs-phishing
April 13th 2015, 18:46:11.949 iocs-phishing
April 13th 2015, 18:46:11.895 iocs-phishing
April 13th 2015, 18:46:11.853 iocs-phishing
April 13th 2015, 18:46:02.574 iocs-phishing
April 13th 2015, 18:45:56.101 iocs-phishing
April 13th 2015, 18:45:54.437 iocs-phishing
April 13th 2015, 18:45:54.434 iocs-phishing
April 13th 2015, 18:45:53.729 iocs-phishing
April 13th 2015, 18:45:53.293 iocs-phishing
April 13th 2015, 18:45:49.574 iocs-phishing

While we cannot release the actual information because it would expose the actual targets we have also seen specific malware similar to Dyre but modified specifically for this attack. Customers of SLC Security Services LLC have been provided additional information in direct messages to their consoles for review.

It is our policy not to release any identifiable information but we continue to see activity directed at this entity. We will release information to the University if they make a formal request.


Monday, April 6, 2015

RECENT BRUTE FORCERS: You are blocking these right?!

121.14.5.125,ssh-brute-force,2015-04-06
218.87.111.110,ssh-brute-force,2015-04-06
43.255.191.164,ssh-brute-force,2015-04-06
37.132.67.140,ssh-brute-force,2015-04-06
218.87.111.108,ssh-brute-force,2015-04-06
218.87.111.107,ssh-brute-force,2015-04-06
61.174.49.103,ssh-brute-force,2015-04-06
218.87.111.117,ssh-brute-force,2015-04-06
43.255.190.151,ssh-brute-force,2015-04-06
182.100.67.113,ssh-brute-force,2015-04-06
182.100.67.114,ssh-brute-force,2015-04-06
221.229.160.222,ssh-brute-force,2015-04-06
58.218.204.226,ssh-brute-force,2015-04-06
58.218.199.49,ssh-brute-force,2015-04-06
221.229.166.29,ssh-brute-force,2015-04-06
218.65.30.92,ssh-brute-force,2015-04-06
58.218.204.245,ssh-brute-force,2015-04-06
218.87.109.60,ssh-brute-force,2015-04-06

Colleges check for SQLi on your systems!

Honestly for the past few months we have seen nothing but a rash of colleges and universities getting smacked with SQLi exploits. Test your servers or I'm sure the hackers responsible for these attacks will test it for you.

We have at least 26 confirmed reports of breaches of which some have been reported and some have been brushed under the rug...

Thursday, March 26, 2015

UPDATED WITH INDICATORS AND NOTES: Large BOTNET exposed

SLC Security Services LLC has discovered a previously unknown BOTNET network. We will be adding the indicators to our paid feeds. We had previously been seeing the nodes responding to various internet host but we couldn't get the host to respond to any of the request we sent. Apparently the bot command and control requires a certain sequence of ports to be queried prior to the C+C actually responding to the infected bot request in a normal fashion.

More information is being sent out via our alert feed to our paid subscribers.

UPDATE: Updated indicators have been rolled out to our client systems. If you see any indicators triggering with "BOTLICK" as the alert type page our on call contact specified in your contract. We would love to catch an active client so we can determine the initial infection vectors.

ADDITIONAL INDICATORS:
If you see encrypted traffic going to any of the following IP addresses please check your source for processes that should not be running. This is affecting Windows 7 and Windows 8 PC's.

179.111.212.221
81.149.12.77
89.156.44.210
38.108.61.227
37.110.214.124
86.126.135.242
112.211.182.241
125.62.97.218
95.31.88.21
112.198.90.89 - Additional C+C Detected
36.79.181.47 - Additional C+C Detected
190.107.244.151 - C+C
80.82.64.201 - C+C

ADDITIONAL DETAILS:
Our security analyst have been able to determine that there are at least 300+ host connected to the last indicator 36.79.171.47. We were able to pull in some additional data from our partners honeypots and network sensors to get a rough count of the activity level going to this system.

UPDATE: We are also seeing large numbers of connections to 80.82.64.201 as well. 

The system appears to be in Indonesia and is connected via cable modem. We are actively working with the ISP to see if they can provide any additional details.

