Aug. 25, 2023, 3:46 p.m. | zapbroob

System Weakness - Medium systemweakness.com

SOC141 EventID:86 — Phishing URL Detected — letsdefend.io

Let’s start with examining alert report.

 
EventID :86
Event Time :Mar, 22, 2021, 09:23 PM
Rule :SOC141 - Phishing URL Detected
Level :Security Analyst
Source Address :172.16.17.49
Source Hostname :EmilyComp
Destination Address :91.189.114.8
Destination Hostname :mogagrocol.ru
Username :ellie
Request URL :http://mogagrocol.ru/wp-content/plugins/akismet/fv/index.php?email=ellie@letsdefend.io
User Agent :Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36
Device Action :Allowed

According to the alert, the source IP address 172.16.17.49 is associated with the hostname …

blue team incident response letsdefendio phishing soc

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC