Indonesia(@IndonesiaMar) 's Twitter Profile Photo

PEGASUS
Los datos adicionales proporcionados por Francia en relación con el caso Pegasus incluyen “indicadores de compromiso” (IOCs), que son una serie de datos que pueden indicar que un sistema ha sido comprometido por un atacante. Estos indicadores pueden incluir direcciones

account_circle
Karol Paciorek(@karol_paciorek) 's Twitter Profile Photo

New discovery with stealer detected.

IP: 194.37.97[.162

🔹BecauseBranch.exe
C2: 37.120.237[.196:50500

🔹UncleLt4.exe
IoCs:
retdirectyourman[.eu
supfoundrysettlers[.us
149.248.79[.62

🔍 IoC query Censys:
🌐 services.http.response.html_title='Soon'

New #opendir discovery with #RisePro stealer detected.

IP: 194.37.97[.162

🔹BecauseBranch.exe
C2: 37.120.237[.196:50500

🔹UncleLt4.exe #nemesis
IoCs:
retdirectyourman[.eu
supfoundrysettlers[.us
149.248.79[.62

🔍 IoC query @censysio:
🌐 services.http.response.html_title='Soon'
account_circle
Alexander Leslie(@aejleslie) 's Twitter Profile Photo

Read more! This report includes substantive mitigations, SolarMarker detections, MITRE ATT&CK mapping, IOCs, and more!

PDF: go.recordedfuture.com/hubfs/reports/…

Read more! This report includes substantive mitigations, SolarMarker detections, MITRE ATT&CK mapping, IOCs, and more!

PDF: go.recordedfuture.com/hubfs/reports/…
account_circle
ANY.RUN(@anyrun_app) 's Twitter Profile Photo

🚨 Beware of , a that's now being used by dozens of threat actors. And check twice before loading an 'educational' RAT on GitHub 👾

Learn about the and collect its samples & ⤵️
any.run/malware-trends…

🚨 Beware of #XenoRAT, a #malware that's now being used by dozens of threat actors. And check twice before loading an 'educational' RAT on GitHub 👾

Learn about the #RAT and collect its samples & #IOCs ⤵️
any.run/malware-trends…
account_circle
CISA Cyber(@CISACyber) 's Twitter Profile Photo

🚨 Healthcare & Public Health Sector orgs❗

Review our latest advisory on ransomware containing & developed with FBI, @HHSgov & Center for Internet Security (CIS)'s MS-ISAC. More info at cisa.gov/news-events/cy…

🚨 Healthcare & Public Health Sector orgs❗

Review our latest #cybersecurity advisory on #BlackBasta ransomware containing #TTPs & #IOCs developed with @FBI, @HHSgov & @CISecurity's MS-ISAC. More info at cisa.gov/news-events/cy… #StopRansomware
account_circle
Alexander Leslie(@aejleslie) 's Twitter Profile Photo

👀 🚨- New Recorded Future report! This report, from my colleague Julian-Ferdinand, leverages Recorded Future Network Intelligence to examine the layered infrastructure and evasion techniques employed by SolarMarker. And yes, there are IOCs! recordedfuture.com/exploring-the-…

account_circle
DC3 DCISE(@DC3DCISE) 's Twitter Profile Photo

Our monthly IOC report has arrived, totaling 3,486 and sourced IOCs in April. This is vital for staying ahead in cyber defense allowing you timely insights into emerging threats, enabling proactive measures to safeguard your systems and data.

