0xFaker(@0x_99796618) 's Twitter Profile Photo

stealer is on the rise 📈🥷 looking at initial ip 194.169.175[.133 reveals login panel. You can pivot using http headers query below to find 33 unique panels within . Additionally, you can pivot on the favicon to reveal a further 3 unique panels! 🎯

#risepro stealer is on the rise 📈🥷 looking at initial ip  194.169.175[.133 reveals login panel. You can pivot using http headers query below to find 33 unique panels within #FOFA. Additionally, you can pivot on the favicon to reveal a further 3 unique panels! 🎯
account_circle
Salman Shaikh(@salmanvsf) 's Twitter Profile Photo

Looks Like Risepro has updated their C2 Panel
http[:]//38[.]47[.]220[.]202

censys
services.http.response.html_title='ProxyTools'

shodan
http.html_hash:-946937792

new panels:
175[.]24[.]178[.]202
38[.]47[.]221[.]56
8[.]140[.]18[.]150
@ShilpeshTrivedi JAMESWT

Looks Like Risepro has updated their C2 Panel
http[:]//38[.]47[.]220[.]202

censys
services.http.response.html_title='ProxyTools'

shodan
http.html_hash:-946937792

new panels:
175[.]24[.]178[.]202
38[.]47[.]221[.]56
8[.]140[.]18[.]150
#RisePro @ShilpeshTrivedi @JAMESWT_MHT
account_circle
Knappresearchlabs(@knappresearchlb) 's Twitter Profile Photo

🧵1. RisePro ThreatHunt. Inspired by some of the people tagged in this thread. Hunting panels using Fofa and there were some intriguing results. First up lets use @viriback for some intel.

Panel

🧵1. RisePro ThreatHunt. Inspired by some of the people tagged in this thread. Hunting #RisePro #stealer panels using Fofa and there were some intriguing results. First up lets use #Viriback @viriback for some intel.

#C2 #C2Panel #ThreatHunt #Malware
account_circle
ANY.RUN(@anyrun_app) 's Twitter Profile Photo

Top 10 last week's threats by uploads 🌐

⬆️ 1259 (973)
⬇️ 110 (152)
⬆️ 110 (25)
⬆️ 105 (65)
⬆️ 76 (50)
⬇️ 55 (89)
⬇️ 43 (77)
⬇️ 40 (45)
⬆️ 39 (8)
⬇️ 38 (61)

Track them all at 🔽…

Top 10 last week's threats by uploads 🌐

⬆️ #Phishing 1259 (973)
⬇️ #Agenttesla 110 (152)
⬆️ #Guloader 110 (25)
⬆️ #Remcos 105 (65)
⬆️ #Njrat 76 (50)
⬇️ #Asyncrat 55 (89)
⬇️ #Xworm 43 (77)
⬇️ #Redline 40 (45)
⬆️ #Orcus 39 (8)
⬇️ #Risepro 38 (61)

Track them all at 🔽…
account_circle
Who said what(@g0njxa) 's Twitter Profile Photo

Stealer is also offering a 'Google Cookies Restoration' Service. 👀🍪

This would be the third stealer malware project offering this kind of service after and .

#Risepro Stealer is also offering a 'Google Cookies Restoration' Service. 👀🍪

This would be the third stealer malware project offering this kind of service after #Lumma and #Rhadamanthys.
account_circle
Who said what(@g0njxa) 's Twitter Profile Photo

stealer has been updated as of December 8th into a new v2.0

Featuring 'Google cookies restoration' from tokens stolen from 'Google Accounts' (same as , and )

More changes!
Please find attached the full release statement 👀👀

#Meduza stealer has been updated as of December 8th into a new v2.0

Featuring 'Google cookies restoration' from tokens stolen from 'Google Accounts' (same as #Lumma, #Rhadamanthys and #Risepro)

More changes!
Please find attached the full release statement 👀👀
account_circle
Cyber_Ravan(@cyber_ra1) 's Twitter Profile Photo

[1/4] C2 panel,This came back after 8 months

http[:]//5[.]42[.]79[.]238[:]8081/login
http[:]//38[.]47[.]220[.]202[:]8081/login
http[:]//45[.]15[.]159[.]248[:]8081/login
http[:]//95[.]214[.]25[.]205[:]8081/login
http[:]//95[.]214[.]25[.]208[:]8081/login

[1/4] #RisePro #stealer C2 panel,This #Malware came back after 8 months

http[:]//5[.]42[.]79[.]238[:]8081/login
http[:]//38[.]47[.]220[.]202[:]8081/login
http[:]//45[.]15[.]159[.]248[:]8081/login
http[:]//95[.]214[.]25[.]205[:]8081/login
http[:]//95[.]214[.]25[.]208[:]8081/login
account_circle
CVREP(@CVREPfoundation) 's Twitter Profile Photo

Prepare your inquiries points for this session!
'Ranolazine from Theory to Practice: Clinical Cases', a session led by the esteemed Prof. Amr Kamal 🤩
Register Now & save yourself a seat: bit.ly/43fEcWt

fellows

Prepare your inquiries points for this session!
'Ranolazine from Theory to Practice: Clinical Cases', a session led by the esteemed Prof. Amr Kamal 🤩
Register Now & save yourself a seat: bit.ly/43fEcWt

#CVREP #RisePro #cardiology #cardiologist #cardiologyfellows
account_circle
Cyber Team(@Cyberteam008) 's Twitter Profile Photo

Queries to find Infra

'services.http.response.headers: (key: `Server` and value.headers: `RisePro`)' => 26 servers

(or)

'services[.]software.product=`risepro` ' => 23 servers

The reason is explained in the below screenshots.

#Censys Queries to find #RisePro #Stealer Infra

'services.http.response.headers: (key: `Server` and value.headers: `RisePro`)'     => 26 servers

(or)

'services[.]software.product=`risepro` '     => 23 servers

The reason is explained in the below screenshots.

#Malware #ioc
account_circle
VMRay(@vmray) 's Twitter Profile Photo

🔍 configuration extractors targeting like and .

🛡️ Detecting threat tactics such as , , and more.

🎣 Enhanced detection capabilities, including automated login interaction.

🚨 Insight into the…

account_circle