'ReDLiNe
67 posts

'ReDLiNe
@ValkSpammer
- TurkHackTeam - Expert Hunter - Professional Sleeper Since 1989 from Tiannenmen Square - Sometimes I Touch Grass Too - World War 3 Veteran
Katılım Kasım 2021
74 Takip Edilen37 Takipçiler
'ReDLiNe retweetledi

Recent #stegocampaign delivering #XWorm RAT #malware
#VBS -> #PowerShell -> #stego picture with executable -> TXT -> #xwormrat
Payloads at #Pastebin and #Firebase
My new analysis + #IOC: malwarelab.eu/posts/stego-xw…
#steganography #anyrun #malwareanalysis #obfuscation #cyberchef




English
'ReDLiNe retweetledi
'ReDLiNe retweetledi

Email -> Undetected PDF -> Zip(Github) -> BAT -> PowerShell -> CMD -> PowerShell -> Exclude Path -> AsyncRat exe (Github) !
Undetected malicious PDF ( 0 VT ) , has a link to download a zip from Github.
The zip contains a batch file which invokes PowerShell to launch cmd, to again launch PowerShell to first get the paths excluded, download and run next stage exe ( again hosted on Github ), eventually leading to AsyncRat.
The Github directory is live as of now, and is hosting tons of malicious stuff since three weeks.
Malicious Github -hxxps[://]github[.]com/thecoolest63/frms
Hacker tries to act "cool" by overdoing cringe stuff.
Cringe 1 - Exclude path is C:\\Users\\CYB3R W4RRIOR\\AppData\\Roaming
Cringe 2 - Mutex name "Cyb3r_R4tMutex_Cyb3rw4rrior"
Cringe 3 - C2 port is 1337
C2 IP \192.177.98.104:1337
Email Subject : "TAX REFUND 2024"
0 detection PDF:
bazaar.abuse.ch/sample/20e5756…
AsyncRAT: bazaar.abuse.ch/sample/fb76f99…




English
'ReDLiNe retweetledi

Türk Hack Team, Başta bankalar olmak üzere Avusturya'da bulunan kurumlara DDOS saldırısı gerçekleştirdiğini açıkladı.
- Bank Avusturya
- Ober Bank
- Avusturya Parlamentosu
- A1 Avusturya Popüler Telekom
- Viyana Genel Hastanesi Asfinag
...
#siberguvenlik #CTI #threatintel

Türkçe
'ReDLiNe retweetledi

@aircaraibes
🇹🇷We Are Türk Hack Team🇹🇷
Check Host:check-host.net/check-report/1…
Target:aircaraibes.com
🇹🇷We Are Türk Hack Team🇹🇷



Eesti
'ReDLiNe retweetledi

Russian Humanities State University Hacked
🎯 Attacked Site: rsuh.ru
🔥 Zone-H: zone-h.org/mirror/id/4058…
#News #BreakingNews #Hacked #Hacking
Russia Ivanovo State University Hacked!
🎯 Attacked Site: ivanovo.ac.ru
🔥 Zone-H: zone-h.org/mirror/id/4058…

English
'ReDLiNe retweetledi

Gölgesini büyük sayan mağrur fillerin belalısıyız!
Our attacks will continue until the persecution ends!
#israel #cybersecurity #cyberattack #hacking #Hacked #Palestine #masjidalaqsa

Türkçe
'ReDLiNe retweetledi
'ReDLiNe retweetledi
'ReDLiNe retweetledi

Although we warned many times, the Quran was burned by Rasmus Paludan in front of the Turkish Consulate.
If you burn the Quran, we will burn your servers. #opdenmark #denmark #cyberattack #quran #respect #cyber #news #breaking #BreakingNews #botnet #sweden #hacked #hacking #data
English
'ReDLiNe retweetledi

Denmark Official Police Site Down By Turk Hack Team
politi.dk - down
We will increase our cyber attacks! #opdenmark #denmark #cyberattack #botnet #hacking #hacked #hacker #hack #news #breakingnews #malware #trojan #quran #respect #rasmuspaludan #sweden #turkish


English
'ReDLiNe retweetledi

Our hearts and prayers are with the people of Turkiye, Syria, Lebanon, Palestine, Jordan and the all regions affected by the devastating earthquake. May Allah have mercy on the deceased and grant quick recovery to the injured.
#PrayForTurkey

English
'ReDLiNe retweetledi









