Threat Reports

Read other reports

SocGholish IoCs and Artifacts: Tricking Users to Download Malware

SocGholish, an initial-access threat, was recently observed deploying ransomware, according to ReliaQuest researchers.1

WhoisXML API used the indicators of compromise (IoCs) published by ReliaQuest to understand the threat’s infrastructure and uncover more artifacts. Our research revealed:

  • From six IoCs, an unredacted registrant email address was found
  • 200+ artifacts registered by the same person behind an IoC
  • 50+ additional artifacts related to the IoCs either through name server or string usage
  • Malicious web properties, accounting for more than 5% of the artifacts

Download a sample of the threat research materials now or contact us to access the complete set of research materials.

  • [1] https://www.reliaquest.com/blog/socgholish-fakeupdates/

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.

Contact Us

White Paper Download

Please complete the form below to download the required file:

Your business email will be validated while the request is being processed. This may take time.