12.
David Ledbetter
@Ledtech3
Mass scanning activity detected from multiple hosts in checking for SolarWinds Orion hosts vulnerablโฆ twitter.com/i/web/status/1โฆ
Retweet of status by @bad_packets
29 Dec 20
copy & paste +upvote -downvote Mass scanning activity detected from multiple hosts in ๐บ๐ธ ๐จ๐ณ ๐ญ๐ฐ ๐ท๐ด ๐ฎ๐ช checking for SolarWinds Orion hosts vulnerablโฆ https://t.co/iafP9AOXWA
13.
David Ledbetter
@Ledtech3
2020-09-07: #Zloader Banker Malware #CobaltStrike ๏ธHTTPS Beacon Install
cfg:
C2Server:cloudome. net,/ca
โฆ twitter.com/i/web/status/1โฆ
cfg:
C2Server:cloudome. net,/ca
โฆ twitter.com/i/web/status/1โฆ
07 Sep 20
copy & paste +upvote -downvote 2020-09-07: ๐๐ฆ#Zloader Banker Malware โก๏ธ#CobaltStrike โ๏ธHTTPS Beacon Install
cfg:
โ๏ธC2Server:cloudome. net,/ca
โ๏ธโฆ https://t.co/sJjv1vEJ30
14.
15.
16.
17.
18.
David Ledbetter
@Ledtech3
New CryptoTester v1.4.0.2 for #ransomware analysis : TONS of fixes/additions to hexboxes, grouped algorithms in dโฆ twitter.com/i/web/status/1โฆ
Retweet of status by @demonslay335
19 Apr 20
copy & paste +upvote -downvote ๐New CryptoTester v1.4.0.2 for #ransomware analysis ๐: TONS of fixes/additions to hexboxes, grouped algorithms in dโฆ https://t.co/upa9sbxCDu
David Ledbetter
@Ledtech3
small #sysmon quiz, what's abnormal (if any) in those logs pic.twitter.com/0nJOM0Q30I
Retweet of status by @SBousseaden
21 Mar 20
copy & paste +upvote -downvote small #sysmon quiz, what's abnormal (if any) in those logs ๐ง https://t.co/0nJOM0Q30I
David Ledbetter
@Ledtech3
25 Feb 20
copy & paste +upvote -downvote @InQuest @Valcan_K well a big red flag in this case was it was downloading something from github ??๐คจ
David Ledbetter
@Ledtech3
@bry_campbell Um, Ok.
At first I couldn't tell if it was software or hardware they were selling.
I'm pretty sure it is software
At first I couldn't tell if it was software or hardware they were selling.
I'm pretty sure it is software
27 Nov 19
copy & paste +upvote -downvote @bry_campbell Um, Ok.
At first I couldn't tell if it was software or hardware they were selling.
I'm pretty sure it is software ๐ค
David Ledbetter
@Ledtech3
@papa_anniekey @Cryptolaemus1 Not all of them.
Keep digging
Keep digging
16 Sep 19
copy & paste +upvote -downvote @papa_anniekey @Cryptolaemus1 Not all of them.
Keep digging ๐คจ
19.
20.
David Ledbetter
@Ledtech3
WARNING
Remote DNS Change Exploit (Hijack) Detected
Source IP: 34.97.223.23 (@googlecloud)
Target: Multipโฆ twitter.com/i/web/status/1โฆ
Remote DNS Change Exploit (Hijack) Detected
Source IP: 34.97.223.23 (@googlecloud)
Target: Multipโฆ twitter.com/i/web/status/1โฆ
Retweet of status by @bad_packets
23 May 19
copy & paste +upvote -downvote โ ๏ธ WARNING โ ๏ธ
Remote DNS Change Exploit (Hijack) Detected
Source IP: 34.97.223.23 (@googlecloud) ๐บ๐ธ
Target: Multipโฆ https://t.co/cu7Scx0fYj
David Ledbetter
@Ledtech3
@decalage2 @StanHacked I would like to see some samples of these to see for myself , just how "Hidden" they can be.
29 Mar 19
copy & paste +upvote -downvote @decalage2 @StanHacked I would like to see some samples of these to see for myself , just how "Hidden" they can be.๐ค
...but wait! There's more!
12.
fakhright
@fakhright
astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat*
14 Jan 13
copy & paste +upvote -downvote astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat* ๐๐๐