Luke Leal

244 posts

Luke Leal banner
Luke Leal

Luke Leal

@rootprivilege

Threat Intel.

United States Tham gia Nisan 2019
38 Đang theo dõi739 Người theo dõi
Luke Leal
Luke Leal@rootprivilege·
@JCyberSec_ @DCPCU_tweets fake louis bag just chilling on the table next to the joint crutch and emptied cigarette 😂 nice work!
English
0
0
1
166
Luke Leal
Luke Leal@rootprivilege·
@nullcookies "All the rumors, the human sacrifices, the Hell portal, the demons... it's all true" let us know where to go to enjoy the synths 🙂
English
0
0
1
77
Luke Leal
Luke Leal@rootprivilege·
@1ZRR4H What's the redacted domain name from $inter_domain that is being used to pull the SEO spam from? The sample I have looks like an older one and its domain isn't active anymore.
English
0
0
0
167
Germán Fernández
Germán Fernández@1ZRR4H·
A threat actor is compromising websites to deploy this PHP tool, used for SEO Poisoning via Google 👀 It receives the content and keywords from C2, injects them into the sitemaps and submits them to the Google Sitemap Ping service.
Germán Fernández tweet mediaGermán Fernández tweet mediaGermán Fernández tweet mediaGermán Fernández tweet media
English
3
49
151
18.6K
Luke Leal
Luke Leal@rootprivilege·
#Arkei #Stealer malware C2 panel using a login page that mimics the #WordPress login page but is actually connected to the C2 panel's database. Used to evade detection so the panel can stay active on compromised websites for longer. #malware #cybersecurity #C2
GIF
English
2
3
11
924
Luke Leal
Luke Leal@rootprivilege·
@j2k3k Isn't that how you get CS:GO from this Sierra published masterpiece?
Luke Leal tweet media
English
0
0
0
0
Luke Leal
Luke Leal@rootprivilege·
@JCyberSec_ I don't think they should be criminally prosecuted unless there is gross negligence and/or the telecom intentionally allowed the abuse.
English
1
0
0
0
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
🚨Phone companies that fail to block scam texts should be prosecuted❓ 📣“Telecom companies have avoided responsibility when it comes to scam texts and calls. A corporate criminal offence should be introduced” 🌐telegraph.co.uk/money/consumer…
English
1
0
4
0
Luke Leal
Luke Leal@rootprivilege·
#strox phishing pages also have the capability to steal #2FA OTP from victims (along with their email account, personal documents, etc - fullz)
English
0
0
1
0
Luke Leal
Luke Leal@rootprivilege·
@CryptoprenuerUK @JCyberSec_ This actor has made the barrier of entry even lower...they provide everything but the domain. They even have a market to sell the phished logins. Also they never directly provide the kits and they use a subscription model ($3/day, 10 day min). I'll drop a post on it later today.
English
0
0
2
0
krypt0.base.eth | ETHGas ⛽Zetarium
krypt0.base.eth | ETHGas ⛽Zetarium@CryptoprenuerUK·
@JCyberSec_ @rootprivilege On the subject of OTP phish pages this always bothered me "standard kits" we see just rely on the victim to enter any old BS in order for the phish to move on "OH yeah I'll just enter anything as the code didn't come must be legit" 🤣 No wonder barrier to entry is so low
English
1
0
1
0
Luke Leal
Luke Leal@rootprivilege·
@JCyberSec_ Yeah they can still get fullz and also access to the email account associated with banking login (assuming victim submits this data).
English
1
1
1
0
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
@rootprivilege Let me get this clear, if the actor turns it off the site just doesn't show the OTP page? So the actor ends up with a username:password but no 2FA so they can't actually do anything with the logins?
English
2
2
0
0
Luke Leal
Luke Leal@rootprivilege·
@glotcode Hi - is there any way to report malicious activity on some of the pastes you host?
English
1
0
0
0
Luke Leal
Luke Leal@rootprivilege·
@nullcookies My understanding is that those videos aren't eligible for Adsense payouts so not sure where the money goes to... 🤔
English
1
0
0
0
nullcookies
nullcookies@nullcookies·
There are people who value advertiser revenue from clicks on lunatic conspiratorial YouTube videos over the lives of our elders. Let’s call misinformation outlets what they truly are—fraudsters. Let’s call fraud what it truly is—evil.
English
1
3
9
0