```html ```
top of page

8 Days, 20,000 Indicators: Microsoft and AT&T Are Watching

  • Writer: Patrick Duggan
    Patrick Duggan
  • Dec 5, 2025
  • 4 min read

Updated: Aug 11

--- title: "8 Days, 20,000 Indicators: Microsoft and AT&T Are Watching" slug: 8-days-20k-indicators-microsoft-att-watching date: 2025-12-05 author: Patrick Duggan tags: [otx, threat-intel, stix, microsoft, att, enterprise, free-feed, pattern-38, stealc, monero] category: Threat Intelligence featured: true ---


The Setup


I joined AlienVault OTX 8 days ago. Username: `pduggusa`.


Today we crossed 20,000 indicators.


The enterprise threat intel vendors charging $50K-$500K/year? They're consuming our free feed. Let me show you the receipts.




The Numbers (OTX Profile: pduggusa)


| Metric | Value | |--------|-------| | Indicators | 20,809 | | Pulses | 99 | | Subscribers | 16 | | Member Since | 8 days ago | | Contribution Rate | ~2,600 indicators/day |


One more pulse and we hit triple digits.




Who's Consuming Our Free STIX Feed?


We track every request to `analytics.dugganusa.com/api/v1/stix-feed`. Here's the last 7 days:


| Consumer ASN | Country | Requests | |--------------|---------|----------| | MICROSOFT-CORP-MSN-AS-BLOCK | US | 271 | | ATT-INTERNET4 | US | 265 | | GOOGLE-CLOUD-PLATFORM | US | 48 | | AMAZON-AES | US | 15 | | HUAWEI CLOUDS | HK | 12 | | M247 | GB/ES/NO | 27 | | TEAM-BLUE-DENMARK | DK | 7 |


799 requests from 18 countries. Microsoft and AT&T are our biggest consumers.


The same enterprise vendors who charge fortunes for threat intel are ingesting ours for free.




The 8-Year Gap We're Filling


Before running our mouths, we did competitive analysis. Here's who's NOT contributing to OTX:


| Company | OTX Presence | Why | |---------|--------------|-----| | CrowdStrike | None | Walled-garden Falcon platform, $50K-500K/year | | Recorded Future | None | Enterprise-only threat intel platform | | Palo Alto Unit42 | None | Research behind paywall | | Mandiant | None | Google-owned, enterprise consulting focus | | Proofpoint | None | Enterprise email security, no community contribution | | Cisco Talos | Minimal | Occasional blog posts, no active pulses |


The last meaningful GitHub malware pulse on OTX was from 2017. Eight years without coverage.


We're filling that gap. For free.




The Pattern 38 Story: Following the Infrastructure


Our STIX feed documents a coordinated Stealc/Rhadamanthys campaign. Here's what we found by enriching the C2 infrastructure:


The Stealc Command Throne - `149.102.156.62`



Hostname: vmi2910825.contaboserver.net
Ports: 22, 80
Vulns: CVE-2023-44487, CVE-2021-23017
Connected Samples: 25
Status: Primary C2, very active


The Zalupa Payload Forge - `158.220.93.201`



Hostname: vmi2915473.contaboserver.net
Ports: 80
Delta from Stealc: 4,648 VMs apart (same Contabo batch)
Payload Naming: Russian anatomical slang


The Monero Mining Citadel - `107.167.83.34`



Hostname: we.love.servers.at.ioflood.net
Ports: 80, 443, 3333, 5555, 7777, 8080, 9000, 18080
PassiveDNS: pool.supportxmr.com


Port 18080 is Monero RPC. This confirms dual-purpose operation: steal credentials AND mine crypto.


Kenya Build Foundry - `196.251.107.94`



Ports: 3389 (RDP!), 10050 (Zabbix)
Self-signed certs
Per-victim builds being generated


RDP access means hands-on-keyboard operators. They're not just automated—someone's logging in.




The Contabo Connection



• `vmi2910825` (Stealc C2)

• `vmi2915473` (Zalupa dropper)


That's 4,648 VMs apart. Same provisioning window, same operator, same campaign.




