Axel F

30 posts

Axel F

Axel F

@Axel_F5

computer security

Katılım Nisan 2010
55 Takip Edilen127 Takipçiler
Axel F
Axel F@Axel_F5·
this is an old C2 that was also used in 2023-01-26 sample 34104f2ee58f629d7222cce339a24db5. However its still active and Bitter has been recently using other, even older C2's
English
0
0
0
163
Axel F
Axel F@Axel_F5·
#Bitter #APT #CHM 410ef267cd56b74c6a7578947efb3b66 Upgradation of Systems Document.chm wbfashionshow[.]com
Axel F tweet media
English
1
1
5
976
Axel F
Axel F@Axel_F5·
Another #Spyder from #Sidewinder #APT - Md5 930f288c9f9ed516f7eaec8f1ccbfc02 hxxp[:]//libreofficeupdates[.]com/drive/files.php hxxp[:]//libreofficeupdates[.]com/drive/includes.php
Axel F tweet mediaAxel F tweet media
English
0
14
26
3.5K
Axel F
Axel F@Axel_F5·
HTML cred phish for #India gov email portal. #APT 488ddfb1fec1408ecf7e9464246374c3 "letter dt 20.06.2023" > hxxp[:]//samedaywalkintub[.]ca/mail.gov.in/
Axel F tweet mediaAxel F tweet mediaAxel F tweet media
English
0
1
8
1.2K
Axel F
Axel F@Axel_F5·
quick look: (a) network traffic is similar including data and headers (b) many same strings in binary, etc
Axel F tweet media
English
0
0
0
321
Axel F
Axel F@Axel_F5·
#Spyder malware looks to be an update of #WarHawk malware from #Sidewinder #APT 1f4b225813616fbb087ae211e9805baf BAF Operations Report CamScannerDocument.exe c2 hxxp[:]//plainboardssixty[.]com/drive/bottom.php
Axel F tweet media
English
2
9
34
4.1K
Axel F
Axel F@Axel_F5·
More samples (same c2): 53b3a018d1a4d935ea7dd7431374caf1 Naxal VPN Version2.2 Setup.exe 1f599f9ab4ce3da3c2b47b76d9f88850 Naxal VPN Version2.2 Setup.exe
English
0
0
0
301
.
.@__0XYC__·
Hindi variables - seeking faster attribution ? winners-final.xls 7f3e405d6e9fb03de14551e19e3dfccb hxxps://mega.nz/file/mTZngbYZ#dm3HkJr-uVp3PUPv-Zw3g5c184gSLMrwfARBVRS3Ek8 hxxps://online-csdgovpk.servehttp.com/images/pmdu_finance_2.jpg #APT hosting maldocs @MEGAprivacy
. tweet media. tweet media. tweet media
Deutsch
4
7
13
2.7K
Axel F
Axel F@Axel_F5·
#Sidewinder #APT d0ca92ce29456931ad14aed48c3ea93f 未命名的附件 00002[.]zip 5356a1193252b4fb2265fc8ac10327a1 .lnk hxxps://mailtsinghua[.]sinacn[.]co/3679/1/55554/2/0/0/0/m/files-94c98cfb/hta
Eesti
0
1
3
0
Axel F
Axel F@Axel_F5·
New variant of #Emotet Excel lure, slight variation where "Relaunch Required" instructions (to bypass Office macro security measures) are in green box instead of yellow. Example file: W-9 form.xls 703d6f27c9b54b604f58d3d853c328f6cd51b8598af4dedb4ae0ddea3074ef38
Axel F tweet media
English
0
0
1
0
Axel F retweetledi
Threat Insight
Threat Insight@threatinsight·
Today Proofpoint observed the #Emotet E4 botnet delivering what seems to be a development build of a new #IcedID Loader. This module has the ID 2445 and directly downloads the IcedID bot.
English
2
51
134
0
Axel F retweetledi
Threat Insight
Threat Insight@threatinsight·
A particularly interesting #Emotet email in #France is spoofing "Chambre des Notaires de Paris." #Emotet emails are targeting many countries, including the United States, United Kingdom, Japan, Germany, Italy, France, Mexico, and Brazil.
Threat Insight tweet media
English
2
17
39
0
Axel F
Axel F@Axel_F5·
@__0XYC__ + f97d5d3e1c2ceb3e9d23ae5b5d4e7c9857155df5acf7f67fee995cb041c797dc 33-Advisory-No-33-2022.pdf.iso 58b3686e4255d32dbcf7dee9dac1d5be6d4692d086cde167da1e1a5e0e1b315a 32-Advisory-No-32.iso
Italiano
0
0
1
0
.
.@__0XYC__·
circular_29092022.iso cd592c969a3a940e43888a1902ec9e4605ed28676d3945ab84d72175fbc87253 bbcca0dc10b700c01e557612f009c050ca618f227e0b8be3d4f471dd9d887a18 NisSrv.exe #APT
Português
3
0
0
0
.
.@__0XYC__·
That's how ! treat actor getting started 🤫 comsats-mail[.]pk #gophish
. tweet media. tweet media
English
1
1
2
0
Axel F
Axel F@Axel_F5·
@__0XYC__ @StopMalvertisin +2 b82580cd92afe20e3a51ec92fb46053b3f78c93cf57811d94ac9fe14d3a5e21f List of Officers and amount deducted for floods 2022.xlsm 9133388cf8754dc7bb98031dad59333868f441c303264b9218a900c8079cfafc List of Officers and amount deducted for floods 2022.xlsm
English
0
0
1
0
.
.@__0XYC__·
List of Officers and amount deducted for floods 2022.xlsm 081ff426ca94307aee5afaf02e76e908b8d63cb58c7c8b9df41ac66114612c29 hxxps://r.mailflix.live/967ebc5fcda61b83d8d8eb66e26c75e3rWngLux0HKBIz #APT Password: SEP2022 CC @StopMalvertisin
. tweet media. tweet media
English
4
2
10
0