Website
*.blob.core.windows.net
Tags
Phishing Download Exfiltration
Phishing
Attackers have the ability to choose a customized subdomain on blob.core.windows.net for blob storage. Attackers abuse this functionality by hosting .html files using the blob.core.windows.net subdomain and therefore creating fake login pages that capture credentials.
Command and Control
None
Exfiltration
Attackers can upload exfiltrated data onto applications hosted on *.blob.core.windows.net
Download
Malicious tools can be stored on *.blob.core.windows.net and downloaded when required.
Service Provider
Microsoft
Created: 2021-11-10
Last Update: 2021-11-10
Credits: mr.d0x