Kyle Ehmke(@kyleehmke) 's Twitter Profileg
Kyle Ehmke

@kyleehmke

Threat intel researcher focused on infrastructure hunting. Views are my own and not my employer's. Others: @[email protected] @kyleehmke.bsky.social

ID:2419824120

calendar_today31-03-2014 02:13:47

2,0K Tweets

5,1K Followers

305 Following

Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Another John Mark Dougan domain administered via the same account as britishchronicle[.]com, gbgeopolitics[.]com, and londonchronicle[.]news: foreignagentintel[.]com

Another John Mark Dougan domain administered via the same account as britishchronicle[.]com, gbgeopolitics[.]com, and londonchronicle[.]news: foreignagentintel[.]com
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domains softupdate[.]org (5.45.93[.]209) and teamsupdate[.]org (5.61.51[.]33) were registered in short proximity through Njalla on 4/3.

Suspicious domains softupdate[.]org (5.45.93[.]209) and teamsupdate[.]org (5.61.51[.]33) were registered in short proximity through Njalla on 4/3.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domain docstorage[.]link was registered through Njalla on 4/2. It and subdomain drv[.]docstorage[.]link resolve to 212.46.38[.]222 and redirect to legitimate Microsoft sites.

Suspicious domain docstorage[.]link was registered through Njalla on 4/2. It and subdomain drv[.]docstorage[.]link resolve to 212.46.38[.]222 and redirect to legitimate Microsoft sites.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Couple additional, recent John Mark Dougan domains to tack onto the below thread:

xposedem[.]com
vidvist[.]com
londoncrier[.]co[.]uk
londoncrier[.]com

Couple additional, recent John Mark Dougan domains to tack onto the below thread: xposedem[.]com vidvist[.]com londoncrier[.]co[.]uk londoncrier[.]com
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domain msdn-live[.]com was registered through Njalla on 3/25 and resolves to 89.147.109[.]166. Domain is hosting a remote support portal.

Suspicious domain msdn-live[.]com was registered through Njalla on 3/25 and resolves to 89.147.109[.]166. Domain is hosting a remote support portal.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Some recent domains administered via Parscale / Nucleus accounts indicating the company has done work for websites related to a Jair Bolsonaro-led protest and event:
dia25euvou[.]com[.]br
euapoioisrael[.]com[.]br

Some recent domains administered via Parscale / Nucleus accounts indicating the company has done work for websites related to a Jair Bolsonaro-led protest and event: dia25euvou[.]com[.]br euapoioisrael[.]com[.]br
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Couple of Parscale / Nucleus domains purporting to be local news:
buckeyestatenews[.]com
bigskyprospector[.]com

Site content currently in development.

Couple of Parscale / Nucleus domains purporting to be local news: buckeyestatenews[.]com bigskyprospector[.]com Site content currently in development.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domain msftauth[.]com was registered through Njalla on 2/15. Co-located with the similarly registered (1/31) domain googlservices[.]com at 195.85.114[.]11.

Suspicious domain msftauth[.]com was registered through Njalla on 2/15. Co-located with the similarly registered (1/31) domain googlservices[.]com at 195.85.114[.]11.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domain salesmicrosoft[.]com was registered through RockHoster on 2/13 and resolves to 104.248.200[.]223.

Suspicious domain salesmicrosoft[.]com was registered through RockHoster on 2/13 and resolves to 104.248.200[.]223.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domain intel-drivers[.]com was registered through Njalla on 2/6 and is resolving to IPs 193.142.30[.]96 and 193.142.30[.]81.

Suspicious domain intel-drivers[.]com was registered through Njalla on 2/6 and is resolving to IPs 193.142.30[.]96 and 193.142.30[.]81.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domain worldclksyncsvr[.]com was registered through Njalla on 2/2 and resolves to 5.255.118[.]21.

Suspicious domain worldclksyncsvr[.]com was registered through Njalla on 2/2 and resolves to 5.255.118[.]21.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domains registered separately through OrangeWebsite on 1/30 that resolve to nondedicated infrastructure, but have subs on dedicated infrastructure:
msedge-srv2[.]com
db2.msedge-srv2[.]com (91.207.183[.]103)
msedge-tenet[.]com
zone1.msedge-tenet[.]com (91.207.183[.]222)

Suspicious domains registered separately through OrangeWebsite on 1/30 that resolve to nondedicated infrastructure, but have subs on dedicated infrastructure: msedge-srv2[.]com db2.msedge-srv2[.]com (91.207.183[.]103) msedge-tenet[.]com zone1.msedge-tenet[.]com (91.207.183[.]222)
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Two sets of suspicious domains registered through Njalla about ten min apart on 1/18:

msft-events[.]com
event-msft[.]com

msftncis[.]com
ncsimsft[.]net

Not definitively related, but timing, theme, and string switching suggest an overlap. Not hosted, but worth keeping an eye on.

Two sets of suspicious domains registered through Njalla about ten min apart on 1/18: msft-events[.]com event-msft[.]com msftncis[.]com ncsimsft[.]net Not definitively related, but timing, theme, and string switching suggest an overlap. Not hosted, but worth keeping an eye on.
account_circle
Kyle Ehmke(@kyleehmke) 's Twitter Profile Photo

Suspicious domains viewandsharedocs[.]com
and pdfview[.]contact were co-registered through Njalla on 1/9 and are hosted at 5.230.44[.]115.

Suspicious domains viewandsharedocs[.]com and pdfview[.]contact were co-registered through Njalla on 1/9 and are hosted at 5.230.44[.]115.
account_circle