GreyNoise Labs Weekly OAST (Well-known Out-of-band Interaction Domains) Report • Week Ending 2026-01-24
ID: 33f553e0-c68f-5572-a044-9c16fd1e3e6a
STIX ID: report--33f553e0-c68f-5572-a044-9c16fd1e3e6a
Feed Name: GreyNoise Labs
GreyNoise observed a seven-day, high-volume scanning campaign (9,004 sessions, 313 source IPs) that embedded Interactsh OAST callback domains in exploit payloads to detect successful remote code execution and redirect vulnerabilities — primarily targeting Spring Cloud Gateway code injection and Keycloak open-redirect (CVE-2024-8883). The activity features an anomalous TCP MSS fingerprint (65495) indicating custom tooling, 5,171 decoded OAST domains across 425 campaign identifiers, heavy concentration in VPS/bulletproof ASNs (notably AS9009 / 146.70.116.218), and actionable IOCs and detection recommendations for network and JA4-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