Our monthly IOC report has arrived, totaling 3,486 #DIB and #USG sourced IOCs in April. This is vital for staying ahead in cyber defense allowing you timely insights into emerging threats, enabling proactive measures to safeguard your systems and data.
#CyberSecurity #InfoSec
account_circle
Cyber_Ravan(@cyber_ra1) 's Twitter Profile Photo

Apart from google meet, They masquerading/using SAP, HubSpot and more.

here is Censys/Fofa qury to find more

IOCs: pastebin.com/HpK8WDz7

Michael Koczwara thansk for brainstorming 🙏

search.censys.io/search?resourc…

en.fofa.info/result?qbase64…

#Fin7 Apart from google meet, They masquerading/using SAP, HubSpot and more.

here is Censys/Fofa qury to find more 

IOCs: pastebin.com/HpK8WDz7

@MichalKoczwara thansk for brainstorming 🙏

search.censys.io/search?resourc…

en.fofa.info/result?qbase64…
account_circle
NDA0E(@NDA0E) 's Twitter Profile Photo



202.79.165.160:9080
202.79.165.162:9080
202.79.165.170:9080
CTG Server Limited

Detection: Trojan-Banker.AndroidOS

All IOCs: paste.ee/r/eBZXH/0

#apk #opendir #malware

202.79.165.160:9080
202.79.165.162:9080
202.79.165.170:9080
#AS152194 CTG Server Limited

Detection: Trojan-Banker.AndroidOS

All IOCs: paste.ee/r/eBZXH/0
account_circle
Perception Point Attack Trends(@AttackTrends) 's Twitter Profile Photo

Hello everyone,

We are happy to share with you fresh IOCs.

eml > pdf > geofenced URL > jar > ps > zip > autoit3.exe & malicious a3x script

:
- afarm[.]net
- adventsales[.]co[.]uk

Hello everyone,  

We are happy to share with you fresh #Darkgate IOCs. 

eml > pdf > geofenced URL > jar > ps > zip > autoit3.exe & malicious a3x script  

#IOCs: 
- afarm[.]net 
- adventsales[.]co[.]uk  

#malware #threatintel #emailsecurity
account_circle
Robin Mayes(@Robin25461631) 's Twitter Profile Photo

IOC’s leaving mature African basins for ‘frontiers like Namibia and Guyana’ - S&P | OilNOW…only one company has prime assets across both basins… ⁦Eco Atlantic Oil & Gas $eco $eog.v oilnow.gy/featured/iocs-…

account_circle
DOCGuard - Detect Maldocs in Seconds!(@doc_guard) 's Twitter Profile Photo

🚨 Phishing PDF File Evaded Nearly All the AV Solutions 🚨

📌 VT Detection: 7 / 65

📁 Filename: Fnb Payment.pdf
🔐 MD5: ba6039f82e0f08711279adc9f4e9f92a
🕵️‍♂️ IOCs:
- https[:]//wearned.com/

DOCGuard Report: app.docguard.io/65d070b5c2e867…

🚨 Phishing PDF File Evaded Nearly All the AV Solutions 🚨

📌 VT Detection: 7 / 65

📁 Filename: Fnb Payment.pdf
🔐 MD5: ba6039f82e0f08711279adc9f4e9f92a
🕵️‍♂️ IOCs: 
- https[:]//wearned.com/

DOCGuard Report: app.docguard.io/65d070b5c2e867…
account_circle
kddx00(@kddx0178318) 's Twitter Profile Photo

999 protected folders + 2 rar containing same configuration related files

Opendir http[:]//173[.]232[.]109[.]208[.]host[.]secureserver[.]net/entrada/ used to scam/phishing companies in name of Banco Bradesco.

GoDaddy.com, LLC
AS26496

More IOCs below & images.

999 protected folders + 2 rar containing same configuration related files 

Opendir http[:]//173[.]232[.]109[.]208[.]host[.]secureserver[.]net/entrada/ used to scam/phishing companies in name of Banco Bradesco. 

