CISA mixup of IOC domains
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我得仔细阅读文章内容,理解主要信息。 文章主要讲的是CISA在报告中发布的IOCs有问题,比如域名拼写错误。GTIG和Mandiant的报告发现这些IOCs和中国黑客有关,而CISA原本是针对俄罗斯的。这可能是因为CISA在发布时出现了混淆或者打字错误。 接下来,我需要提取关键点:CISA报告中的IOCs与GTIG报告有重叠,但可能存在拼写错误;特别是两个域名的例子,“accesscan.org”和“glize.com”可能是误写。此外,GTIG报告中的相关域名属于Dynu Systems,常被恶意使用。 然后,我要把这些信息浓缩到100字以内,确保涵盖主要问题:CISA IOC混淆、拼写错误、涉及不同威胁组织以及域名归属情况。 最后,检查语言是否简洁明了,没有使用复杂的术语,并且符合用户的要求。 </think> CISA报告中提到的IOC域名与GTIG报告存在重叠,但部分域名疑似拼写错误,例如"accesscan.org"与"accesscam.org","glize.com"可能来自误写。GTIG报告中的相关域名属于Dynu Systems,常被恶意利用,而CISA提及的某些域名则为合法网站。 2026-2-26 09:35:0 Author: www.netresec.com(查看原文) 阅读量:11 收藏

Thursday, 26 February 2026 09:35:00 (UTC/GMT)


CISA mixup of IOC domains

Google's Threat Intelligence Group (GTIG) and Mandiant's recent Disrupting the GRIDTIDE Global Cyber Espionage Campaign report is great and it has lots of good Indicators of Compromise (IOC). Many of these IOCs had already been shared by CISA in May last year as part of their Alert AA25-141A titled "Russian GRU Targeting Western Logistics Entities and Technology Companies". The IOC overlap between these two reports is surprisingly big, provided that the GTIG report covers a Chinese espionage group while the CISA report covers the Russian GRU unit 26165 (aka APT28 / Fancy Bear).

But some of the domain names in CISA's report from last year seemed strange. For example, the domain name "accesscan[.]org" doesn't seem to ever have been registered. The GTIG report, however, contains the very similar domain "accesscam[.]org". This accesscam domain is registered to the dynamic DNS provider Dynu Systems, whose services are often abused by malicious actors. Is it possible that there are typos in the IOCs published by CISA? I think so.

accesscan glize spelling mistakes

Another odd domain in CISA's AA25-141A is "glize[.]com", which I suspect is a typo from either "giize[.]com" or "gleeze[.]com". The two latter domains are listed in the GTIG report and both of them also belong to the dynamic DNS provider Dynu Systems. The domain listed in CISA's alert, on the other hand, appears to be a legit website (archived page from 2024) from the marketing company Glize in Malta.

Screenshot of Glize's website from 2024

Glize's website seems to have disappeared sometime in 2025.

Posted by Erik Hjelmvik on Thursday, 26 February 2026 09:35:00 (UTC/GMT)

Tags: #IOC

Short URL: https://netresec.com/?b=26233f4


文章来源: https://www.netresec.com/?page=Blog&month=2026-02&post=CISA-mixup-of-IOC-domains
如有侵权请联系:admin#unsafe.sh