Mikhail Kasimov(@500mk500) 's Twitter Profileg
Mikhail Kasimov

@500mk500

Malicious traffic detection system -- @maltrail -- co-developer

Maltrail Demo Page: https://t.co/eimXdZvjWo
Maltrail FAQ: https://t.co/Kne9lewPHT

ID:4820426207

linkhttp://maltrail.github.io calendar_today17-01-2016 07:45:52

5,6K Tweets

2,8K Followers

549 Following

Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

[2024-04-11, PART 3] -related (kritec-skimmer) low detected domains (amount: 276) from IPs 195.242.111[.]XXX

Detection: github.com/stamparm/maltr…

account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

[2024-04-10, PART 2] -related (kritec-skimmer) low detected domains (amount: 157) from IPs 195.242.111[.]XXX

Detection: github.com/stamparm/maltr…

account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

[2024-04-10] -related (kritec-skimmer) low detected domains (amount: 123) from IPs 195.242.111[.]XXX

Ref: twitter.com/sdcyberresearc…

Detection: github.com/stamparm/maltr…

account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

[2024-04-07] -related (kritec-skimmer) low detected domains from IPs 195.242.111[.]XXX

Domains: pastebin.com/ND5r9rbs

Refs:
[1] malwarebytes.com/blog/threat-in…

[2] malwarebytes.com/blog/threat-in…

[3] twitter.com/sdcyberresearc…

Detection: github.com/stamparm/maltr…

account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

More domains, discovered by CERT_FINGERPRINT_* options

Domains: pastebin.com/6ZqcpcHA

Detection: github.com/stamparm/maltr…

More #Android #Joker domains, discovered by CERT_FINGERPRINT_* options Domains: pastebin.com/6ZqcpcHA Detection: github.com/stamparm/maltr…
account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

Some fresh panels to detect:

hXXp://147.45.125.142
hXXp://5.182.86.229
purpleflowers[.]org
salaamt[.]top

D: github.com/stamparm/maltr…

Some fresh #Meduza #Stealer panels to detect: hXXp://147.45.125.142 hXXp://5.182.86.229 purpleflowers[.]org salaamt[.]top D: github.com/stamparm/maltr…
account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

Would be brave to extend IOCs list a little bit:

hXXp://195.123.218.28
hXXp://195.123.218.36
hXXp://195.123.218.37
hXXp://195.123.218.40
hXXp://195.123.218.46

/

Detection: github.com/stamparm/maltr…

Would be brave to extend IOCs list a little bit: hXXp://195.123.218.28 hXXp://195.123.218.36 hXXp://195.123.218.37 hXXp://195.123.218.40 hXXp://195.123.218.46 #KoiLoader/#KoiStealer Detection: github.com/stamparm/maltr…
account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

Taking chlmpstatiic\.com for Validin tool, some other not pretty good detected -related domains were found:

chimpstatiic[.]com
g-staticxs[.]com (detected by Sansec )
gstatics[.]org
sucuriwebtrack[.]org (impers Sucuri Security )

github.com/stamparm/maltr…

Taking chlmpstatiic\.com for @ValidinLLC #lookalike tool, some other not pretty good detected #Magecart-related domains were found: chimpstatiic[.]com g-staticxs[.]com (detected by @sansecio ) gstatics[.]org sucuriwebtrack[.]org (impers @sucurisecurity ) github.com/stamparm/maltr…
account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

More of -related domains after taking jqueurystatics[.]com as a start-point of search:

bulkmailsms\.com
chlmpstatiic\.com
fraudlabzpros\.com
googleinfodata\.com
jqueryoverlay\.com
jquerystatics\.com
jqueurystatic\.xyz
jqueurystatics\.xyz
jqueurystaticx\.com
jstags\.com

More of #Magecart-related domains after taking jqueurystatics[.]com as a start-point of search: bulkmailsms\.com chlmpstatiic\.com fraudlabzpros\.com googleinfodata\.com jqueryoverlay\.com jquerystatics\.com jqueurystatic\.xyz jqueurystatics\.xyz jqueurystaticx\.com jstags\.com
account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

Ref: reversinglabs.com/blog/suspiciou… (ReversingLabs )

Connection: 117.41.187[.]235:60000

Detection: github.com/stamparm/maltr…

TF: threatfox.abuse.ch/ioc/1249506/

account_circle
Mikhail Kasimov(@500mk500) 's Twitter Profile Photo

Small update for list:

C2: eyedr[.]art

Related: us17[.]xyz

Refs:
virustotal.com/gui/ip-address…

virustotal.com/gui/file/bfe9b…

account_circle