UPDATES MOVED TO MAILING LIST

UPDATED 3-25-2014: Third US Health Entity Suspected of being Compromised

While we can't name any particular names at this time we have started seeing indicators of another related attack originating out of China aimed at US Healthcare entities. This time another well known affiliate of a previously breached healthcare entity appears to be attacking other Healthcare entities in California and Arizona.

Additional research is being done at this time but it appears as though a new malware variant is being sent via Phishing emails and they are coming from other healthcare entities so it appears as legitimate traffic which may be problematic as they may be assumed to be trusted entities.

The malware is being sent via email and is in zip, exe and also embedded HTML to infected flash websites. UPDATE: And now we are seeing PDF and word document with the same payload.

Updates will be posted here as we can obtain additional information. It appears as though one individual was also socially engineered to get malware inside an organization in Arizona. Additional reports are coming in from Utah and North Dakota as well.

Additional Details:
After researching we have noted that the botnet post from yesterday seems to be directly related to the compromised host.  - Additional IP's (Indicators) can be seen in this post.

After our report yesterday we also noted similar activity to what was seen prior to the Anthem, Community Health Systems and several University breaches we have been tracking.

If you run snort we have sent out the snort signatures (a total of 5 of them via our alert mailing list).

MOVED TO MAILING LIST - In addition another Intel provider may have already leaked the information this past week.... Have a good weekend everybody!

Apple Credential Phishing Attempts - As reported by MalwareBytes

We have been seeing many reports of Apple phishing schemes to include over 100 pages hosted at ovh.net. The scheme starts by emailing users purchase confirmations that look nearly identical to Apples legitimate purchase notifications but the links to cancel or verify the purchase lead to ovh.net and we have also noted xcelwings.com to be hosting similar content.

Ensure that you are verifying that you are connected to Apple to use secure pay or any of the other methods of purchase from the Apple store and be leary of any verification emails received. At a minimum verify that the domain is an actual Apple domain before proceeding.

Original Source: MalwareBytes
Additional Domain Indicator: SLC Security Services LLC

Researched by Analyst

Monday, March 23, 2015

BREACH: Berkeley Get's Whacked

Our OSINT monitoring is showing that a server at Berkeley has been compromised. Currently the site is reporting to be on IP 181.224.147.237 but indications show that problems started on the 19th of March. It's not a good time to be in the educational sector as sites are getting hit nearly daily.

Friday, March 13, 2015

Highmark - Related to Anthem Attack

More than 51,000 current Highmark health insurance customers in Pennsylvania will receive letters this week notifying them that their personal information may have been stolen as part of the larger Anthem Inc. data heist.

Those customers are in Highmark’s Western and Central Pennsylvania markets, 49 counties in all. “Letters are going out now,” spokesman Aaron Billger said.

What is interesting is that Highmark has been noted in Open Source feeds as having compromised systems in the past as well. This may have been part of the vectors used to gain access to Anthem and deserves a second look.

Sunday, February 22, 2015

Theory: Utilizing Porn Sites to Infect and Gain Access - Gov Connection or Bad Guys?

Over the course of the last few days we have been seeing a ton of traffic being exfiltrated to 101 Ave of the America's, 10th Floor (registrations in Whois and through some other utilities in our stack). When checking these host it appears as though they are mostly porn hosting and cloud computing computers. As we researched more we started finding certificates with strange references to legitimate Government organizations.

Would these people be so stupid to use real certificates on fake sites to collect data from suspects and users. In addition these same nodes are Tor exit nodes meaning that traffic on Tor could be sniffed as it exits the network.

A little more research is needed but it appears as though some of these host are being disquised albeit poorly to look like porn sites and other web servers when in fact their true purpose is not known. One IP that is sticking out in the ordeal is 37.139.6.7. This IP is showing up in all sorts of indicators and is also being picked up by multiple sensors on the Internet as Tor, Malicious, SSH Attacking, etc, etc.

Due to the nature of businesses being attacked from this IP and a few others that we are not currently disclosing it appears as though this is a concerted effort to get into the infrastructure of some heavy industry to include Healthcare, Communications Companies as well as Intelligence providers.

