1.
scsideath
@cybersyrupblog
malware @Planner5D
/planner5d-new.com
/planner5d-main.com
/planner5d-app.com
/planner5d-download.com
/planner5d-β¦ twitter.com/i/web/status/1β¦
/planner5d-new.com
/planner5d-main.com
/planner5d-app.com
/planner5d-download.com
/planner5d-β¦ twitter.com/i/web/status/1β¦
Retweet of status by @idclickthat
20 Mar 23
copy & paste +upvote -downvote malware @Planner5D π€
/planner5d-new.com
/planner5d-main.com
/planner5d-app.com
/planner5d-download.com
/planner5d-β¦ https://t.co/VX4rCoGa9s
2.
scsideath
@cybersyrupblog
#OpenCTI 5.5.3 is out ! Notification systems, case management for incident response, 2FA enforcement, assignation,β¦ twitter.com/i/web/status/1β¦
Retweet of status by @FiligranHQ
06 Feb 23
copy & paste +upvote -downvote #OpenCTI 5.5.3 is out π₯³! Notification systems, case management for incident response, 2FA enforcement, assignation,β¦ https://t.co/PpATDJdUYX
3.
4.
5.
6.
7.
scsideath
@cybersyrupblog
Possible #Qakbot
Onenote -> Cmd -> powershell -> rundll32 + ??
Notable Changes...
- C:\\users\\public
- Rundlβ¦ twitter.com/i/web/status/1β¦
Onenote -> Cmd -> powershell -> rundll32 + ??
Notable Changes...
- C:\\users\\public
- Rundlβ¦ twitter.com/i/web/status/1β¦
Retweet of status by @embee_research
10 Feb 23
copy & paste +upvote -downvote Possible #Qakbot π
Onenote -> Cmd -> powershell -> rundll32 + ??
Notable Changes...
- C:\\users\\public
- Rundl⦠https://t.co/S0tDffmhnj
21 Dec 22
copy & paste +upvote -downvote #Qakbot Switched from HTML smuggling to PDF luringπ¨
#TTPs:
[+] Spearphishing Attachment: PDF (T1566.001)
[+] Mali⦠https://t.co/4E51OSSDvA
18 Nov 22
copy & paste +upvote -downvote #Qakbot once again had some surprises π for us this week. See below for a brief overview of what we found. 𧡠1/6
scsideath
@cybersyrupblog
Fresh #CobaltStrike (1day).
Related to ransomware operations
softsupdate[.]com
anushl[.]com pic.twitter.com/HWZTUeiafs
Related to ransomware operations
softsupdate[.]com
anushl[.]com pic.twitter.com/HWZTUeiafs
06 Oct 22
copy & paste +upvote -downvote Fresh #CobaltStrike (1day).
Related to ransomware operations π¨
softsupdate[.]com
anushl[.]com https://t.co/HWZTUeiafs
scsideath
@cybersyrupblog
Royal Ransomware sample:
2598e8adb87976abe48f0eba4bbb9a7cb69439e0c133b21aee3845dfccf3fb8f
Same ransom note asβ¦ twitter.com/i/web/status/1β¦
2598e8adb87976abe48f0eba4bbb9a7cb69439e0c133b21aee3845dfccf3fb8f
Same ransom note asβ¦ twitter.com/i/web/status/1β¦
Retweet of status by @BushidoToken
03 Oct 22
copy & paste +upvote -downvote πβ£οΈ Royal Ransomware sample:
2598e8adb87976abe48f0eba4bbb9a7cb69439e0c133b21aee3845dfccf3fb8f
Same ransom note as⦠https://t.co/ly9FYRA4eg
8.
9.
10.
11.
scsideath
@cybersyrupblog
#CyberChef Recipe 69: Powershell Bumblebee payload. With thanks for help by the amazing @_shtove! First steps areβ¦ twitter.com/i/web/status/1β¦
Retweet of status by @mattnotmax
31 Aug 22
copy & paste +upvote -downvote #CyberChef Recipe 69: Powershell Bumblebee πpayload. With thanks for help by the amazing @_shtove! First steps areβ¦ https://t.co/ZJCPrfHOjl
scsideath
@cybersyrupblog
Hey guys, my #malware #analysis for absolute beginners guide just dropped!
Completely Free
Mistakes to Avoid
β¦ twitter.com/i/web/status/1β¦
Completely Free
Mistakes to Avoid
β¦ twitter.com/i/web/status/1β¦
Retweet of status by @c3rb3ru5d3d53c
23 Jun 22
copy & paste +upvote -downvote Hey guys, my #malware #analysis for absolute beginners guide just dropped!
β
Completely Free
β
Mistakes to Avoid
β
β¦ https://t.co/XLMwEpguRN
scsideath
@cybersyrupblog
Mentioned #Eternity samples
bazaar.abuse.ch/browse/tag/Ete⦠twitter.com/FBussoletti/st⦠pic.twitter.com/7U27ta6BdC
bazaar.abuse.ch/browse/tag/Ete⦠twitter.com/FBussoletti/st⦠pic.twitter.com/7U27ta6BdC
Retweet of status by @JAMESWT_MHT
16 May 22
copy & paste +upvote -downvote Mentioned #Eternity samples
πππ
https://t.co/GcLQ7a0oVF https://t.co/0HFVDTt8rS https://t.co/7U27ta6BdC
scsideath
@cybersyrupblog
#CobaltStrike
IP: 194.37.97.150
C2: /opennetworksystems.com pic.twitter.com/xVNqmLh1so
IP: 194.37.97.150
C2: /opennetworksystems.com pic.twitter.com/xVNqmLh1so
18 May 22
copy & paste +upvote -downvote #CobaltStrike β οΈ
IP: 194.37.97.150
C2: /opennetworksystems.com https://t.co/xVNqmLh1so
...but wait! There's more!
1.
fakhright
@fakhright
astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat*
14 Jan 13
copy & paste +upvote -downvote astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat* πππ