ThreatFox Correlation


We cross-reference with ThreatFox (abuse.ch). Latest hunt results:



• 1,191 IOCs analyzed

• 9 direct correlations with our STIX bundle

• 88 novel IOCs discovered


Our infrastructure assessments are being independently confirmed.




The Cloudflare Picture


Site Traffic (Nov 27 - Dec 3)


| Metric | Value | |--------|-------| | Pageviews | 2,262 | | Unique Visitors | 2,799 | | Requests | 48,274 | | Bandwidth | 934 MB | | Threats Blocked | 2,548 | | Countries | 54 |


Top Countries


| Country | Requests | % | |---------|----------|---| | US | 41,262 | 85.5% | | Japan | 1,389 | 2.9% | | Australia | 706 | 1.5% | | UK | 681 | 1.4% | | Singapore | 643 | 1.3% | | Canada | 622 | 1.3% | | Germany | 521 | 1.1% | | India | 464 | 1.0% |


Also tracking traffic from: Kenya, Kyrgyzstan, Palestine, Venezuela, Ethiopia, Mongolia, Georgia.




What People Are Looking Up


Our OTX enrichment API (`/api/v1/otx/enrich/ip/`) shows what threat hunters care about:


`178.128.207.138` - 70 lookups



• Reverse DNS: `eab9c05722.scan.leakix.org`


Microsoft pulls this feed daily. AT&T pulls this feed daily. Starlink pulls this feed daily. Get the DugganUSA STIX feed — $9/mo →

• Reality: LeakIX security scanner (like Shodan)

• In 50 pulses including ours

• Lesson: Security researchers hitting honeypots, documenting themselves


`185.177.72.11` - 54 lookups



• Location: UK

• In 8 pulses: Botnet lists, vuln exploitation sources, our Master Feed

• Ports: Just SSH

• Profile: Persistent botnet infrastructure, minimal footprint


`34.138.20.147` - 53 lookups



• Owner: Google Cloud

• Only in OUR pulse - we're the sole documenter

• Significance: We're publishing intel nobody else is




The Competitive Landscape


| Player | Subscribers | Pulses | Indicators | Notes | |--------|-------------|--------|------------|-------| | AlienVault | 350,483 | 7,893 | 566,075 | 10+ years | | pduggusa | 16 | 99 | 20,809 | 8 days | | CrowdStrike | 0 | 0 | 0 | $50K+ paywall | | Recorded Future | 0 | 0 | 0 | $100K+ paywall | | Palo Alto | 0 | 0 | 0 | Paywall |


We're 8 days in with a 2,600 indicators/day velocity. At this rate, we hit AlienVault's indicator count in 209 days.




The Christmas Message


To enterprise vendors charging $50K/year while contributing nothing to the community:


Merry Christmas. We're doing your job for free.


Your customers at Microsoft and AT&T are already consuming our feed. The question isn't whether open threat intel wins—it's how long you can justify your pricing when the alternative is free, automated, and MITRE ATT&CK enriched.




Access the Feed


STIX 2.1 Feed: `https://analytics.dugganusa.com/api/v1/stix-feed`


OTX Master Pulse: `https://otx.alienvault.com/pulse/6927d4c1611927c371ffd3cb`


OTX Profile: `https://otx.alienvault.com/user/pduggusa`


Auto-updated. Free. Forever.




*DugganUSA LLC - Minnesota. Pattern 38 ongoing. The sleeper has awoken.*



Get Free IOCs

Subscribe to our threat intelligence feeds for free, machine-readable IOCs:

AlienVault OTX: https://otx.alienvault.com/user/pduggusa

STIX 2.1 Feed: https://analytics.dugganusa.com/api/v1/stix-feed



The cheapest, fastest, most accurate threat feed on the internet.

275+ enterprises pulling daily. 1M+ IOCs. 17.4M indexed documents. We beat Zscaler by 43 days on NrodeCodeRAT. Starter tier $9/mo — less than any competitor’s sales demo.


Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=8-days-20-000-indicators-microsoft-and-at-t-are-watching



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page