Intel-Ops (@intel_ops_io) 's Twitter Profile
Intel-Ops

@intel_ops_io

Adversary Infrastructure Hunting & Training
Curated Threat Intelligence Feed (Coming Soon)

intel-ops.io
medium.com/@Intel_Ops

ID: 1748077076689637376

linkhttps://academy.intel-ops.io/courses/hunting-adversary-infra calendar_today18-01-2024 20:17:21

113 Tweet

2,2K Takipçi

4 Takip Edilen

Validin (@validinllc) 's Twitter Profile Photo

New feature now available to premium AND community users! Per popular request, Validin now supports pivoting of certificate SHA256 hashes in addition to SHA1. This pivot makes it easier to continue searches from or on other platforms that favor SHA256.

New feature now available to premium AND community users! Per popular request, Validin now supports pivoting of certificate SHA256 hashes in addition to SHA1. This pivot makes it easier to continue searches from or on other platforms that favor SHA256.
Michael Koczwara (@michalkoczwara) 's Twitter Profile Photo

This one is a good example how infrastructure is reused by different actors. 216.189.159[.]34 - BianLian Ransomware💰 216.189.159[.]34 - North Korean APT 🇰🇵 Intel-Ops

Michael Koczwara (@michalkoczwara) 's Twitter Profile Photo

Cybersecurity "experts" be like... APTs in 2024 will be using Artificial Intelligence to create undetectable malware, payloads, zero-day exploits, cyber weapons, and probably some cyber nuclear bombs too🥱 Meanwhile, APTs (Muddy Water 🇮🇷)in 2024 🙃

Cybersecurity "experts" be like... APTs in 2024 will be using Artificial Intelligence to create undetectable malware, payloads, zero-day exploits, cyber weapons, and probably some cyber nuclear bombs too🥱

Meanwhile, APTs (Muddy Water 🇮🇷)in 2024 🙃
Michael Koczwara (@michalkoczwara) 's Twitter Profile Photo

We are pleased to announce a new partnership between Intel-Ops and Hunt.io🤝 This partnership will provide all current and new IntelOps students with access to the Hunt.io platform. Students will learn to use the platform effectively for exploring new

We are pleased to announce a new partnership between <a href="/Intel_Ops_io/">Intel-Ops</a>  and <a href="/Huntio/">Hunt.io</a>🤝

This partnership will provide all current and new IntelOps students with access to the Hunt.io platform. 

Students will learn to use the platform effectively for exploring new
Michael Koczwara (@michalkoczwara) 's Twitter Profile Photo

APT43/Kimsuky (Black Banshee)🇰🇵 /141.11.95.135 /67.217.60.68 /67.217.62.219 /185.141.171.31 /185.203.119.14 /note.iiiii.info /share-defence.uberlingen.com /imagedownload.ignorelist.com /signin-ym.quest /mnlp.quest /oso-usps.com /drives.youramys.com /www.uidlogin.o-r.kr

APT43/Kimsuky (Black Banshee)🇰🇵

/141.11.95.135
/67.217.60.68
/67.217.62.219
/185.141.171.31
/185.203.119.14

/note.iiiii.info
/share-defence.uberlingen.com
/imagedownload.ignorelist.com
/signin-ym.quest
/mnlp.quest
/oso-usps.com
/drives.youramys.com
/www.uidlogin.o-r.kr
Intel-Ops (@intel_ops_io) 's Twitter Profile Photo

Interesting recently created (2024-05-22) domain impersonating GE HealthCare. Resolving to 46.101.212[.]131, running #CobaltStrike server. Using Hunt.io we can see: ➡️the DNS record, ➡️Hoster: DigitalOcean, ➡️Watermark: 987654321 (cracked version).

Interesting recently created (2024-05-22) domain impersonating <a href="/GEHealthCare/">GE HealthCare</a>.

Resolving to 46.101.212[.]131, running #CobaltStrike server.

Using <a href="/Huntio/">Hunt.io</a> we can see:
➡️the DNS record,
➡️Hoster: <a href="/digitalocean/">DigitalOcean</a>,
➡️Watermark: 987654321 (cracked version).