Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
2026-08-25T19:23:42Z•656c51e3fd976e501ac09f3b0bc836bd68e8333997ed93c89a8d7d2ac08a8e15
169.254.169.254DOUBLECUPMFAMicrosoft Entra IDMicrosoft GraphPNG payloadPowerShellSSRFURL filtering bypasscloud identity monitoringcloud metadata servicehostname obfuscationpassword sprayingrisky sign-insstale accountssteganography
What happened
SANS Internet Storm Center entries covering SSRF attempts against the cloud metadata service and evasion by representing 169.254.169.254 as a hostname, DOUBLECUP PNG-based payload delivery, and Microsoft Entra/M365 security administration topics including MFA coverage, Graph API automation, risky logins, password spraying, stale accounts, and license discovery. The material is primarily defensive guidance and threat awareness; no specific vulnerability identifiers are provided.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 656c51e3fd976e501ac09f3b0bc836bd68e8333997ed93c89a8d7d2ac08a8e15
- Enrichment time
- 2026-08-25T19:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.