#threadkit resultados de búsqueda

doc files are #threadkit as well...cc @cocaman

James_inthe_box's tweet image. doc files are #threadkit as well...cc @cocaman

First run is absolutely #LokiBot, doc uses #threadkit by the look of it...not sure what to make of <snicker> this though.

James_inthe_box's tweet image. First run is absolutely #LokiBot, doc uses #threadkit by the look of it...not sure what to make of &amp;lt;snicker&amp;gt; this though.

Pretty sweet #threadkit doc via #malspam, is #pony with c2 of: http://www.a10gamesa10[.]com/php/gate.php cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_

James_inthe_box's tweet image. Pretty sweet #threadkit doc via #malspam, is #pony with c2 of:

http://www.a10gamesa10[.]com/php/gate.php

cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_
James_inthe_box's tweet image. Pretty sweet #threadkit doc via #malspam, is #pony with c2 of:

http://www.a10gamesa10[.]com/php/gate.php

cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_

#threadkit dropping #formbook via #malspam; c2 sites here: pastebin.com/P5Z80Bzu hash aa590a773eb2297f2d474d11792f6311 for the doc on @mal_share

James_inthe_box's tweet image. #threadkit dropping #formbook via #malspam; c2 sites here:

pastebin.com/P5Z80Bzu

hash aa590a773eb2297f2d474d11792f6311 for the doc on @mal_share
James_inthe_box's tweet image. #threadkit dropping #formbook via #malspam; c2 sites here:

pastebin.com/P5Z80Bzu

hash aa590a773eb2297f2d474d11792f6311 for the doc on @mal_share

#LokiBot #ThreadKit 103_010COUS180790001_6412663116-09-04-18.doc 8c64c1f6830691ac48a80dc7cd30e0f3 185.82.202.87 POST /~zadmin/cam/conn.php Subject: SWIFT Transfer (103) 010COUS180790001 From: [email protected] [+] WebShell Active

pollo290987's tweet image. #LokiBot #ThreadKit
103_010COUS180790001_6412663116-09-04-18.doc
8c64c1f6830691ac48a80dc7cd30e0f3

185.82.202.87 POST /~zadmin/cam/conn.php

Subject: SWIFT Transfer (103) 010COUS180790001
From: swift@dtbafrica.com

[+] WebShell Active

New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named "saver.scr". app.any.run/tasks/efceacee… virustotal.com/#/file/73b61af…

3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…
3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…
3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…
3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…

#threadkit #maldoc #rtf sample seems to be very busy. Had a lot of signature hits, not sure how many are true. @malwrhunterteam Run at: app.any.run/tasks/16deb6c8…

Zerophage1337's tweet image. #threadkit #maldoc #rtf sample seems to be very busy. Had a lot of signature hits, not sure how many are true. @malwrhunterteam 
Run at: app.any.run/tasks/16deb6c8…
Zerophage1337's tweet image. #threadkit #maldoc #rtf sample seems to be very busy. Had a lot of signature hits, not sure how many are true. @malwrhunterteam 
Run at: app.any.run/tasks/16deb6c8…

Precision meets craftsmanship with our Advance Thread Solution 1-1/2-6 UNC Kit, beautifully encased in a premium wooden box. Perfect for all your threading needs, with durability that stands the test of time. 🛠️ #ThreadKit #Craftsmanship #PrecisionTools #Rapicoil


Looks like a modified #threadkit doc but I don't know what the payload is. It does periodically run a .txt file as an EXE and I'm guessing the DNS requests are connectivity checks. Any thoughts? @Antelox @malwrhunterteam @James_inthe_box @avman1995 app.any.run/tasks/8056a83d…

Zerophage1337's tweet image. Looks like a modified #threadkit doc but I don&apos;t know what the payload is. It does periodically run a .txt file as an EXE and I&apos;m guessing the DNS requests are connectivity checks. Any thoughts? @Antelox @malwrhunterteam @James_inthe_box @avman1995 

app.any.run/tasks/8056a83d…
Zerophage1337's tweet image. Looks like a modified #threadkit doc but I don&apos;t know what the payload is. It does periodically run a .txt file as an EXE and I&apos;m guessing the DNS requests are connectivity checks. Any thoughts? @Antelox @malwrhunterteam @James_inthe_box @avman1995 

app.any.run/tasks/8056a83d…

Two #threadkit #rtf docs dropping #Azorult both docs had 8/59 on VT and one seemed blockchain themed. maksssnd[.]beget[.]tech/index.php 94[.]250.248.105/task.bat app.any.run/tasks/caab858a… app.any.run/tasks/1e37e603…

