1.
TheAnalyst
@ffforward
@logwithtrunc @WordPress No never heard back from anyone and haven't seen anything new about since that time...
16 Sep 22
copy & paste +upvote -downvote @logwithtrunc @WordPress No never heard back from anyone and haven't seen anything new about since that time... 🤔
2.
TheAnalyst
@ffforward
They have a nice invalid cert to pivot on too, #FJJGRZHNSCPISZVYBX. I know you love these @JAMESWT_MHT
bazaar.abuse.ch/sample/4f13d35…
bazaar.abuse.ch/sample/4f13d35…
08 Sep 22
copy & paste +upvote -downvote They have a nice invalid cert to pivot on too, #FJJGRZHNSCPISZVYBX. I know you love these @JAMESWT_MHT 😅
https://t.co/52iL8y90zN
3.
4.
5.
6.
7.
TheAnalyst
@ffforward
/top.noneabusers.xyz is probably one of the better C2s I've ever have seen
#Remcos
#Remcos
16 Jun 22
copy & paste +upvote -downvote /top.noneabusers.xyz is probably one of the better C2s I've ever have seen 🤣
#Remcos
TheAnalyst
@ffforward
NEW: @k3dg3 and @Myrtus0x0 join us to talk all things cybercrime, why Pim loves and hates Emotet, what makes Bumbl… twitter.com/i/web/status/1…
Retweet of status by @selenalarson
07 Jun 22
copy & paste +upvote -downvote 🎙NEW: @k3dg3 and @Myrtus0x0 join us to talk all things cybercrime, why Pim loves and hates Emotet, what makes Bumbl… https://t.co/a0wCoVYnYs
TheAnalyst
@ffforward
#Emotet Update - Looks like Ivan was experimenting with 64 bit XLLs on the week of April 11th. This is big news! A… twitter.com/i/web/status/1…
Retweet of status by @Cryptolaemus1
26 Apr 22
copy & paste +upvote -downvote #Emotet Update 🚨- Looks like Ivan was experimenting with 64 bit XLLs on the week of April 11th. This is big news! A… https://t.co/m06A6UulZb
TheAnalyst
@ffforward
#Fake "Windows11 Installation Assistant"
bazaar.abuse.ch/sample/d220553…
Run
app.any.run/tasks/5cc9b70d…
> vssadmin delete… twitter.com/i/web/status/1…
bazaar.abuse.ch/sample/d220553…
Run
app.any.run/tasks/5cc9b70d…
> vssadmin delete… twitter.com/i/web/status/1…
Retweet of status by @JAMESWT_MHT
23 Apr 22
copy & paste +upvote -downvote #Fake "Windows11 Installation Assistant"
👇
https://t.co/tFTjCxK6qF
Run👇
https://t.co/8qcTG6wBjV
> vssadmin delete… https://t.co/jWpWKYllre
TheAnalyst
@ffforward
Unknown loader (+panel) exposed in #Conti Jabber logs
"ts": "2021-02-11T16:08:14.394172" pic.twitter.com/kM5GUaUNTK
"ts": "2021-02-11T16:08:14.394172" pic.twitter.com/kM5GUaUNTK
28 Feb 22
copy & paste +upvote -downvote Unknown loader (+panel) exposed in #Conti Jabber logs
"ts": "2021-02-11T16:08:14.394172" 🧐 https://t.co/kM5GUaUNTK
8.
9.
10.
11.
TheAnalyst
@ffforward
To all my fellow researchers out there
Roses are red
Violets are blue
Threat actors feel fear
Because of you
Roses are red
Violets are blue
Threat actors feel fear
Because of you
14 Feb 22
copy & paste +upvote -downvote ❤️To all my fellow researchers out there❤️
Roses are red
Violets are blue
Threat actors feel fear
Because of you
TheAnalyst
@ffforward
@BleepinComputer @Ionut_Ilascu I wonder when they will share defense tips of maldocs on onedrive leading to Conti?
18 Oct 21
copy & paste +upvote -downvote @BleepinComputer @Ionut_Ilascu I wonder when they will share defense tips of maldocs on onedrive leading to Conti? 🧐
TheAnalyst
@ffforward
BazarCall to Conti Ransomware via Trickbot and Cobalt Strike
Initial Access: maldoc (#BazarCall)
Discovery: Ad… twitter.com/i/web/status/1…
Initial Access: maldoc (#BazarCall)
Discovery: Ad… twitter.com/i/web/status/1…
Retweet of status by @TheDFIRReport
02 Aug 21
copy & paste +upvote -downvote BazarCall to Conti Ransomware via Trickbot and Cobalt Strike
➡️Initial Access: maldoc (#BazarCall)
➡️Discovery: Ad… https://t.co/LLvSubibC0
TheAnalyst
@ffforward
@ANeilan #RedlineStealer that drops Chrome install when done. Couldn't they have dropped @CCleaner instead? … twitter.com/i/web/status/1…
24 Mar 21
copy & paste +upvote -downvote @ANeilan #RedlineStealer that drops Chrome install when done. Couldn't they have dropped @CCleaner instead? 😅… https://t.co/hxRzmIhoPS
...but wait! There's more!
1.
fakhright
@fakhright
astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat*
14 Jan 13
copy & paste +upvote -downvote astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat* 🙈🙈🙊