Mr_4zure's profile picture. Cyber Security Analyst, Threat Researcher

#InfoSec #CyberSecurity #CyberDefence

NULL

@Mr_4zure

Cyber Security Analyst, Threat Researcher #InfoSec #CyberSecurity #CyberDefence

NULL reposted

#Spyware — and the "mercenary" groups behind these tools — is still popping up and, in some cases, growing. We have a new blog post about why these groups are dangerous and what other steps the security community should be taking to combat these threats. cs.co/6016Py6uI

TalosSecurity's tweet image. #Spyware — and the "mercenary" groups behind these tools — is still popping up and, in some cases, growing. We have a new blog post about why these groups are dangerous and what other steps the security community should be taking to combat these threats. cs.co/6016Py6uI

NULL reposted

#Lokibot #Malware from #malspam MD5: 87D96F1D67CB3142621BF58A527A3A06 🔥hxxp://sempersim.su/gk10/fre.php #infosec #malware #CyberSecurity

reecdeep's tweet image. #Lokibot #Malware from #malspam

MD5: 87D96F1D67CB3142621BF58A527A3A06
🔥hxxp://sempersim.su/gk10/fre.php

#infosec #malware #CyberSecurity

NULL reposted

multiple #AgentTesla #malware by #GuLoader targeting #italy too 🇮🇹 🔥exfiltration via FTP: fxp://ftp[.onogost[.com/ infoo[@[onogost[.com fxp://ftp[.overviewsupplies[.com/ wrk1[@[wiprorealstate[.com #infosec #CyberSecurity #infosecurity #Security

🇮🇹#GuLoader is delivering #AgentTesla #malware in #italy too from massive #malspam thanks to @AgidCert ➡️urls: hxxp://asblp.tk/bvvc/MAHrNVsQLYBv140.csv /lJrJtbe135.dsp hxxp://asblp[.tk/scrtt/pcqPOYCq163.hhp /eemnWjnxSePvDyq91.csv #CyberSec #infosec #CyberAttack



NULL reposted

🇮🇹#GuLoader is delivering #AgentTesla #malware in #italy too from massive #malspam thanks to @AgidCert ➡️urls: hxxp://asblp.tk/bvvc/MAHrNVsQLYBv140.csv /lJrJtbe135.dsp hxxp://asblp[.tk/scrtt/pcqPOYCq163.hhp /eemnWjnxSePvDyq91.csv #CyberSec #infosec #CyberAttack


NULL reposted

"Richiesta Preventivo" spread #guloader #italy Gz bazaar.abuse.ch/sample/c879d04… Zip password protected not write in email (pw 1) bazaar.abuse.ch/sample/a6603d5… Exe bazaar.abuse.ch/sample/c690e22… C2 config hXXps://andreameixueiro.com/build_EXjhnftQHX181.bin bazaar.abuse.ch/sample/4b64d0d… cc @Arkbird_SOLG

JAMESWT_WT's tweet image. "Richiesta Preventivo"
spread #guloader #italy
Gz
bazaar.abuse.ch/sample/c879d04…
Zip password protected not write in email (pw 1)
bazaar.abuse.ch/sample/a6603d5…
Exe
bazaar.abuse.ch/sample/c690e22…
C2 config
hXXps://andreameixueiro.com/build_EXjhnftQHX181.bin
bazaar.abuse.ch/sample/4b64d0d…
cc @Arkbird_SOLG
JAMESWT_WT's tweet image. "Richiesta Preventivo"
spread #guloader #italy
Gz
bazaar.abuse.ch/sample/c879d04…
Zip password protected not write in email (pw 1)
bazaar.abuse.ch/sample/a6603d5…
Exe
bazaar.abuse.ch/sample/c690e22…
C2 config
hXXps://andreameixueiro.com/build_EXjhnftQHX181.bin
bazaar.abuse.ch/sample/4b64d0d…
cc @Arkbird_SOLG

NULL reposted

Malspam with weaponized word document distributing TrickBot (rob96) 🔥 docx -> dot -> exe 🪲 Domains: micrsoft365 .live download3 .xyz docx: 📄 bazaar.abuse.ch/sample/4835f6d… dot: 📃bazaar.abuse.ch/sample/fd05481… exe: 📁 bazaar.abuse.ch/sample/24dd0b8… Payload URLs: 🌍 urlhaus.abuse.ch/browse/tag/rob…

abuse_ch's tweet image. Malspam with weaponized word document distributing TrickBot (rob96) 🔥

docx -> dot -> exe 🪲

Domains:
micrsoft365 .live
download3 .xyz

docx:
📄 bazaar.abuse.ch/sample/4835f6d…

dot:
📃bazaar.abuse.ch/sample/fd05481…

exe:
📁 bazaar.abuse.ch/sample/24dd0b8…

Payload URLs:
🌍 urlhaus.abuse.ch/browse/tag/rob…

NULL reposted

"Re: New order of goods" spred #FormBook too in #italy Revised_Order PDF .zip bazaar.abuse.ch/sample/355af5b… Revised_Order PDF.exe bazaar.abuse.ch/sample/bfc5459… C2 hXXp://www.kalptarucentrino.com/owws/ cc @58_158_177_102 @felixw3000