Zerophage1337's tweet image. Two #threadkit #rtf docs dropping #Azorult both docs had 8/59 on VT and one seemed blockchain themed.

maksssnd[.]beget[.]tech/index.php
94[.]250.248.105/task.bat

app.any.run/tasks/caab858a…
app.any.run/tasks/1e37e603…
Zerophage1337's tweet image. Two #threadkit #rtf docs dropping #Azorult both docs had 8/59 on VT and one seemed blockchain themed.

maksssnd[.]beget[.]tech/index.php
94[.]250.248.105/task.bat

app.any.run/tasks/caab858a…
app.any.run/tasks/1e37e603…

Booby-trapped Office docs build with #ThreadKit trigger #CVE20184878 flaw dlvr.it/QP1rjd

h8v6com's tweet image. Booby-trapped Office docs build with #ThreadKit trigger #CVE20184878 flaw dlvr.it/QP1rjd

#threadkit , bad times ahead if you open this maldoc.. "Urgent Overdue Outstanding Payement.doc" app.any.run/tasks/ed7813ca…

Zerophage1337's tweet image. #threadkit , bad times ahead if you open this maldoc.. &quot;Urgent Overdue Outstanding Payement.doc&quot;
app.any.run/tasks/ed7813ca…
Zerophage1337's tweet image. #threadkit , bad times ahead if you open this maldoc.. &quot;Urgent Overdue Outstanding Payement.doc&quot;
app.any.run/tasks/ed7813ca…

Use your promo code: ✨THREADKIT✨ to get free ground shipping if you purchase one of our thread kits! #FreeShipping #threadkit #hydraulicfittings #promo #HappyMarch

ROYALSUPPLY's tweet image. Use your promo code: ✨THREADKIT✨ to get free ground shipping if you purchase one of our thread kits! #FreeShipping  #threadkit #hydraulicfittings #promo #HappyMarch

Found a #maldoc #threadkit -> #betabot hxxp://trashbin[.]pw/bin/p/logout.php hxxp://www[.]gallerdo.[i]nfo/d7/config.php?account=diego app.any.run/tasks/8e2865d2…

Zerophage1337's tweet image. Found a #maldoc #threadkit -&amp;gt; #betabot 

hxxp://trashbin[.]pw/bin/p/logout.php  
hxxp://www[.]gallerdo.[i]nfo/d7/config.php?account=diego

app.any.run/tasks/8e2865d2…

Done, should match the initial #threadkit and this recent one. pastebin.com/EE4SqW1G


Precision meets craftsmanship with our Advance Thread Solution 1-1/2-6 UNC Kit, beautifully encased in a premium wooden box. Perfect for all your threading needs, with durability that stands the test of time. 🛠️ #ThreadKit #Craftsmanship #PrecisionTools #Rapicoil


Use your promo code: ✨THREADKIT✨ to get free ground shipping if you purchase one of our thread kits! #FreeShipping #threadkit #hydraulicfittings #promo #HappyMarch

ROYALSUPPLY's tweet image. Use your promo code: ✨THREADKIT✨ to get free ground shipping if you purchase one of our thread kits! #FreeShipping  #threadkit #hydraulicfittings #promo #HappyMarch

Malicious document builders like #LCGKit and #ThreadKit have recently become a common tool for attackers. Now they're adding Microsoft Word macro capabilities. hubs.ly/H0hrVQp0


is this something specific to #threadkit?