We will be keeping an eye on this and will let you know if anything changes as we are monitoring for any traffic to these host and alerting our SOC to review immediately.

Monday, February 9, 2015

FBI Online Agent Screenlocker

We have been seeing a ton of screen lockers lately. Just today one of our customer calls and states that they believe the FBI has locked out a machine. Upon inspection of course it's just a run of the mill screen locker claiming to be the FBI. I can tell you that the FBI would not tell you to go and get a moneypak to pay for unlocking your machine. In fact the FBI would just come and get the machine to perform forensics and be done with it.






When you see this message it is NOT the FBI. :-) Read r0cket's malware blog to learn how to remove the infection.

Interesting Routing Anamalies on the Internet

We are currently researching some really interesting routing anomalies on the Internet. It seems that not only is the Great Firewall of China doing some really interesting things to Chinese users but some really strange routing is taking place on the US east cost the past few days.

Could be coincidence but we don't think so. Funny how some of these sites are doing redirects to phishing sites as well. Tell me again why we allow China to have root servers again?!

And that's only half of it.

Friday, February 6, 2015

May just wanna disable flash until this situation becomes stable... Wait it's flash... Ugggghh

For the third time in two weeks, Adobe has issued an emergency security update for its Flash Player software to fix a dangerous zero-day vulnerability that hackers already are exploiting to launch drive-by download attacks.

Seriously consider disabling this until Adobe get's their issues resolved... You may be waiting awhile with this one.

IOC's for Digestion

Traffic to or from:
196.203.89.134
194.105.9.85


 



Tuesday, February 3, 2015

D-Link Router Vulnerability - CONFIRMED

D-Link’s popular DSL2740R wireless router is vulnerable to domain name system (DNS) hijacking exploits that requiring no authentication to access its administrative interface.

According to Todor Donev of the Belgian security firm Ethical Hacker, a number of other D-Link routers are affected by this bug as well, particularly the DLS-320B. PCWorld is reporting that the vulnerability exists in a widely deployed piece of router firmware called ZynOS, which is developed by ZuXEL Communications Corporation.

The troubling part of this issue is that it appears as though this and a few other bugs are allowing law enforcement to monitor the activities of individuals utilizing this hardware. We previously reported on similar vulnerabilities with Linksys hardware that allows similar interception without the end user being aware and allows Cisco to monitor customer usage of devices. For this reason we do not allow Cisco or Linksys hardware in our secured networking environment.

Monday, February 2, 2015

Hardware Hacking and Physical Attacks Largely Being Ignored

One of the recurring issues that we are seeing on audits are the lack of knowledge on physical attacks to infrastructure. Most of the companies we are working with do not check physical path of network connections as well as security systems. We have seen many companies that are either ignoring physical attacks or they feel as though they are not important. It should be noted that while your watching your network, attackers are building hardware, buying hardware and exploiting things such as your camera's, network security appliances, security systems, networks and communications systems such as telephone and hard wired infrastructure.

Find out today if hackers and bypass your defenses.  Email SLC Security Services LLC SOC and ask for a free no obligation security audit. The findings are confidential. Let us show you why our audits are the best in the industry.

Sunday, February 1, 2015

Malware: tinba is gonna be the end of Suntrust, Regions Bank and a few others... wait for it! (Dyre Banking Trojan) - Updated

If your monitoring infections and malware traffic it goes without saying that banking targets are high on the priority watch list. I'm making this prediction based on intelligence that we are seeing in the SOC. Let's see how this plays out.

My prediction is that the following banks are gonna get nailed by tinba:

1.Suntrust

2. Regions Bank

3. Credit One Bank

4. Netteller

5. TD Bank

6. JP Morgan Chase

7. PNC Bank

8. RBC Bank

Since this campaign is targeting customers there is little that the banks can do to stop it. Most of the issue is being caused by anonymous proxies and some very interesting MITM traffic.

