âJustJoinâ Landing Page Linked to Suspected DPRK Activity Resurfaces
ID: 5962d715-4e0c-5f61-8e5e-67d620b74487
STIX ID: report--5962d715-4e0c-5f61-8e5e-67d620b74487
Feed Name: Hunt.io Blog
Hunt researchers identified a cluster of Hostwinds-hosted servers and domains resolving to IPs (notably 23.254.167.216, 108.174.194.44, and 108.174.194.196) serving a 'JustJoin' landing page linked to TA444/BlueNoroff activity; the analysis highlights domain naming tricks (hex-encoded IP), shared SSH fingerprints across servers, and associated domains that may support phishing or malware delivery. The report provides observables (IPs, domains, hosting AS) and defensive recommendations to monitor HTML hashes and block suspicious domains/IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
