DESCRIPTION LAST UPDATED: 2023-12-07
DEFAULT SEVERITY LEVEL: CRITICAL
This report identifies the IP addresses of all the devices that were reported to Shadowserver from Microsoft after communicating with Microsoft non-HTTP sinkhole servers. Sinkholing is a technique whereby a resource used by malicious actors to control malware is taken over and redirected to a benign listener that can (to a varying degree) understand connections coming from infected devices.
Only infected systems or security researchers should be seen in this list.
Report format is the same as Sinkhole Events Report
You can learn more on the report in our Sinkhole Events Report tutorial.
Severity levels are described here.
You can learn more on our reports in general in our Overview of Free Public Benefit Shadowserver Reports presentation, which also explains example Use Cases.
File names: event4_microsoft_sinkhole