GoDaddy.com, LLC
AS26496

More IOCs below & images.
account_circle
DOCGuard - Detect Maldocs in Seconds!(@doc_guard) 's Twitter Profile Photo

🚨 Phishing PDF File Evaded All the AV Solutions 🚨

📌 VT Detection: 1 / 63

📁 Filename: EFT-Payment.pdf
🔐 MD5: 12d4c4978092229073cf4d4d57729f2e
🕵️‍♂️ IOCs:
- https[:]//bafkreig6e4hmlnuktybscumout2n4ntbka34db5vtscvx5tknmzs3h5bsu.ipfs.cf-ipfs.com/

DOCGuard Report:

🚨 Phishing PDF File Evaded All the AV Solutions 🚨

📌 VT Detection: 1 / 63

📁 Filename: EFT-Payment.pdf
🔐 MD5: 12d4c4978092229073cf4d4d57729f2e
🕵️‍♂️ IOCs:
- https[:]//bafkreig6e4hmlnuktybscumout2n4ntbka34db5vtscvx5tknmzs3h5bsu.ipfs.cf-ipfs.com/

DOCGuard Report:
account_circle
Dark Web Informer(@DarkWebInformer) 's Twitter Profile Photo

⚠️TweetFeed⚠️collects Indicators of Compromise (IOCs) shared by the infosec community on Twitter. Here you will find malicious URLs, domains, IPs, & SHA256/MD5 hashes. Link in sub-post.👇

Informer

⚠️TweetFeed⚠️collects Indicators of Compromise (IOCs) shared by the infosec community on Twitter. Here you will find malicious URLs, domains, IPs, & SHA256/MD5 hashes. Link in sub-post.👇

#TweetFeed #OSINT #CTI #Clearnet #DarkWeb #DarkWebInformer #Cybercrime #Cybersecurity
account_circle
DOCGuard - Detect Maldocs in Seconds!(@doc_guard) 's Twitter Profile Photo

🚨 Phishing HTML File Evaded Most of the AV Solutions 🚨

📌 VT Detection: 2 / 60

📁 Filename: Attach.html
🔐 MD5: 50bb75d6e28550c7639975d5d3d56d61
🕵️‍♂️ IOCs:
- https[:]//bc1q7syczyekazugzppa6kcse4n.com/

DOCGuard Report: app.docguard.io/d2f166b0669a67…

🚨 Phishing HTML File Evaded Most of the AV Solutions 🚨

📌 VT Detection: 2 / 60

📁 Filename: Attach.html
🔐 MD5: 50bb75d6e28550c7639975d5d3d56d61
🕵️‍♂️ IOCs:
- https[:]//bc1q7syczyekazugzppa6kcse4n.com/

DOCGuard Report: app.docguard.io/d2f166b0669a67…
account_circle
DOCGuard - Detect Maldocs in Seconds!(@doc_guard) 's Twitter Profile Photo

🚨 Pakistan Prime Minister's Office Themed Phishing PDF File Evaded All the AV Solutions 🚨

📌 VT Detection: 0 / 63

📁 Filename: Outstanding Payment of Tender upload fee - PPRA.pdf
🔐 MD5: d4eb4cee8aeb6f2ea36afadeda9dbb23
🕵️‍♂️ IOCs:
- http[:]//docs.mofa-services-server.top/
-

🚨 Pakistan Prime Minister's Office Themed Phishing PDF File Evaded All the AV Solutions 🚨

📌 VT Detection: 0 / 63

📁 Filename: Outstanding Payment of Tender upload fee - PPRA.pdf
🔐 MD5: d4eb4cee8aeb6f2ea36afadeda9dbb23
🕵️‍♂️ IOCs:
- http[:]//docs.mofa-services-server.top/
-
account_circle
Central Bank of Nigeria(@cenbank) 's Twitter Profile Photo

Further Clarifications on The Circular on Cash Pooling of Repatriated Oil And Gas Export Proceeds by International Oil Companies (IOCS)

ow.ly/Yk8k50RyPpJ

Further Clarifications on The Circular on Cash Pooling of Repatriated Oil And Gas Export Proceeds by International Oil Companies (IOCS)

ow.ly/Yk8k50RyPpJ
account_circle