Kafeine

1.3K posts

Kafeine

Kafeine

@kafeine

Sleep is a symptom of caffeine deprivation.

Katılım Ağustos 2008
620 Takip Edilen15.2K Takipçiler
Kafeine
Kafeine@kafeine·
TFW your favorite actor, Sagrid (TA543), does not come back from vacation
Kafeine tweet mediaKafeine tweet mediaKafeine tweet media
English
4
12
64
0
Kafeine
Kafeine@kafeine·
Is Gootkit gone?
Kafeine tweet media
Indonesia
1
2
8
0
Kafeine
Kafeine@kafeine·
Archeology: Necurs (crap2p) and its distribution. If you are interested in what they were doing in 2011,you might want to look at this FakeRean: 7d5ea317f2d1248386b904301bb19bbde44df3e1c3d8d08cd0644fed24362e2a cc/thx @maciekkotowicz @Antelox
Kafeine tweet mediaKafeine tweet mediaKafeine tweet mediaKafeine tweet media
English
0
15
49
0
Kafeine retweetledi
hadojae
hadojae@switchingtoguns·
Posting malware wireshark screencaps is pretty cool, but sharing #pcap with @ET_Labs to help protect the community is even cooler.
English
1
15
34
0
Kafeine retweetledi
hadojae
hadojae@switchingtoguns·
2029206 - ET EXPLOIT Possible Citrix Application Delivery Controller Arbitrary Code Execution Attempt (CVE-2019-19781) (exploit.rules) in the @EmergingThreats OPEN set as of Dec 29th
Français
0
18
19
0
Kafeine
Kafeine@kafeine·
Unsure yet what this comeback/evolution, after 2 years missing, of Zloader/Terdot.A is about...but this is one of the emerging trend in december 2019. cc/thx @tildedennis @threatinsight
Kafeine tweet media
English
1
20
44
0
Kafeine
Kafeine@kafeine·
Illustration of some ServHelper distribution for the past year (TL;DR: it's more than one actor)
Kafeine tweet media
English
0
22
50
0
Kafeine
Kafeine@kafeine·
Note:TA505 != Dridex. They were massively spreading it, with, as customer, Necurs. Dridex 125 then 220 and 7200, but also Locky 3, Trickbot mac1 before moving to ServerHelper and FlawedAmmyy. Other actor are spreading Dridex. Smilex was part of the team spreading Dridex 120.
Kafeine tweet mediaKafeine tweet mediaKafeine tweet media
English
2
48
108
0
Kafeine
Kafeine@kafeine·
@BobbyEberle13 @BobbyEberle13 gopusa is compromised. You probably want to get that clean fast. (illustration - redirect to an Exploit Kit (RIG) itself dropping a malware (Trickbot "nev3") )
Kafeine tweet media
English
0
2
4
0
Kafeine retweetledi
Marc-Etienne M.Léveillé
Marc-Etienne M.Léveillé@marc_etienne_·
I don’t endorse the vocabulary in this tweet but I’d like to share our side of things and perhaps set the records straight. We never really wanted to (and still don’t want to) discredit Dragos publicly, there is really no point. 1/x
English
3
85
220
0
Kafeine
Kafeine@kafeine·
For the records, sLoad is still dropping Ramnit "fB1oN5frGqf" in Italy. virustotal.com/gui/file/2c096… cc/thx @reecDeep @Antelox (cf: twitter.com/reecdeep/statu… )
Kafeine tweet mediaKafeine tweet mediaKafeine tweet media
reecDeep@reecdeep

again 👾#sload #malware #geofenced #italy 🇮🇹 hxxps://passneet.com/cert/leultimenotizie.jpg same c2: hxxps://rtexo.eu/view/, hxxps://nvroe.eu/view/ @JAMESWT_MHT @malwrhunterteam @matte_lodi @luc4m @vxsh4d0w @VK_Intel @gigafio #ThreatIntel #ThreatMonitoring #Threat #infosec

English
1
11
36
0