notracking/hosts-blocklists

gluvoob.com - suggestion to be added to blacklist

lucamosca1 opened this issue · 2 comments

Hi there! Today we've been warned by AWS GuardDuty that one of our internal dns tried to resolve this harmful domain

What specifically is malicious about this domain?

GuardDuty details says: EC2 instance i-XXX is querying a domain name associated with a known Command & Control server.

Evidence: Threat intelligence details
Threat IP list
CrowdStrike
Threat names
PdfCaptchaLure21