Vendor
high
advisory
Windows Hosts Querying Abused Web Services
2 rules 1 TTP 33 IOCsSuspicious processes on Windows hosts are making DNS queries to known, abused web services such as text-paste sites, file sharing platforms, and tunneling services, potentially indicating malware downloading or command and control activity.
Microsoft Windows +4
abused-web-services
command-and-control
windows
2r
1t
33i
medium
advisory
Windows Hosts Querying Abused Web Services
2 rules 1 TTP 34 IOCsAdversaries may use abused web services such as paste sites, VoIP, and file hosting to host malicious payloads or facilitate command and control, detected via DNS queries from Windows hosts to these services.
githubusercontent.com +34
abused-web-service
command-and-control
initial-access
windows
2r
1t
34i