Advice Request any one ever got Lucky elephant malware from siem?

Please provide comments and solutions that are helpful to the author of this topic.

rhyzoptera

New Member
Thread author
May 14, 2020
3
Hi good people!
Im using alienvault siem and i always get this alert OTX Pulse: Lucky Elephant Campaign Masquerading and it always detected in payload a malicious domain ss.userscontent.com

i already did mitigation blocking domain, blocking port dest and install ads block in the detected asset (i found a log that contain this lucky elephant domain has something to do with ads banner or something) and already scan using malwarebytes but never find any threat. Yet this alarm still appear in siem.

I really need some advice to get rid of this alarm

thanks
 
  • Like
Reactions: [correlate]

Learning

New Member
May 17, 2020
1
What's the device?

Have you tried removing ads from your device (phone / laptop)?
Clear all chace Browser on ur device (chrome, firefox, ie, etc)

Try to Update ur Browser dude or Re-Install and also the OS
 
  • Like
Reactions: [correlate]

rhyzoptera

New Member
Thread author
May 14, 2020
3
What's the device?

Have you tried removing ads from your device (phone / laptop)?
Clear all chace Browser on ur device (chrome, firefox, ie, etc)

Try to Update ur Browser dude or Re-Install and also the OS
the device is windows laptop,
anyway we already figure it out and all the domain already blocked, now when we got alert from lucky elephant its noted in raw log that the domain is redirect to our fortinet IP
1590573260583.png
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top