Skip to content

New hostnames / usernames checked for by malware #227

@recvfrom

Description

@recvfrom

New hostname / username that we could add to the known_usernames and known_hostnames checks:

Hostnames checked for by OSTap [1]

VBOX7-PC
JANUSZ-PC
ABBY-PC
DESKTOP-HRW10
AMAZING-LINGON
SANDBOX-O365

Usernames checked for by OSTap [1]

Aimy
fred
Brad

[1] https://twitter.com/GossiTheDog/status/1357019072534355970 (or see https://gist.github.com/kirk-sayre-work/82cdc8f8faba929259bacb8ecea22162)

From ObliqueRAT [2], blocklisted keywords for username and computer name:

15pb
7man2
stella
f4kh9od
willcarter
biluta
ehwalker
hong lee /* Already covered */
joe cage
jonathan
kindsight
malware
peter miller
petermiller
phil
rapit
r0b0t
cuckoo
vm-pc
analyze
roslyn
vince
test
sample
mcafee
vmscan
mallab
abby
elvis
wilbert
joe smith
hanspeter
johnson
placehole
tequila
paggy sue
klone
oliver
stevens
ieuser
virlab
beginer
beginner
markos
semims
gregory
tom-pc
will carter
angelica
eric johns
john ca
lebron james
rats-pc
robot
serena
sofynia
straz
bea-ch

[2] https://blog.talosintelligence.com/2021/02/obliquerat-new-campaign.html

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions