· @kioan
26 followers · 84 posts · Server mastodon.social

Another campaign trying to trick users into supplying their credentials:
🎣https[:]//jccm.com[.]ve/camezs/MailUpdateFresh/index.html

📧email via mail9.uitech[.]jp
☁️hosted by @Cloudflare

Webserver shows multiple phishing sites.

#phishing #opendir #infosec #cybersecurity #ioc

Last updated 3 years ago

StalkPhish · @stalkphish_io
17 followers · 17 posts · Server infosec.exchange

Hive... again!

Detected by Stalkphish.io

Targeting @USPS @swisspost


#phishingkit #phishing #soc #cybersecurity #scam #stalkphish #opendir

Last updated 3 years ago

James_inthe_box · @james_inthe_box
213 followers · 58 posts · Server infosec.exchange

@Myrtus @da_667 is a classic for a tab as well.

#opendir

Last updated 3 years ago

[Threatview.io ] 🔥 Our latest collection on using telemetry gathered through our proactive hunter "Peaking inside an malicious host using on "37.77.239[.]239"

⚠️ Previously & C2 were hosted on the IP
⚠️
⚠️

virustotal.com/gui/collection/


#virustotal #opendir #qakbot #redline #ransomware #hacktools #threatintel #dfir

Last updated 3 years ago

[Threatview.io ] 🔥 Our latest collection on using telemetry gathered through our proactive hunter "Peaking inside toolkit of using on 95.213.145[.]101"



⚠️PoshC2
⚠️Netscan
⚠️Mimikatz
⚠️ PowerShell

virustotal.com/gui/collection/

#virustotal #medusalokcker #opendir #threatintel #dfir #cobaltstrike

Last updated 3 years ago

[Threatview.io ] 🔥 Our latest collection on using telemetry gathered through our proactive hunter "Peaking inside toolkit of using on "62.182.159[.]147"

virustotal.com/gui/collection/

⚠️Mimikatz
⚠️Netscan
⚠️PoshC2
⚠️Cobaltstrike
⚠️Netscan
⚠️Historic detections on host also shows use of C2 along with





#virustotal #medusalokcker #opendir #mythic #cobaltstrike #threatintel #dfir #cybersecurity #threatintelligence #poshc2

Last updated 3 years ago

James_inthe_box · @james_inthe_box
183 followers · 52 posts · Server infosec.exchange

Some shenanigans at:

4.204.233.44/dll
4.204.233.44/rump

leading to

#opendir #agenttesla

Last updated 3 years ago

· @kioan
5 followers · 15 posts · Server mastodon.social

emails were sent to potential victims from an with Leaf PHPMailer

#phishing #opendir #spam

Last updated 3 years ago

· @kioan
5 followers · 22 posts · Server mastodon.social

emails were sent to potential victims from an with Leaf PHPMailer

#phishing #opendir #spam

Last updated 3 years ago

· @kioan
5 followers · 14 posts · Server mastodon.social

emails were sent to potential victims from an with Leaf PHPMailer

#phishing #opendir #spam

Last updated 3 years ago

avc · @avc
5 followers · 5 posts · Server infosec.exchange

http://18.190.153.173:8080/ again ;)

#opendir

Last updated 3 years ago

avc · @avc
5 followers · 5 posts · Server infosec.exchange

@Gerald_Auger It looks like .

#opendir

Last updated 3 years ago

@avc is this an or?

Quite a repo, and cobaltstrike to boot. I'm aware of opendir but don't really run in those circles so just asking/guessing. Thx.

#opendir

Last updated 3 years ago

Oliver Hough · @olihough86
12 followers · 875 posts · Server infosec.exchange

Multi Service Phishing page & kit

hxxps://aptitudelyfit.in/wp-includes/Mercy/SYNCDATA/login.php

Kit in hxxps://aptitudelyfit.in/wp-includes/Mercy/

Actor email: Allahmercyisreal@gmail.com

#opendir

Last updated 6 years ago

Oliver Hough · @olihough86
12 followers · 875 posts · Server infosec.exchange

complete with manual in Russian

hxxp://qwerkkc.ru/

#godzillaloader #opendir

Last updated 7 years ago