EKFiddle

160 posts

EKFiddle banner
EKFiddle

EKFiddle

@EKFiddle

An extension/rules for the Fiddler Classic and Fiddler Everywhere web debuggers | Tweets by @malwareinfosec

Fiddler Katılım Ocak 2017
1 Takip Edilen1.1K Takipçiler
EKFiddle
EKFiddle@EKFiddle·
Added 'Mag_cache' skimmer detection to EKFiddle (ref: twitter.com/MBThreatIntel/…) Rules for Fiddler Classic and Fiddler Everywhere: github.com/malwareinfosec…
EKFiddle tweet media
ThreatDown@Threat_Down

ℹ️ We found a #Magecart skimmer that was new to us via @urlscanio ➡️ Seen ITW and tagged by @sansecio: #transactions" target="_blank" rel="nofollow noopener">urlscan.io/result/9d8b406… ➡️ Exfiltrates data via: gs27usa[.]com/translations/tw/mails.php ➡️ Raw: github.com/MBThreatIntel/… ➡️ Beautified: github.com/MBThreatIntel/…

English
0
3
13
0
EKFiddle
EKFiddle@EKFiddle·
#FakeUpdates .breatheinnew[.]life .roles.thepowerofgodswhisper[.]com 77.91.127[.]52
EKFiddle tweet media
English
2
8
14
0
EKFiddle
EKFiddle@EKFiddle·
💡 The latest update for #FiddlerEverywhere adds a similar feature known as the 'TextWizard' in Fiddler Classic. ➡️ Select a string and right-click 'Decode Selection'
EKFiddle tweet media
English
0
2
3
0
EKFiddle
EKFiddle@EKFiddle·
ℹ️ It looks like the SSL certificate for maps .windows .com (Bing maps) expired 2 days ago
EKFiddle tweet media
English
1
0
0
0
EKFiddle
EKFiddle@EKFiddle·
💡 New version of Fiddler Everywhere adds horizontal view mode.
EKFiddle tweet mediaEKFiddle tweet media
English
0
2
12
0
EKFiddle
EKFiddle@EKFiddle·
New #Magecart domain jsconfigur[.]net ➡️ JavaScript: jsconfigur[.]net/js/config.js ➡️ Exfiltration: jsconfigur[.]net/configure/collecting.php
EKFiddle tweet media
English
1
6
19
0
Marc
Marc@CTI_Marc·
@EKFiddle Do you have any publication for this antisandbox cluster ?
English
1
0
0
0
EKFiddle
EKFiddle@EKFiddle·
New hostnames related to the 'Anti-sandbox' #Magecart skimmer js[.]knowledgecdn[.]org m[.]sale-alerts[.]com s[.]geotac[.]net 185.253.33[.]176 185.63.190[.]141 89.108.109[.]26
EKFiddle tweet media
English
1
13
22
0
EKFiddle
EKFiddle@EKFiddle·
#Magecart exfiltration with image (hash: ad7f76306b7deced1aea2cafb9e0cdfd00716ba713b382a079c7d743a396cf87) links to previous Porkbun infrastructure. dxloc[.]buzz dylorean[.]cyou 141.98.82[.]244 5.188.62[.]10
EKFiddle tweet media
English
0
0
6
0
EKFiddle
EKFiddle@EKFiddle·
💡 #EKFiddle tip ➡️ Flag traffic by IP address with exact match or regular expression. Works for both Fiddler Classic and Fiddler Everywhere
EKFiddle tweet media
English
0
1
6
0
EKFiddle
EKFiddle@EKFiddle·
@PaulWebSec @pancak3lullz Depends what exactly you need it for, but EKFiddle can parse the page content in real time and find patterns that you can define as well
English
0
0
2
0
Paul Sec.jpeg                                 .exe
Paul Sec.jpeg .exe@PaulWebSec·
Hey tweeps, any recommendation for a tool to analyze web page loading? (and not web inspector from the browser itself)
English
4
1
0
0
EKFiddle
EKFiddle@EKFiddle·
'Mirasvit' Magecart skimmer. Maybe tied to exploitation of the Mirasvit plugin? ➡️ Exfiltration: hubberstore[.]com
EKFiddle tweet media
English
1
1
8
0
EKFiddle
EKFiddle@EKFiddle·
'Recaptcha' Magecart skimmer ➡️ JavaScript: cafeunido[.]com/pub/media/flag/flag.js candlemaking[.]com/media/email/logo/default/az1.js ➡️ Exfiltration: cafeunido[.]com/pub/errors/default/403.php ariaperfume[.]com/errors/default/403.php
EKFiddle tweet media
English
0
4
4
0
EKFiddle
EKFiddle@EKFiddle·
New 'Bom' Magecart skimmer domain (compromised site) ➡️ apfeltee[.]de/js/prototype/form.js Regexes for Fiddler Classic/Everywhere available at: github.com/malwareinfosec…
EKFiddle tweet media
English
0
2
13
0