JAMESWT_WT's tweet image. "Re: New order of goods" spred #FormBook too in #italy
Revised_Order PDF .zip
bazaar.abuse.ch/sample/355af5b…
Revised_Order PDF.exe
bazaar.abuse.ch/sample/bfc5459…
C2 hXXp://www.kalptarucentrino.com/owws/

cc @58_158_177_102 @felixw3000

NULL reposted

"Re:FW: PROFORMA INVOICE2" #spread #Formbook too today in #italy Zip bazaar.abuse.ch/sample/20958a9… PROFORMA INVOICE PDF.exe bazaar.abuse.ch/sample/98acba3… C2 hXXp://www.kalptarucentrino.com/owws/ cc @58_158_177_102 @felixw3000

JAMESWT_WT's tweet image. "Re:FW: PROFORMA INVOICE2"
#spread #Formbook too today in #italy
Zip
bazaar.abuse.ch/sample/20958a9…
PROFORMA INVOICE PDF.exe
bazaar.abuse.ch/sample/98acba3…
C2 hXXp://www.kalptarucentrino.com/owws/
cc @58_158_177_102 @felixw3000
JAMESWT_WT's tweet image. "Re:FW: PROFORMA INVOICE2"
#spread #Formbook too today in #italy
Zip
bazaar.abuse.ch/sample/20958a9…
PROFORMA INVOICE PDF.exe
bazaar.abuse.ch/sample/98acba3…
C2 hXXp://www.kalptarucentrino.com/owws/
cc @58_158_177_102 @felixw3000

NULL reposted

Individuata nuova variante delle campagna #sLoad veicolata via #PEC ⚠️Disponibili gli #ioc 🔗 cert-agid.gov.it/news/individua…

AgidCert's tweet image. Individuata nuova variante delle campagna #sLoad veicolata via #PEC

⚠️Disponibili gli #ioc 

🔗 cert-agid.gov.it/news/individua…

NULL reposted

Collections of #signed "1.A Connect GmbH" Samples including #CobaltStrike #signed Samples 🔽🔽🔽 bazaar.abuse.ch/browse/tag/1.A… H/T @malwrhunterteam

JAMESWT_WT's tweet image. Collections of #signed "1.A Connect GmbH" Samples
including #CobaltStrike #signed Samples
🔽🔽🔽
bazaar.abuse.ch/browse/tag/1.A…

H/T @malwrhunterteam
JAMESWT_WT's tweet image. Collections of #signed "1.A Connect GmbH" Samples
including #CobaltStrike #signed Samples
🔽🔽🔽
bazaar.abuse.ch/browse/tag/1.A…

H/T @malwrhunterteam

NULL reposted

⚠️Nuova ondata #Flubot solita modalità #smishing/#phishing "Il pacco è pronto per la consegna. Richiedilo ora..." #DHL🎣https://corgamacfi[.com/3tosyn.php?ucqr9ljistwb campione #apk ⤵️ virustotal.com/gui/file/a34c1…

Slvlombardo's tweet image. ⚠️Nuova ondata #Flubot solita modalità #smishing/#phishing
"Il pacco è pronto per la consegna. Richiedilo ora..."
#DHL🎣https://corgamacfi[.com/3tosyn.php?ucqr9ljistwb
campione #apk ⤵️
virustotal.com/gui/file/a34c1…
Slvlombardo's tweet image. ⚠️Nuova ondata #Flubot solita modalità #smishing/#phishing
"Il pacco è pronto per la consegna. Richiedilo ora..."
#DHL🎣https://corgamacfi[.com/3tosyn.php?ucqr9ljistwb
campione #apk ⤵️
virustotal.com/gui/file/a34c1…

NULL reposted

⚠️Nuova ondata #Flubot solita modalità #smishing/#phishing "Il pacco è pronto per la consegna. Richiedilo ora..." #DHL🎣https://corgamacfi[.com/3tosyn.php?ucqr9ljistwb campione #apk ⤵️ virustotal.com/gui/file/a34c1…