#Threadkit exploit kit is distributing #Formbook malware targeting an old vulnerability. The 2017 bug was discovered, exploited and patched back in July 2017, but that hasn’t stopped it from viewing the exploit as still valuable. ow.ly/Iqf230nClMo


Pretty sweet #threadkit doc via #malspam, is #pony with c2 of: http://www.a10gamesa10[.]com/php/gate.php cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_

James_inthe_box's tweet image. Pretty sweet #threadkit doc via #malspam, is #pony with c2 of:

http://www.a10gamesa10[.]com/php/gate.php

cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_
James_inthe_box's tweet image. Pretty sweet #threadkit doc via #malspam, is #pony with c2 of:

http://www.a10gamesa10[.]com/php/gate.php

cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_

Pretty sweet #threadkit doc via #malspam, is #pony with c2 of: http://www.a10gamesa10[.]com/php/gate.php cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_

James_inthe_box's tweet image. Pretty sweet #threadkit doc via #malspam, is #pony with c2 of:

http://www.a10gamesa10[.]com/php/gate.php

cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_
James_inthe_box's tweet image. Pretty sweet #threadkit doc via #malspam, is #pony with c2 of:

http://www.a10gamesa10[.]com/php/gate.php

cc @benkow_ @Xylit0l @Anti_Expl0it @h3x2b @cocaman @0Btemos_BHS @fumik0_

First run is absolutely #LokiBot, doc uses #threadkit by the look of it...not sure what to make of <snicker> this though.

James_inthe_box's tweet image. First run is absolutely #LokiBot, doc uses #threadkit by the look of it...not sure what to make of &amp;lt;snicker&amp;gt; this though.

doc files are #threadkit as well...cc @cocaman

James_inthe_box's tweet image. doc files are #threadkit as well...cc @cocaman

New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named "saver.scr". app.any.run/tasks/efceacee… virustotal.com/#/file/73b61af…

3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…
3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…
3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…
3pun0x's tweet image. New #ThreadKit campaign. Malicious doc (RTF exploit #CVE-2017-8570) drops SCT, decoy doc, cmd files, kill-switch (blOCk.tXt) and finally payload named &quot;saver.scr&quot;. 
app.any.run/tasks/efceacee…
virustotal.com/#/file/73b61af…

#threadkit dropping #formbook via #malspam; c2 sites here: pastebin.com/P5Z80Bzu hash aa590a773eb2297f2d474d11792f6311 for the doc on @mal_share

James_inthe_box's tweet image. #threadkit dropping #formbook via #malspam; c2 sites here:

pastebin.com/P5Z80Bzu

hash aa590a773eb2297f2d474d11792f6311 for the doc on @mal_share
James_inthe_box's tweet image. #threadkit dropping #formbook via #malspam; c2 sites here:

pastebin.com/P5Z80Bzu

hash aa590a773eb2297f2d474d11792f6311 for the doc on @mal_share

#LokiBot #ThreadKit 103_010COUS180790001_6412663116-09-04-18.doc 8c64c1f6830691ac48a80dc7cd30e0f3 185.82.202.87 POST /~zadmin/cam/conn.php Subject: SWIFT Transfer (103) 010COUS180790001 From: [email protected] [+] WebShell Active

pollo290987's tweet image. #LokiBot #ThreadKit
103_010COUS180790001_6412663116-09-04-18.doc
8c64c1f6830691ac48a80dc7cd30e0f3

185.82.202.87 POST /~zadmin/cam/conn.php

Subject: SWIFT Transfer (103) 010COUS180790001
From: swift@dtbafrica.com

[+] WebShell Active

#threadkit #maldoc #rtf sample seems to be very busy. Had a lot of signature hits, not sure how many are true. @malwrhunterteam Run at: app.any.run/tasks/16deb6c8…

Zerophage1337's tweet image. #threadkit #maldoc #rtf sample seems to be very busy. Had a lot of signature hits, not sure how many are true. @malwrhunterteam 
Run at: app.any.run/tasks/16deb6c8…
Zerophage1337's tweet image. #threadkit #maldoc #rtf sample seems to be very busy. Had a lot of signature hits, not sure how many are true. @malwrhunterteam 
Run at: app.any.run/tasks/16deb6c8…

Use your promo code: ✨THREADKIT✨ to get free ground shipping if you purchase one of our thread kits! #FreeShipping #threadkit #hydraulicfittings #promo #HappyMarch

ROYALSUPPLY's tweet image. Use your promo code: ✨THREADKIT✨ to get free ground shipping if you purchase one of our thread kits! #FreeShipping  #threadkit #hydraulicfittings #promo #HappyMarch

