#opendir: aitelong[.]top/amadi/
contents: .exe and .hta
malware: #lokibot#pony
For this episode of "chose your malware", I offer a wide range of files.
@James_inthe_box
Second stage dropper hosted on: pomf.pyonpyon[.]moe/befqki.doc
Find different payload on #opendir: irishlebanese[.]com/wp-admin/images/eight/
It's seen like files aren't on Virus Total, yet.
@malwrhunterteam@ViriBack
Today the presentation of my POC: a solution who collect and identify threats
✓ scalable solution
✓ automatically collect links
✓ identify the threat
✓ design a "user friendly" interface
Thank to @benkow_ and @ViriBack for them great job who help me for identification
Amazing PO_.doc: RTF
HASH: d6122adcf1bc34f293fed334d928f25dda5a76e53226c89a7bdb4c869c734ec8
It's NOT a dropper but an "all inclusive package" with all what he needs
Behavior: #Ransomware + #Persistance
Request: test1[.]ru/newbuild/t.php (may be a test ?)
@malwrhunterteam
Website compromised: mcts-qatar[.]com
Url used for delivering payload: mcts-qatar[.]com/wp-content/plugins/de6.exe
Well, it's not your first time: urlhaus.abuse.ch/host/mcts-qata… …
May be it's time to upgrade your Wordpress extensions or you deliberately host malware?
Wave of office document.
mimetype: RTF
Dropper use CVE-2017-11882 with eqnedt32.exe
Domain with payload: b.reich[.]io (/jsdrjs.exe or /kdhqfz.png)
Paypload: Password Stealer #lokibot
Panel: detini.nut[.]cc
cc @ViriBack@malwrhunterteam
868 Followers 2K FollowingReader in the Serbian Orthodox Church, but not ethnically Serbian. Trying to love Christ and my neighbor. ☦️ 🇷🇸 Programmer and InfoSec guy for fun and profit.
4 Followers 206 FollowingI personally love Alta, shopping, and reading. Reading books by Jodi Pacult are my favorite. I also enjoy working as a paralegal in Jacksonville.
48K Followers 1 FollowingA fast, trustworthy, and easy-to-use VPN is a good first step toward reclaiming your privacy. Just €5/month.
// Need help? Email [email protected]
1K Followers 1 FollowingThis bot provides intel related to DNS updates from cybercriminal websites, Ransomware claims, cyberattacks in the news, Whiteintel corp exposed creds and more!
132K Followers 57 FollowingProviding intel from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threats, Crypto & more. Follow X Bot: @DarkWebIntelBot. https://t.co/Fi7VW9lg94
590 Followers 154 FollowingRed Team / Offensive Security, Cameo in @StrawHat_CTF for pentest. Web Security / Windows / Active Directory / Post Exploitation
8K Followers 150 FollowingFor contact in the security community. NOTE: All the tweets are totally my personal opinions, not about any of my current employer stuff.
18K Followers 222 FollowingAnda boleh melakukan segala-galanya dari syurga ke bumi, wanita kecil!!
If you have any questions, please contact me
https://t.co/MkzsavUU9V
20K Followers 271 FollowingOffensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
5K Followers 265 FollowingPassionate about Total Security Management offering the very best in Ethical Hacking, Education & Training, Governance, Risk, & Compliance, and Managed Services
26K Followers 1K FollowingSenior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
No recent Favorites. New Favorites will appear here.