ottoto · @ottoto2017
131 followers · 2176 posts · Server prattohome.com

自インスタンスの を検査していたら、また、, Inc. が隠しポートをノックしていました。

懲りませんね。

止めろ!! 止めろ!!

#sshログ #censys #prattohome

Last updated 1 year ago

ottoto · @ottoto2017
131 followers · 2165 posts · Server prattohome.com

自インスタンスの を検査していたら、また、, Inc. が隠しポートをノック。

本当に頻度が高い。こいつら、一つ一つの IP Address の すべてのポートをランダムに(管理はされている)に別々の IP Address からアクセスする方法でクロールする。内部的には一つの IP Address に対して、すべての したことになる。やり口が巧妙と言うか、汚いと言うか。あきれるほどの慎重さ。

皆さんも是非、こいつらのやっていることを自インスタンスで確認してください。

#sshログ #censys #ポートスキャン #prattohome

Last updated 1 year ago

ottoto · @ottoto2017
125 followers · 1667 posts · Server prattohome.com

自インスタンスの を検査していて、 を発見。80.66.66[.]159 から。

登録名は XHOST INTERNET SOLUTIONS LP
で住所はイギリス。
使用ネットワークはフィンランドで、サーバーはフィンランド。
ところが 連絡先がロシア。

結局のところ 勢の不正アクセスと断定。

強引にアクセスしようとして失敗。腹立たしい。

もう一件はいつもの , Inc.(167.94.138[.]52) 。こちらも腹立たしいが、ロシア勢がこの辺から情報を貰っているおそれもある。ロシア勢がいきなり隠しポートを見つける偵察行動なしで来たので。

ご用心!!

止めろ!!不正アクセス。

#sshログ #不正アクセス #abuse #ロシア #censys #prattohome

Last updated 1 year ago

mle✨ · @mle
464 followers · 189 posts · Server infosec.exchange
mle✨ · @mle
457 followers · 164 posts · Server infosec.exchange

Still tracking ESXiArgs & wrote up a new piece about it, looking more at:

➡️ Historically affected hosts—we initially found 2, but on further investigation found 11 more with a similar ransom note in October 2022
➡️ Spread of the 2 different variants we’ve tracked thus far
➡️ Presence of SLP on infected hosts

Read more: censys.io/esxiargs-history-var

#ransomware #threatresearch #threathunting #cti #censys

Last updated 1 year ago

mle✨ · @mle
453 followers · 140 posts · Server infosec.exchange

We've been tracking the for the last few days, here's what we've seen so far :

🔎 We’ve observed a new variant of ESXiArgs emerge over the last 24 hours. Key updates to this version include:
➡️ A new ransom note with no addresses–making it more difficult for researchers to track payments
➡️ Encryption of additional data, rendering existing decryption tools ineffective

🔎 In the last few days, we’ve seen just over 3,800 unique hosts compromised, and 1,800 which are online currently. Over the last 24 hours, just over 900 hosts have upgraded to the latest ransomware variant.

🔎 As we reported yesterday, OpenSLP does not appear to be the method of attack, given that multiple compromised hosts did not have SLP running.

censys.io/esxwhy-a-look-at-esx

#esxiargs #ransomware #btc #censys #threatresearch #cti

Last updated 2 years ago

mle✨ · @mle
436 followers · 131 posts · Server infosec.exchange
mle✨ · @mle
355 followers · 107 posts · Server infosec.exchange

wrote a little bit about the vulnerability and how things look one year later. 🫣

tl;dr: things aren't *bad*, but why aren't they better? a lot of things got patched and upgraded over 2022, but there are still a non-trivial number of potentially vulnerable devices out there.

censys.io/tis-the-season-%F0%9

#log4j #cve #vulnerability #Log4Shell #infosec #internet #censys

Last updated 2 years ago

mle✨ · @mle
410 followers · 122 posts · Server infosec.exchange

wrote a little bit about the vulnerability and how things look one year later. 🫣

tl;dr: things aren't *bad*, but why aren't they better? a lot of things got patched and upgraded over 2022, but there are still a non-trivial number of potentially vulnerable devices out there.

censys.io/tis-the-season-%F0%9

#log4j #cve #vulnerability #Log4Shell #infosec #internet #censys

Last updated 2 years ago

Aidan H · @thehappydinoa
10 followers · 4 posts · Server infosec.exchange

Interested in fingerprinting C2 severs? Check out these 20+ Censys Search for identifying them: github.com/thehappydinoa/aweso

Just added Empire C2, Raccoon Stealer V2 (RecordBreaker C2), AsyncRAT, and more.
What would you like to see added next?

#osint #censys #dorks #c2 #rat #fingerprinting

Last updated 2 years ago

Aidan H · @thehappydinoa
1 followers · 2 posts · Server infosec.exchange

I am working on a collection of fascinating Censys Search queries. Have a interesting query you want to add? Contributions welcome! github.com/thehappydinoa/aweso

#osint #censys #dorks #query

Last updated 2 years ago

Rules · @yara
34 followers · 966 posts · Server noc.social

and have a competitor.

zoomeye.org/

#censys #shodan

Last updated 4 years ago

Arthur Lutz · @arthurlutzim
375 followers · 4986 posts · Server mamot.fr

watching live 🔴

Internet of Telemetry: I Know What You Did Last Lockdown pretalx.com/rc3/talk/306433/

#rC3 #mqtt #python #geojson #shodan #censys

Last updated 4 years ago