David Ledbetter

31.4K posts

David Ledbetter

David Ledbetter

@Ledtech3

System Repair, Windows system tools ,Security research. IDA Challenged.

Katılım Aralık 2015
289 Takip Edilen3.5K Takipçiler
Germán Fernández
Germán Fernández@1ZRR4H·
Malware dirigido a empresas en Perú 🇵🇪 email > html > zip +password > vbs Descarga desde (#geofenced): /sunat-mail.xyz/2/ /easynsecureinvest.com/cobr/?id=1 Payloads/C2 desde: /gringox1.chickenkiller.com/g1/ +Header: UA-CPU Samples: bazaar.abuse.ch/browse/tag/gri… Sin atribución 🤔
Germán Fernández tweet mediaGermán Fernández tweet mediaGermán Fernández tweet mediaGermán Fernández tweet media
Català
4
22
36
0
David Ledbetter retweetledi
ExecuteMalware
ExecuteMalware@executemalware·
As others have mentioned, the "presidents" #qakbot #qbot distribution (obama221) is back to using "DLL Search Order Hijacking" today (see screenshot). Here are the IOCs: github.com/executemalware…
ExecuteMalware tweet media
English
0
10
45
0
David Ledbetter
David Ledbetter@Ledtech3·
@c_APT_ure you can bck up most of the stuff, but If I remember correctly it doesn't do the DM's thoguh. I've done 2 backup's since i've been here
English
1
0
1
0
David Ledbetter
David Ledbetter@Ledtech3·
@t3ft3lb It looks like the site is down already. Is there a hash for what it downloaded ?
English
1
0
0
0
David Ledbetter
David Ledbetter@Ledtech3·
@t3ft3lb Ok thanks. I'll have to download this and take a closer look at the shellcode. Looks interesting.
English
1
0
1
0
t3ft3lb
t3ft3lb@t3ft3lb·
#APT #Donot Malicious RTF file "ProtocolUpdate.doc" (MD5: 53dfa7deb28e449bbb20c7ad27aeefb6) virustotal.com/gui/file/47d85… Template URL: http://encureyou[.]buzz/QuINNYN6nvc9ZFW6/A04ih06yN8255rXL.php Metadata: ModifyDate & CreateDate - 2022:07:29 13:56:00 rtf -> macro -> shellcode -> dll
t3ft3lb tweet mediat3ft3lb tweet mediat3ft3lb tweet media
Nederlands
1
8
34
0
David Ledbetter
David Ledbetter@Ledtech3·
@hacks4pancakes I have several people that I have DM'd with and the DM's have disappeared but I'm not sure how they do it.
English
1
0
1
0
Cryptolaemus
Cryptolaemus@Cryptolaemus1·
Guess Ivan went hunting or something. Nothing happening on the botnets E4 or E5 in the way of distro/spam. Some modules and loader updates came down though earlier this morning. Will keep everyone posted. Qakbot BB/TR Distro is back heavy today though... 🤔Must be Duck Season.
GIF
English
1
8
28
0
Ankit Anubhav
Ankit Anubhav@ankit_anubhav·
Open this in chrome, this would open rick roll video for you. http://google.com@1157586937 This hiding of IP in plain sight by converting it to decimal value is also abused by #Smokeloader campaign , which is arriving via hacked sites. Payload lies in the "contract" folder.
Ankit Anubhav tweet mediaAnkit Anubhav tweet mediaAnkit Anubhav tweet mediaAnkit Anubhav tweet media
English
6
113
489
0
David Ledbetter
David Ledbetter@Ledtech3·
@t3ft3lb I have not had time to look at this one yet 🤔 Just from the screenshots you got the "External Link/Template" I'll have to see what it downloads
English
1
0
0
0
t3ft3lb
t3ft3lb@t3ft3lb·
@Ledtech3 But you could share your findings anyway.
English
1
0
0
0
Justin Seitz
Justin Seitz@jms_dot_py·
*sips coffee* morning!
English
1
0
3
0
Justin Seitz
Justin Seitz@jms_dot_py·
*sips…* shit!
English
5
0
10
0
💻 Sherrod DeGrippo
💻 Sherrod DeGrippo@sherrod_im·
The consensus seems to be that InfoSec twitter is gone to other platforms. Does this mean I should convert my twitter to just sex and dating stories? Cause… 💥
English
49
5
317
0
mRr3b00t
mRr3b00t@UK_Daniel_Card·
these two fuckers are costing me logging money!
mRr3b00t tweet media
English
5
1
22
0
Bryce
Bryce@bryceabdo·
i will now only be disseminating threat intel and IOC’s in the format of screenshots of sha256 hashes and domains on a private Mastodong server
English
6
1
39
0