.@CrowdStrike says the "COSY BEAR" group in #DNCHack is RU for this reason. But tbh, looks more like a piggyback oppic.twitter.com/SVFubyejAF
Mostly #infosec or #natsec tweets. Also @foiathethings | email: matt.tait$gmail,com |
RTs are not emoluments
When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more
Add this Tweet to your website by copying the code below. Learn more
Add this video to your website by copying the code below. Learn more
| Country | Code | For customers of |
|---|---|---|
| United States | 40404 | (any) |
| Canada | 21212 | (any) |
| United Kingdom | 86444 | Vodafone, Orange, 3, O2 |
| Brazil | 40404 | Nextel, TIM |
| Haiti | 40404 | Digicel, Voila |
| Ireland | 51210 | Vodafone, O2 |
| India | 53000 | Bharti Airtel, Videocon, Reliance |
| Indonesia | 89887 | AXIS, 3, Telkomsel, Indosat, XL Axiata |
| Italy | 4880804 | Wind |
| 3424486444 | Vodafone | |
| » See SMS short codes for other countries | ||
This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.
Hover over the profile pic and click the Following button to unfollow any account.
When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.
The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.
Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.
Get instant insight into what people are talking about now.
Follow more accounts to get instant updates about topics you care about.
See the latest conversations about any topic instantly.
Catch up instantly on the best stories happening as they unfold.
.@CrowdStrike says the "COSY BEAR" group in #DNCHack is RU for this reason. But tbh, looks more like a piggyback oppic.twitter.com/SVFubyejAF
COSYBEAR is an interesting implant. Python and Powershell; comms via .NET using AES with a fixed sym-key #DncHackpic.twitter.com/CpCXNEQTux
That puts COSYBEAR here on the @daveaitel implant-sophistication scale :) #DncHackpic.twitter.com/DXNIhVplhx
Fixed IV/key in COSYBEAR means can traffic-decrypt from pcap. Clearly not written by folks who know crypto #DNCHackpic.twitter.com/BrPLBNjli9
lolwtf? COSYBEAR operators apparently are lame script kiddies. Clearing event logs is like the worst opsec #DncHackpic.twitter.com/KW2AA1iW7a
Serious Q: What AV does DNC run? How did it possibly miss an implant clearing win-event logs w/ WMI persistance?pic.twitter.com/bls5QPOn8R
For some reason @CrowdStrike listing IOCs as SHA256, when industry standard is SHA1. Makes it harder to search for.pic.twitter.com/p2BQY92hXz
.@CrowdStrike Also for some reason clearly have, but aren't sharing the binaries. Seems optimized to stop people checking their results.
Btw, if you want to piggyback onto COSYBEAR, its startup module downloaded w/ fixed AES/IV dl-ed over HTTP (port80)pic.twitter.com/HejStU8MWi
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.