stamparm / maltrail

Malicious traffic detection system
MIT License
6.6k stars 1.09k forks source link

Bad domains #19259

Closed jjwrolstad closed 5 months ago

jjwrolstad commented 6 months ago

Describe the bug The source https://www.cyberresilience.com/threatonomics/resilience-threat-researchers-identify-new-campaigns-from-scattered-spider/

These domains should not be present: powerdms.com, polaris.me, docusign.net

How To Reproduce Link: https://github.com/stamparm/maltrail/blob/master/trails/static/malware/0ktapus.txt

Expected behavior A clear and concise description of what you expected to happen.

Screenshots If applicable, add screenshots to help explain your problem.

Environment:

Additional context Add any other context about the problem here.

MikhailKasimov commented 6 months ago

Hello!

Fixed: https://github.com/stamparm/maltrail/commit/916ce06a90227a0f3ab4629aa101417effcc0b47 Whitelisted: https://github.com/stamparm/maltrail/commit/249d61e6500045defcc61e4876c87a80cf7c03bd

Thank you for alerting!

MikhailKasimov commented 5 months ago

Considering as resolved.