-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Open
Labels
Description
New hostname / username that we could add to the known_usernames
and known_hostnames
checks:
Hostnames checked for by OSTap [1]
VBOX7-PC
JANUSZ-PC
ABBY-PC
DESKTOP-HRW10
AMAZING-LINGON
SANDBOX-O365
Usernames checked for by OSTap [1]
Aimy
fred
Brad
[1] https://twitter.com/GossiTheDog/status/1357019072534355970 (or see https://gist.github.com/kirk-sayre-work/82cdc8f8faba929259bacb8ecea22162)
From ObliqueRAT [2], blocklisted keywords for username and computer name:
15pb
7man2
stella
f4kh9od
willcarter
biluta
ehwalker
hong lee /* Already covered */
joe cage
jonathan
kindsight
malware
peter miller
petermiller
phil
rapit
r0b0t
cuckoo
vm-pc
analyze
roslyn
vince
test
sample
mcafee
vmscan
mallab
abby
elvis
wilbert
joe smith
hanspeter
johnson
placehole
tequila
paggy sue
klone
oliver
stevens
ieuser
virlab
beginer
beginner
markos
semims
gregory
tom-pc
will carter
angelica
eric johns
john ca
lebron james
rats-pc
robot
serena
sofynia
straz
bea-ch
[2] https://blog.talosintelligence.com/2021/02/obliquerat-new-campaign.html