Tuesday, January 27, 2015

NOTICE: Patch your Linux Servers

As you may have read in the media recently, a new zero-day security vulnerability for a common component in the Linux operating system has been released into the wild. This vulnerability allows attackers to remotely access some vulnerable Linux-based systems without the use of compromised passwords or other user credentials. Once in the system, attackers could leverage other vulnerabilities to escalate privileges until they gain root access. A good article that describes the vulnerability can be found here:

http://www.zdnet.com/article/critical-linux-security-hole-found/

We recommend that you immediately patch your operating system with the appropriate latest version. At the time of sending this e-mail (approximately at 7pm Central time on Tuesday, Jan. 27), the following Linux distributions have issued patches:

·      Red Hat
·      Debian
·      Ubuntu

Other popular distributions, such as CentOS, have indicated publicly that patches are in the works.

Since the vulnerable library is very common and is used by a wide range of server-side software, applying the patch is not without risk of collateral damage or side effects. In other words, there is some risk that patching your system might impact the performance of other applications on your server that also use the same library.

Nonetheless, taking into account the severity of the security hole, we are advising our clients to apply the patch immediately upon it becoming available to them. The risk of not patching outweighs the potential risk from side effects.

We strongly recommend that you patch your servers immediately with the appropriate patch.

If you are running Red Hat Enterprise Linux or CentOS, you may execute the following command on your server to patch:

CentOS/Red Hat Linux: yum -y update glibc
Ubuntu/Debian Linux: apt-get upgrade glibc

Please note that patching your system WILL require a restart after you execute the above commands.

Friday, January 23, 2015

ALERT: Whale Phishing Alert

The FBI and Internet Crime Complaint Center warns of a very profitable spam campaign that has already claimed more than 2,000 victims globally.
The FBI and the Internet Crime Complaint Center (IC3) are warning of a spam email campaign known as the Business E-mail Compromise (BEC) that has resulted in the global victim dollar loss of $215 million so far.

The IC3 alert, which was issued on Jan. 22, provides statistics on the impact of the BEC campaign for the period of Oct. 1, 2013, to Dec. 1, 2014. During that period, the IC3 received complaints about BEC from 45 countries, with a combined victim count of 2,126. In the United States alone, the IC3 said there were 1,198 victims.

Read More from the Original Report:
http://www.eweek.com/security/spam-campaign-business-e-mail-compromise-pilfers-215-million.html

Activity: Confirmed
Number of Confirmed Cases Reported: 3


The FBI and Internet Crime Complaint Center warns of a very profitable spam campaign that has already claimed more than 2,000 victims globally.

The FBI and the Internet Crime Complaint Center (IC3) are warning of a spam email campaign known as the Business E-mail Compromise (BEC) that has resulted in the global victim dollar loss of $215 million so far. The IC3 alert, which was issued on Jan. 22, provides statistics on the impact of the BEC campaign for the period of Oct. 1, 2013, to Dec. 1, 2014. During that period, the IC3 received complaints about BEC from 45 countries, with a combined victim count of 2,126. In the United States alone, the IC3 said there were 1,198 victims. - See more at: http://www.eweek.com/security/spam-campaign-business-e-mail-compromise-pilfers-215-million.html#sthash.DRlL878Z.dpuf

Thursday, January 22, 2015

Drones Being Used to Smuggle Drugs Over the Border

It goes without saying that Drones provide a unique way to take photographs, explore hard to reach areas and in this case to smuggle drugs across the US/Mexico border. Border Patrol has indicated that they are seeing increased instances of the use of drones to carry packages of drugs from Mexico into the US. There have been 3 separate news articles in the past week on the topic as well as some discussion in Government circles on how to combat the problem.

Drones have been used to smuggle phones, tobacco, drugs and weapons into prison courtyards in the past and are frequently used to carry out wireless attacks by moving devices into target areas for interception purposes.

The FAA has begun issuing licenses to licensed pilots to be allowed to operate drones for hire (highly restricted). It is thought that the rules on drone use will be relaxed at some point in 2015.

We are following this topic with interest.

Wednesday, January 21, 2015

ALERT: RSA Public Key has a backdoor

We are seeing indications that the RSA public key is compromised and has a backdoor. Several security researchers have confirmed through actual data that the key's are compromised but they have not indicated the responsible party.

Dell SecureWorks put out an alerts as did several bloggers over the past 2 weeks.