You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ope...@googlegroups.com
Fixed and sanitized the links in the first section (obviously the links in the ioc file are still dangerous)
OR Network DNS contains msecure<dot>ru Port Remote IP is 198.162.116.16 Port Remote IP is 93.186.171.133 Network DNS contains proscitomash<dot>com Network DNS contains quliner<dot>ru File MD5 is 91B64502A89D6C47D1ADBDE3EBBF
And
the last IP comes from the malwarebytes blog entry - it's the IP
infected clients are redirected to when they try to access certain
security sites.
As always, no warranties implied and comments,
suggestions welcome. For some reason I still can't attach files, so
here's the IOC pasted below.