Andrii Kava ☕(@AmadeyMozart1) 's Twitter Profile Photo

🛩️💥🇷🇺 Good detonation of the tank after hitting the of the drone. The detonation occurred after the first hit while the tank was moving.

The work was performed by a company of attack UAVs of the 47th OMBr

account_circle
Andrii Kava ☕(@AmadeyMozart1) 's Twitter Profile Photo

🛩️💥🇷🇺 A good video of a drone hitting 2 occupants. One of which tried to defend itself seems like a big bucket.

The attack was carried out with the support of the community by the forces of .

Result:
-2 Russian soldiers
-1 bucket (accidental loss)

account_circle
Spartakurd(@carducian) 's Twitter Profile Photo

Min pêşmergey Kurdistanim
Amadey cergey meydanim
Be ser û mal û jiyanim
Eyparêzim nîştîmanim

Dest le çekim hell nagirim
Yan ser ekewim yan emirim

account_circle
Mangusta(@Tac_Mangusta) 's Twitter Profile Photo

propagated via compromised USB similar TTPs observed before. Probably same TA 🧐

USB > .lnk > .ps1 > 'Runtime Broker.exe'

S1
🔗s://arstechnica.]com/civis/members/frncbf22.1062014/about/

S2
👾 s://evinfeoptasw.]dedyn.]io/updater.php?from=USB1

#Amadey propagated via compromised USB similar TTPs observed before. Probably same TA 🧐

USB > .lnk > .ps1 > 'Runtime Broker.exe'

S1
🔗s://arstechnica.]com/civis/members/frncbf22.1062014/about/

S2
👾 s://evinfeoptasw.]dedyn.]io/updater.php?from=USB1
account_circle
Fox_threatintel(@banthisguy9349) 's Twitter Profile Photo

c2 that was discovered a while ago on 5.42.64.44 is still active and now recently the ip 91.92.250.47 was observed to be spreading the stealer malware.

Do not download the files outside a secure environment.

the 91.92.250.47 will be taking down shortly from now

#amadey c2 that was discovered a while ago on 5.42.64.44 is still active and now recently the ip 91.92.250.47 was observed to be spreading the stealer malware. 

Do not download the files outside a secure environment.

the 91.92.250.47 will be taking down shortly from now
account_circle
Karol Paciorek(@karol_paciorek) 's Twitter Profile Photo

🔒 Login panel

🌐 : 62.204.41[.78

💻 Panel URL: 62.204.41[.78/8BvxwQdec3/

🔍 Query to urlscan.io:
page.url:'8BvxwQdec3'

📡 Other:
194.116.215[.177/8BvxwQdec3/

🔒 Login panel #Amadey #Stealer

🌐 #opendir: 62.204.41[.78

💻 Panel URL: 62.204.41[.78/8BvxwQdec3/

🔍 Query to @urlscanio:  
page.url:'8BvxwQdec3'

📡 Other:  
194.116.215[.177/8BvxwQdec3/
account_circle
TheProfiler0(@THProfiler) 's Twitter Profile Photo

Amadey CNC targeting with new unique TTP at
h[x][x]p://77[.]91[.]68.52/fuza/1.ps1

$ie_procinfo = Start-Process iexplore -ArgumentList 'accounts.google.com' -passthru
Start-Process -FilePath Chrome -ArgumentList 'accounts.google.com'

Amadey CNC targeting with new unique TTP at 
h[x][x]p://77[.]91[.]68.52/fuza/1.ps1

$ie_procinfo = Start-Process iexplore -ArgumentList 'accounts.google.com' -passthru
Start-Process -FilePath Chrome -ArgumentList 'accounts.google.com'
account_circle
vx-underground(@vxunderground) 's Twitter Profile Photo

We will be mostly AFK for the remainder of the weekend. It is the weekend of rest – not just Sunday:)

Next week we will be adding new malware builders: Amadey (Panel), MetaStealer, and 'Сборка 2.0'. We don't know what Сборка 2.0 (Russian for 'Build 2.0') is.

Have a cat.

We will be mostly AFK for the remainder of the weekend. It is the weekend of rest – not just Sunday:)

Next week we will be adding new malware builders: Amadey (Panel), MetaStealer, and 'Сборка 2.0'. We don't know what Сборка 2.0 (Russian for 'Build 2.0') is.

Have a cat.
account_circle
Ksenia \n(@naumovax) 's Twitter Profile Photo

New key & HTTP URI found in ProxyBot described earlier in bitsight.com/blog/unveiling… 👾

C2: 88.80.147[.]36:1074
tria.ge/231123-g7kkvag…
gchq.github.io/CyberChef/#rec…

Thanks Eugene !

New #rc4 key & HTTP URI found in ProxyBot #Socks5Systemz described earlier in bitsight.com/blog/unveiling… 👾

C2: 88.80.147[.]36:1074
tria.ge/231123-g7kkvag…
gchq.github.io/CyberChef/#rec…

Thanks @4ekin !
account_circle
مالك الدوسري/Malek Aldossary(@MAlajab) 's Twitter Profile Photo

برمجيات سرقة المعلومآت منتشره بكثره، بل نجدها تتلون في أشكال مختلفة من المحتويات التي يبحث عنها المستخدم بشكل يومي، ومن أبرزها LummaC2, Redline, Raccoon, Amadey, , Formbook.
وهنا تقرير مبسط يوضح هدفها وأشكالها: socradar.io/the-anatomy-of…

برمجيات سرقة المعلومآت منتشره بكثره، بل نجدها تتلون في أشكال مختلفة من المحتويات التي يبحث عنها المستخدم بشكل يومي، ومن أبرزها  LummaC2, Redline, Raccoon, Amadey, , Formbook.
وهنا تقرير مبسط يوضح هدفها وأشكالها: socradar.io/the-anatomy-of…
#الامن_السيبراني
account_circle
Andrii Kava ☕(@AmadeyMozart1) 's Twitter Profile Photo

Новинарня Він блять сказав, що військові за власні кошти боєприпаси до автоматів купують та інші БК - скажіть чесно, він йобнутий, чи просто росіяни йому платять за таку рідкісну хрінь?

account_circle
Aaron Jornet(@RexorVc0) 's Twitter Profile Photo

APT-C-36

📍🇨🇴
💥🇨🇴🇵🇦🇪🇸🇪🇨

⛓️ > Doc > | > Download payload | + Steal info > Dll reflection > Persistence > Download stage > injection (InstallUtil)

🔗360 Threat Intelligence: mp.weixin.qq.com/s?__biz=MzUyMj…

#APT #BlindEagle APT-C-36 #amadey #AsyncRat #threat

📍🇨🇴
💥🇨🇴🇵🇦🇪🇸🇪🇨

⛓️ #Phishing > Doc > #Lnk | #vbs > Download payload | #Amadey + Steal info > Dll reflection > Persistence > Download stage > #AsyncRAT injection (InstallUtil)

🔗360 Threat Intelligence: mp.weixin.qq.com/s?__biz=MzUyMj…
account_circle