Rezultati pretraživanja
  1. 4. velj

    Looks like is up early today, clean xls already served at de-cnd/en-cnd/es-cnd/fr-cnd.one-drive-ms.com/download.php. Their normal schedule of weaponizing at around 10:00 UTC will probably hold.

    Prikaži ovu nit
  2. prije 6 sati

    2020-02-06:🔥🆕 Injector 'wsus.exe' ➡️ v0.2 'tinymet.exe' <Usage: tinymet.exe [transport] LHOST LPORT> h/t 🚨🗯️TinyMet as Precursor for TA505 Post-Exploitation Operation to MD5: b7fd25034019bc0b09242047d2c1d62a

  3. prije 5 sati

    Daily download domain: /shared-cnd.com, playing around with subdomains today. C2 /mainten-ferrum.com

    Prikaži ovu nit
  4. 3. velj

    New download url's ..? - hxxp://en-pld00238.cloud-store-cdn[.]com/download.php - hxxp://en-pld01904.cloud-store-cdn[.]com/download.php but the file seems to be known for quite some time.

  5. prije 5 sati

    The domain /live-cnd.com did have an A-record yesterday and several subdomains, but doesn't resolve today. Saving it for another day maybe?

  6. prije 8 sati

    Just so it's documented on twitter too, yesterdays download domain was en/de/fr/es.onedrive.live-msr.com and C2 was indeed /wpad-home.com as suspected.

  7. 30. sij

    Your daily dose of goodness: cdn-de-0691.clouds-share[.]com, cdn-en-0334.clouds-share[.]com - secure-53[.]com smells like the C2 as well but unconfirmed until the kit goes live.

  8. 31. sij

    2020-01-31:[INTEL]🙏💬Please remember: is not necessarily (linked to operation). 🕯️While there might be some distribution member overlap, these groups are not the same and cannot be equated. I'm not sure why TA505 is being again AKA'ed as EvilCorp here.

  9. 30. sij

    This report is a year journey✈️ to follow the trail of TA505. ⭐️Especially : TTP, Malwares, Relevance with Carbanak (Only published in Korean😅)

  10. 4. velj

    Another for today is: wpad-home[.]com | 185.176.222.44 Live soon I guess ! (cc )

  11. prije 23 sata
  12. [INFO] campaign uses redirectors to spread info . To read more visit:

    Prikaži ovu nit
  13. 4. velj

    At least the whole != thing is giving me a clear indication of who is blindly retweeting articles and not doing their own research, and which intel vendors don't define their intrusion sets well.

  14. 4. velj
  15. 4. velj

    Seems Microsofts commentary may be forcing to go back into doing spoof download pages instead of lazily doing attachment redirects to download.php

  16. 4. velj

    Seems todays on one-drive-ms[.]com still hasnt been deployed - still dropping G-Payroll-spreadsheet it seems

  17. 3. velj

    is back for another round, this time uses HTML Redirectors to deliver |

  18. 3. velj
  19. 3. velj

    Confirmings today . Downloads from s/cloud-store-cdn.com/download.php, C2 /microsoft-sback-server.com as I thought.

    Prikaži ovu nit
  20. 3. velj

    Todays C2: /microsoft-sback-server.com ? Resolves to same IP as last weeks C2 IP, but new registrar.

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.