logo

GreyNoise Labs Weekly OAST (Well-known Out-of-band Interaction Domains) Report • Week Ending 2026-02-13

ID: 0f968358-2c45-5284-8709-8b4c325de68c

STIX ID: report--0f968358-2c45-5284-8709-8b4c325de68c

Feed Name: GreyNoise Labs

Threat Score
72/100

Date Published: 2026-02-15

Date Updated: 2026-04-27

Author: 🔮Orbie✨

...
...

This report analyzes a multi-campaign, large-scale automated scanning operation that injected Interactsh OAST domains across numerous HTTP vectors and actively probed/exploited hundreds to thousands of hosts (notably CVE-2026-1281 Ivanti EPMM). Analysts cluster activity into distinct infrastructure groups (Cloudflare-proxied, Oracle Cloud, Private Layer, PROSPERO bulletproof hosting, Vietnamese/Estonian nodes, Tor exits) using JA4T/JA4H/JA3 fingerprints, enumerate primary IPs and OAST domains, and provide detection rules and prioritized mitigations including blocking specific ASNs/IPs, monitoring OAST domains, and patching targeted CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.