Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
tamaral
Employee
Employee

Malicius file download and lateral movement detected over Quantum gateway data

Hi guys, 
See the brief below, showcasing additional detections and correlations over Quantum Gateway used to stop lateral movement using a malicious script.

0 Kudos
4 Replies
the_rock
Legend
Legend

Interesting...I checked both external IPs you listed and first one was not found at all in below database and 2nd one says about 12500 times.

Andy

AbuseIPDB - IP address abuse reports - Making the Internet safer, one IP at a time

0 Kudos
tamaral
Employee
Employee

Actually, now they are both reported in Abuse, but not sure it was the case at the time, 

 

87.121.84.37 - 100% confidence

193.32.162.27 - 26% confidence

Thanks for replaying, Andy!! 

0 Kudos
the_rock
Legend
Legend

Kind of odd when I checked 15 mins ago, was clean, showing Italy and now shows Netherlands, 100% confidence lol

Anyway, thanks for checking!

Andy

0 Kudos
the_rock
Legend
Legend

Thanks again for looking into it, appears its listed below as well.

Cheers,

Andy

https://www.apivoid.com/tools/ip-reputation-check/

0 Kudos
Upcoming Events

    CheckMates Events