
Dominic Alvieri
@alvierid
Cybersecurity Analyst | Security Researcher | CTI Deleted my own Facebook and hacked yours. thecybershow.blogspot.com
ID: 3378683890
https://linkedin.com/in/dominicalvieri 16-07-2015 11:05:53
12,12K Tweet
17,17K Followers
336 Following




Don't trust the Host header in HTTP, firstly - check DNS 🧐 Here #ACRStealer mimics Bitdefender (indicates the official website in this POST request, but the real IP is different) 🦎 C2: 87.120.219[.]223 tria.ge/251014-qd8j9aa… virustotal.com/gui/file/83b63… #stealer
![Kseniia \n (@naumovax) on Twitter photo Don't trust the Host header in HTTP, firstly - check DNS 🧐
Here #ACRStealer mimics <a href="/Bitdefender/">Bitdefender</a> (indicates the official website in this POST request, but the real IP is different) 🦎
C2: 87.120.219[.]223
tria.ge/251014-qd8j9aa…
virustotal.com/gui/file/83b63…
#stealer Don't trust the Host header in HTTP, firstly - check DNS 🧐
Here #ACRStealer mimics <a href="/Bitdefender/">Bitdefender</a> (indicates the official website in this POST request, but the real IP is different) 🦎
C2: 87.120.219[.]223
tria.ge/251014-qd8j9aa…
virustotal.com/gui/file/83b63…
#stealer](https://pbs.twimg.com/media/G3OWWlQXgAAD9Cb.jpg)





New Scattered Lapsus Shiny message Live on the Shiny clearnet :) “Hello James from Scattered…” DragonBall Z starting again vx-underground




NEW: 🇰🇵DPRK has begun hiding malware on blockchain. Result, decentralized, immutable malware. Nearly impossible to remove. Research by Mandiant (part of Google Cloud)




