Beaconing Leads To Swarft Trojan & Suspicious Netblock
ID: a6198d81-4716-5751-abee-3e18dff631f2
STIX ID: report--a6198d81-4716-5751-abee-3e18dff631f2
Feed Name: Zscaler Security Research Blog
Threat Score
Observed hosts are beaconing every five minutes to 216.108.234.168/scr1p7-r5.php with large POST payloads (~20KB) and minimal responses, behavior consistent with a keylogger/ data-exfiltration drop site. Open-source correlation links the URL pattern to the Swarft banking Trojan; the hosting netblock and customer details are identified as suspicious and listed in some blocklists, and organizations are advised to block/alert on the IOC and investigate impacted hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
