DonPasci (@donpasci) 's Twitter Profile
DonPasci

@donpasci

ID: 1429827800878489608

calendar_today23-08-2021 15:30:19

827 Tweet

230 Takipçi

192 Takip Edilen

John F - abjuri5t.bsky.social (@abjuri5t) 's Twitter Profile Photo

Finally published #ChartingTheIOCs - a blog post to: - help #SysAdmins defend their networks 🛡️ - explain how SarlackLab’s mapping works - … and share my wisdom (rant) on hunting #C2 servers medium.com/@the_abjuri5t/… Let us know what your thoughts are! #OneTeamOneFight

Curated Intelligence (@curatedintel) 's Twitter Profile Photo

⚠️PSA: Curated Intel DFIR has noticed a new trend among Akira Ransomware cases in Summer 2024. For a while, Akira has been exploiting Cisco ASA devices. ➡️ They are now targeting SonicWall SSL-VPNs for access with no MFA (!) and weak passwords (!). Other TTPs remain the same 🔍

DonPasci (@donpasci) 's Twitter Profile Photo

Hello Namecheap.com, These domains are used by Lumma stealer: https://teachherwjw[.]shop/api https://condedqpwqm[.]shop/api Sample: tria.ge/240907-yqxbrav… The domains are registered at Namecheap. Thanks!

DonPasci (@donpasci) 's Twitter Profile Photo

Hi Namecheap.com Can you check these domains (linked to Lumma Stealer) and registered at Namecheap: deepymouthi[.]sbs consumeroo[.]sbs ferrycheatyk[.]sbs captaitwik[.]sbs snailyeductyi[.]sbs monstourtu[.]sbs

The DFIR Report (@thedfirreport) 's Twitter Profile Photo

🌟New report out today!🌟 Navigating Through The Fog Analysis and reporting completed by Angelo Violetti, and reviewed by Zach. Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/04/28/nav…

DonPasci (@donpasci) 's Twitter Profile Photo

Hi Namecheap.com Can you check this #mythic c2 panel on https://159[.]198[.]36[.]237 urlscan.io/result/0199c48… See also: docs.mythic-c2.net/home

Hi <a href="/Namecheap/">Namecheap.com</a> 
Can you check this #mythic c2 panel on https://159[.]198[.]36[.]237
urlscan.io/result/0199c48…

See also:
docs.mythic-c2.net/home