#threadkit , bad times ahead if you open this maldoc.. "Urgent Overdue Outstanding Payement.doc" app.any.run/tasks/ed7813ca…

Zerophage1337's tweet image. #threadkit , bad times ahead if you open this maldoc.. &quot;Urgent Overdue Outstanding Payement.doc&quot;
app.any.run/tasks/ed7813ca…
Zerophage1337's tweet image. #threadkit , bad times ahead if you open this maldoc.. &quot;Urgent Overdue Outstanding Payement.doc&quot;
app.any.run/tasks/ed7813ca…

Booby-trapped Office docs build with #ThreadKit trigger #CVE20184878 flaw dlvr.it/QP1rjd

h8v6com's tweet image. Booby-trapped Office docs build with #ThreadKit trigger #CVE20184878 flaw dlvr.it/QP1rjd

Found a #maldoc #threadkit -> #betabot hxxp://trashbin[.]pw/bin/p/logout.php hxxp://www[.]gallerdo.[i]nfo/d7/config.php?account=diego app.any.run/tasks/8e2865d2…

Zerophage1337's tweet image. Found a #maldoc #threadkit -&amp;gt; #betabot 

hxxp://trashbin[.]pw/bin/p/logout.php  
hxxp://www[.]gallerdo.[i]nfo/d7/config.php?account=diego

app.any.run/tasks/8e2865d2…

Looks like a modified #threadkit doc but I don't know what the payload is. It does periodically run a .txt file as an EXE and I'm guessing the DNS requests are connectivity checks. Any thoughts? @Antelox @malwrhunterteam @James_inthe_box @avman1995 app.any.run/tasks/8056a83d…

Zerophage1337's tweet image. Looks like a modified #threadkit doc but I don&apos;t know what the payload is. It does periodically run a .txt file as an EXE and I&apos;m guessing the DNS requests are connectivity checks. Any thoughts? @Antelox @malwrhunterteam @James_inthe_box @avman1995 

app.any.run/tasks/8056a83d…
Zerophage1337's tweet image. Looks like a modified #threadkit doc but I don&apos;t know what the payload is. It does periodically run a .txt file as an EXE and I&apos;m guessing the DNS requests are connectivity checks. Any thoughts? @Antelox @malwrhunterteam @James_inthe_box @avman1995 

app.any.run/tasks/8056a83d…

Two #threadkit #rtf docs dropping #Azorult both docs had 8/59 on VT and one seemed blockchain themed. maksssnd[.]beget[.]tech/index.php 94[.]250.248.105/task.bat app.any.run/tasks/caab858a… app.any.run/tasks/1e37e603…

Zerophage1337's tweet image. Two #threadkit #rtf docs dropping #Azorult both docs had 8/59 on VT and one seemed blockchain themed.

maksssnd[.]beget[.]tech/index.php
94[.]250.248.105/task.bat

app.any.run/tasks/caab858a…
app.any.run/tasks/1e37e603…
Zerophage1337's tweet image. Two #threadkit #rtf docs dropping #Azorult both docs had 8/59 on VT and one seemed blockchain themed.

maksssnd[.]beget[.]tech/index.php
94[.]250.248.105/task.bat

app.any.run/tasks/caab858a…
app.any.run/tasks/1e37e603…

Booby-trapped Office docs build with #ThreadKit trigger #CVE_2018_4878 flaw bit.ly/2Ex82c0

noleadershipgap's tweet image. Booby-trapped Office docs build with #ThreadKit trigger #CVE_2018_4878 flaw bit.ly/2Ex82c0

#Researchers have discovered a new version of #ThreadKit, #malware known to be used by Cobalt Group, first identified in 2016, according to Fidelis #Cybersecurity. Find out more here: cysec-rco.com/2018/12/18/cob…

CysecResourceCo's tweet image. #Researchers have discovered a new version of #ThreadKit, #malware known to be used by Cobalt Group, first identified in 2016, according to Fidelis #Cybersecurity. Find out more here: cysec-rco.com/2018/12/18/cob…

Loading...

Something went wrong.


Something went wrong.


United States Trends