I've recently decided to come up with a proper analysis on a well known GCHQ URL shortening service used for monitoring purposes where the ultimate goal would be to provide additional insights into its Internet-connected infrastructure and try to find additional links and connections between related campaigns courtesy of the GCHQ
Sample URL known to have been involved in the campaign:
hxxp://lurl.me
Related domains known to have been involved in the campaign include:
hxxp://mhhiuag.com
hxxp://lhgeesp.biz
hxxp://ciwcesp.com
hxxp://lhgeesp.net
hxxp://ciwcesp.biz
Sample related responding IPs known to have been involved in the campaign include:
hxxp://198.105.254.11
hxxp://37.220.34.116
hxxp://109.235.48.3
hxxp://64.74.223.47
hxxp://198.105.244.11
Sample screenshots include:
No comments:
Post a Comment