Threat Reports

Read other reports

Own a Facebook Business? Beware of Ducktail

WithSecurity recently discovered malicious operation Ducktail targeting businesses that maintain Facebook pages and engage in Facebook advertising.1 Their report identified 1,885 indicators of compromise (IoCs).2

WhoisXML API researchers analyzed 1,747 of the publicized IoCs (1,739 email addresses and eight domains) as investigation jump-off points that led to the following findings:

  • Only 429 of the email addresses identified as IoCs were valid.
  • Only one of the IoCs currently resolved to an IP address—ductai[.]xyz pointed to 58[.]158[.]177[.]102.
  • At least 300 other domains shared ductai[.]xyz’s IP host, 27 of which were malicious.
  • A total of 170 domains contained the string “ductai” akin to two IoCs.

Download a sample of the threat research materials now or contact us to access the complete set of research materials.

  • [1] https://labs.withsecure.com/content/dam/labs/docs/WithSecure_Research_DUCKTAIL.pdf
  • [2] https://github.com/WithSecureLabs/iocs/blob/master/DUCKTAIL/iocs.csv

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.