IOC extraction logic has flaw when producing this domain, it was indiacode[.]nic[.]in[.]admin-mcas[.]ms in original post, so subdomain truncation is likely introduce false positive.
Fix
I think it is better to remove the subdomain truncation when extracting domain from public post. e.g. we should only produce
Describe the bug "admin-mcas.ms" was listed in https://github.com/stamparm/maltrail/blob/master/trails/static/malware/apt_transparenttribe.txt#L2151, this is a white domain owned by microsoft, reference: https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-url
IOC extraction logic has flaw when producing this domain, it was indiacode[.]nic[.]in[.]admin-mcas[.]ms in original post, so subdomain truncation is likely introduce false positive.
Fix I think it is better to remove the subdomain truncation when extracting domain from public post. e.g. we should only produce
instead of: