Geekmaster πŸ‘½:system76: · @Geekmaster
199 followers · 1408 posts · Server ioc.exchange

⚠️ New ⚠️
Saw a new phishing vector hit my systems today: Code . Had a user report that they got a "Security Authentication" request via email, which presented a QR code for them to scan. I collected the for this one just now on my . Direct link: github.com/Geekmaster-General/

#phishing #vector #qr #iocs #github

Last updated 1 year ago

Geekmaster πŸ‘½:system76: · @Geekmaster
196 followers · 1397 posts · Server ioc.exchange

Been seeing a lot more very sophisticated MocuSign () emails this week. I have been updating my list on my . Fraudsters are doing a much better job on their contents, even using legitimate non-phishing sites as proxy to redirect to the actual site so they get by email scanners - but they haven't yet gotten past my protections (so far, so good).

Keep up-to-date on my findings on my so you can add them to your platforms as well. I update them multiple times per week: github.com/Geekmaster-General/

#docusign #phishing #ioc #github #endpoint #iocs #repository

Last updated 1 year ago

Geekmaster πŸ‘½:system76: · @Geekmaster
196 followers · 1397 posts · Server ioc.exchange
SarlackLab · @SarlackLab
33 followers · 249 posts · Server ioc.exchange

Command-and-control IPv4 map, 2023-07-30 to 2023-08-12
abjuri5t.github.io/SarlackLab/

185.215.113[.]0/24
82.115.223[.]0/24
185.106.92[.]0/24
45.15.156[.]0/24
194.36.177[.]0/24
94.142.138[.]0/24
77.73.134[.]0/24
91.103.252[.]0/24
193.106.190[.]0/23

#iocs

Last updated 1 year ago

Geekmaster πŸ‘½:system76: · @Geekmaster
192 followers · 1387 posts · Server ioc.exchange

Great blog post by a colleague of mine who asks why "Security through obscurity" is not dead in 2023! How many " " is it going to take to finally realize that keeping your a secret is a good thing? How many times does the have to demonstrate that sharing of , , , , methods, , and everything else that goes along with having a approach to a , is ACTUALLY THE GOOD THING 🀨

(ahem)

You want to know about the platform I architected? No problem! πŸ‘ŒπŸ»
You want to know what Threat Intelligence I gather? Check my GitHub (link on my profile 😁).
You want the keys to my kingdom? 🀣 No, but thanks for playing πŸ‘πŸ»

I'm NOT saying yourself or open some dark to your systems. Just share the knowledge of how you're protecting stuff! Everyone is more for it, and the next generation will make it better.

kalahari.substack.com/p/securi

#cybersecurity #INCIDENTS #securitycontrols #cybercommunity #threatintelligence #TTPs #iocs #securityconcepts #awarenesstraining #zerodays #defenseindepth #healthysecurityprogram #compromise #backdoor #secure

Last updated 1 year ago

SarlackLab · @SarlackLab
25 followers · 178 posts · Server ioc.exchange

Command-and-control domain tree, 2023-06-27 to 2023-07-10
abjuri5t.github.io/SarlackLab/

*.gz[.]apigw[.]tencentcs[.]com
*.sh[.]apigw[.]tencentcs[.]com
*.bj[.]apigw[.]tencentcs[.]com
*.z01[.]azurefd[.]net
*.com[.]s3[.]bucket-amazon[.]com

#iocs

Last updated 1 year ago

SarlackLab · @SarlackLab
25 followers · 174 posts · Server ioc.exchange

Command-and-control IPv4 map, 2023-06-26 to 2023-07-09
abjuri5t.github.io/SarlackLab/

176.111.174[.]0/24
77.91.68[.]0/24
103.234.72[.]0/24
79.110.49[.]0/24
91.103.252[.]0/24
45.12.253[.]0/24
45.154.98[.]0/24
87.251.67[.]0/24
94.142.138[.]0/24
185.252.179[.]0/24

#iocs

Last updated 1 year ago

Geekmaster πŸ‘½:system76: · @Geekmaster
177 followers · 1311 posts · Server ioc.exchange
SarlackLab · @SarlackLab
21 followers · 149 posts · Server ioc.exchange

Command-and-control domain tree, 2023-06-05 to 2023-06-18
abjuri5t.github.io/SarlackLab/

*.gz[.]apigw[.]tencentcs[.]com
*.sh[.]apigw[.]tencentcs[.]com
*.z01[.]azurefd[.]net
*.bj[.]apigw[.]tencentcs[.]com
*.com[.]s3[.]bucket-amazon[.]com

#iocs

Last updated 1 year ago

Brett :cheers: · @brett
512 followers · 359 posts · Server mas.town

If you can't answer whether you have in your environment, now is the time to engage all elements of your IT team. There are two recently assigned :

-2023-35036Β (June 9, 2023)
-2023-34362Β (May 31, 2023)

If you identify unpatched instances of MOVEit in your environment, you may want to consider moving to the detect/assess phase of the Incident Response framework.

Details and here:

progress.com/security/moveit-t

#moveit #cves #cve #nist #iocs #cybersecurity

Last updated 1 year ago

Geekmaster πŸ‘½:system76: · @Geekmaster
166 followers · 1262 posts · Server ioc.exchange
Geekmaster πŸ‘½:system76: · @Geekmaster
166 followers · 1246 posts · Server ioc.exchange
dubbel · @dubbel
120 followers · 259 posts · Server mstdn.io

Reported malicious python package "colors5", downloading an executable on setup from
https://resetname.peanutgamerdot.repl[.]co/Built.exe

It's the best documented malicious package I've seen, with helpful comments like

# write the malware to a file
# attempt to add a windows defender exclusion if the person runs our batch as admin
the malware

The only attempt at evasion is the screen-full of newlines before this code. :blob_confused:

#run #python #pypi #malware #iocs #threatintel

Last updated 1 year ago

SarlackLab · @SarlackLab
16 followers · 81 posts · Server ioc.exchange

Command-and-control IPv4 map, 2023-04-11 to 2023-04-24
abjuri5t.github.io/SarlackLab/

143.92.58[.]96/30
94.142.138[.]0/24
45.15.156[.]0/24
103.231.31[.]128/26
37.220.87[.]0/24
91.215.85[.]0/24
45.227.255[.]192/26
83.217.11[.]0/24
179.60.146[.]0/24

#iocs

Last updated 1 year ago

mithrandir · @mithrandir
63 followers · 143 posts · Server defcon.social

Seeing more similar samples today, all coming from malicious ads. Some keywords have been "pdf-tools" and "Advanced IP Scanner".

Payloads are MSIX files containing a PowerShell script which downloads the stealer.

IOCs:
adv-sect[.]site
advert-job[.]ru
pdf-editor[.]store
advanced-ip-scanner[.]world/

Ad Domains:
tucsontreeservicecompany[.]com
branchmanconstruction[.]com

#google #redline #iocs #malware #malvertising

Last updated 1 year ago

SarlackLab · @SarlackLab
11 followers · 55 posts · Server ioc.exchange

Command-and-control IPv4 map, 2023-03-26 to 2023-04-08
abjuri5t.github.io/SarlackLab/

94.142.138[.]0/24
202.79.174[.]24/29
45.15.156[.]0/24
46.161.27[.]160/28
45.9.74[.]0/24
83.217.11[.]0/24
37.220.87[.]0/24
45.227.255[.]192/26
185.106.92[.]0/24
77.73.134[.]0/24

#iocs

Last updated 1 year ago

Geekmaster πŸ‘½:system76: · @Geekmaster
156 followers · 1212 posts · Server ioc.exchange

⚠️ ⚠️
You may have heard that got compromised. You can get details here: cisa.gov/news-events/alerts/20 or here 3cx.com/blog/news/desktopapp-s

here: crowdstrike.com/blog/crowdstri

If you use this platform, and have one of the compromised versions running, uninstall it and use the web interface for now, then wait for the new release.

#supplychainhackalert #3cx #iocs

Last updated 1 year ago

Colin Cowie · @th3_protoCOL
681 followers · 303 posts · Server infosec.exchange

My latest blog: Decoding a New JavaScript Malware Campaign!
πŸ”—β€‹ th3protocol.com/2023/New-JS-Ma

Earlier today researchers from HuntressLabs shared observations about a case involving RClone. They identified initial access as a javascript file named β€œInvoice-DocuSign-Mar03-2023.js"

In my blog post I walk through analyzing this JavaScript malware, identifying persistency and decoding C2 traffic!
: github.com/colincowie/colincow

πŸ”—β€‹ poc for decoding the C2 traffic:
gist.github.com/colincowie/2bb

πŸ’¬β€‹ Authors Note:
Recently I've been feeling a little bit burnt out - this research excited me and provided some internal encouragement πŸ˜ƒ

​​

#AvosLocker #iocs #threatintel #cti #malware #ransomware #javascript #virustotal

Last updated 1 year ago

SarlackLab · @SarlackLab
6 followers · 18 posts · Server ioc.exchange

Command-and-control domain tree, 2023-02-21 to 2023-03-06
abjuri5t.github.io/SarlackLab/

*.apigw[.]tencentcs[.]com
*.ssndob[.]cn[.]com
*.z01[.]azurefd[.]net
*.dnsv1[.]com[.]cn
*.w[.]kunluncan[.]com
*.prod[.]fastly[.]net

#iocs

Last updated 1 year ago