Security Pulse Round-Up 01/02/2021

A weekly round-up of security pulses created by the BIT Security team.

Phishing attempt Link connection to sites

A spoofed email address attempted to deploy malicious trojans and other malicious files, using sites.

C2 server IoC's

IoC's found when exploring This is a known C2 domain. This IP was originally taken from an existing sunburst pulse Explored using virus total.

Emotet dropping domains

IOC's extracted from and using virus total. These domains drop .doc files with malicious macros that appear to download Emotet These two domains were analyzed using virus total. The domains themselves were taken from the November 03 2020 malware domain feed v2.

