Healthcare IoC Expansion and EHR Vendor Spoofing Detection | WhoisXML API

Threat Reports

Beyond Healthcare IoCs: Threat Expansion and EHR Impersonation Detection

Cuba ransomware is only one of the threats the healthcare industry faces as the Internet of Medical Things (IoMT)1 continues to expand.

To aid the sector, WhoisXML API looked at Cuba ransomware IoCs2, 3 to enable threat contextualization and expansion. The researchers  also investigated how the top EHR software providers4 were being spoofed in the DNS as part of third-party risk assessment. Among our key findings are:

  • 90+ Cuba ransomware IoCs that led to 1,700+ artifacts that shared their IP hosts, name servers, and registrant details
  • 9% of these artifacts were already flagged as malicious
  • 1,700+ cybersquatting domains containing the names of the top EHR software providers, only 1% of which could be publicly attributed to the legitimate companies

Download a sample of the threat research materials now or contact us to access the complete set of research materials.

  • [1] https://www.armis.com/blog/chapter-8-how-to-spot-the-top-indicators-of-compromise-in-healthcare/ 
  • [2] https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-335a
  • [3] https://otx.alienvault.com/pulse/63aa973b66bd186912d90650 
  • [4] https://www.forbes.com/advisor/business/software/best-ehr-software/
Try our WhoisXML API for free
Get started