Slvlombardo's tweet image. ⚠️Nuova ondata #Flubot solita modalità #smishing/#phishing
"Il pacco è pronto per la consegna. Richiedilo ora..."
#DHL🎣https://corgamacfi[.com/3tosyn.php?ucqr9ljistwb
campione #apk ⤵️
virustotal.com/gui/file/a34c1…
Slvlombardo's tweet image. ⚠️Nuova ondata #Flubot solita modalità #smishing/#phishing
"Il pacco è pronto per la consegna. Richiedilo ora..."
#DHL🎣https://corgamacfi[.com/3tosyn.php?ucqr9ljistwb
campione #apk ⤵️
virustotal.com/gui/file/a34c1…


NULL reposted

Probabile campagna di #Phishing ai danni dei rivenditori di #Sky veicolato con dominio creato Ad Hoc lo scorso 22 Maggio. IoC: - assistenzapdv[.]com Invitiamo gli utenti a prestare la massima attenzione!

D3LabIT's tweet image. Probabile campagna di #Phishing ai danni dei rivenditori di #Sky veicolato con dominio creato Ad Hoc lo scorso 22 Maggio.

IoC:
- assistenzapdv[.]com

Invitiamo gli utenti a prestare la massima attenzione!

NULL reposted

Researchers disclose details on several critical vulnerabilities affecting Nagios IT monitoring #software that could let attackers hijack corporate networks. Read: thehackernews.com/2021/05/detail… #infosec #cybersecurity #hacking


NULL reposted

#oletools 0.60 / olevba: I am integrating XLMMacroDeobfuscator from @DissectMalware to extract and deobfuscate Excel 4 / XLM macros (work in progress - bugs expected) If you want to test it, install the latest dev version of oletools: github.com/decalage2/olet…

decalage2's tweet image. #oletools 0.60 / olevba: I am integrating XLMMacroDeobfuscator from @DissectMalware to extract and deobfuscate Excel 4 / XLM macros (work in progress - bugs expected)
If you want to test it, install the latest dev version of oletools: github.com/decalage2/olet…

NULL reposted

#Lokibot #Malware targets #Italy 🇮🇹 from #malspam "Copia di pagamento dell'Ordine" 🔥c2: hxxp://mbyi.]xyz/five/fre.php #infosec #CyberSecurity #cybercrime #Security @guelfoweb @VirITeXplorer @58_158_177_102 @matte_lodi @D3LabIT

reecdeep's tweet image. #Lokibot #Malware targets #Italy 🇮🇹 from #malspam

"Copia di pagamento dell'Ordine"

🔥c2:
hxxp://mbyi.]xyz/five/fre.php

#infosec #CyberSecurity #cybercrime #Security 
@guelfoweb @VirITeXplorer @58_158_177_102 @matte_lodi @D3LabIT
reecdeep's tweet image. #Lokibot #Malware targets #Italy 🇮🇹 from #malspam

"Copia di pagamento dell'Ordine"

🔥c2:
hxxp://mbyi.]xyz/five/fre.php

#infosec #CyberSecurity #cybercrime #Security 
@guelfoweb @VirITeXplorer @58_158_177_102 @matte_lodi @D3LabIT

NULL reposted

In a new blog post @teamcymru share some of their finding on the IcedID/Bokbot infrastructure. team-cymru.com/blog/2021/05/1…

virusbtn's tweet image. In a new blog post @teamcymru share some of their finding on the IcedID/Bokbot infrastructure. team-cymru.com/blog/2021/05/1…

NULL reposted

"Bank Payment Copy Attached" spread #nanocore #rat too in #italy Ace bazaar.abuse.ch/sample/9ee0828… Exe bazaar.abuse.ch/sample/f2dcc47… >>> joetrump2022.ddns[.net cc @felixw3000 @58_158_177_102 @verovaleros

JAMESWT_WT's tweet image. "Bank Payment Copy Attached" spread #nanocore #rat
too in #italy
Ace
bazaar.abuse.ch/sample/9ee0828…
Exe
bazaar.abuse.ch/sample/f2dcc47…
>>> joetrump2022.ddns[.net
cc @felixw3000 @58_158_177_102 @verovaleros
JAMESWT_WT's tweet image. "Bank Payment Copy Attached" spread #nanocore #rat
too in #italy
Ace
bazaar.abuse.ch/sample/9ee0828…
Exe
bazaar.abuse.ch/sample/f2dcc47…
>>> joetrump2022.ddns[.net
cc @felixw3000 @58_158_177_102 @verovaleros
JAMESWT_WT's tweet image. "Bank Payment Copy Attached" spread #nanocore #rat
too in #italy
Ace
bazaar.abuse.ch/sample/9ee0828…
Exe
bazaar.abuse.ch/sample/f2dcc47…
>>> joetrump2022.ddns[.net
cc @felixw3000 @58_158_177_102 @verovaleros

Loading...

Something went wrong.


Something went wrong.