Own a Facebook Business? Beware of Ducktail | WhoisXML API

Threat reports

Own a Facebook Business? Beware of Ducktail

WithSecurity recently discovered malicious operation Ducktail targeting businesses that maintain Facebook pages and engage in Facebook advertising.1 Their report identified 1,885 indicators of compromise (IoCs).2

WhoisXML API researchers analyzed 1,747 of the publicized IoCs (1,739 email addresses and eight domains) as investigation jump-off points that led to the following findings:

  • Only 429 of the email addresses identified as IoCs were valid.
  • Only one of the IoCs currently resolved to an IP address—ductai[.]xyz pointed to 58[.]158[.]177[.]102.
  • At least 300 other domains shared ductai[.]xyz’s IP host, 27 of which were malicious.
  • A total of 170 domains contained the string “ductai” akin to two IoCs.

Download a sample of the threat research materials now or contact us to access the complete set of research materials.

  • [1] https://labs.withsecure.com/content/dam/labs/docs/WithSecure_Research_DUCKTAIL.pdf
  • [2] https://github.com/WithSecureLabs/iocs/blob/master/DUCKTAIL/iocs.csv
Try our WhoisXML API for free
Get started