SecAI (@secai_ai) 's Twitter Profile
SecAI

@secai_ai

Innovative threat intelligence-driven and AI-powered company aiming at cyber threat detection and response.
šŸ¢ secai.ai
šŸ”Ž i.secai.ai/research

ID: 1783668584159621120

linkhttps://www.secai.ai/ calendar_today26-04-2024 01:25:15

316 Tweet

490 Followers

113 Following

SecAI (@secai_ai) 's Twitter Profile Photo

The #Kimsuky #APT group used phishing sites to collect account credentials, but the sites has not been resolved to any IP addresses. #IOC: post.blogalarm.kro[.]kr nid-info.checkmyblog.kro[.]kr i.secai.ai/research/bloga… i.secai.ai/research/check…

The #Kimsuky #APT group used phishing sites to collect account credentials, but the sites has not been resolved to any IP addresses.
#IOC:
post.blogalarm.kro[.]kr
nid-info.checkmyblog.kro[.]kr
i.secai.ai/research/bloga…
i.secai.ai/research/check…
SecAI (@secai_ai) 's Twitter Profile Photo

The #Kimsuky #APT group also registered other #phishing assets. #IOC: 158.247.242[.]169 i.secai.ai/research/158.2…

The #Kimsuky #APT group also registered other #phishing assets.
#IOC: 158.247.242[.]169
i.secai.ai/research/158.2…
SecAI (@secai_ai) 's Twitter Profile Photo

New #phishing assets of the #Kimsuky #APT group: #IOC: 158.247.192[.]105 ips-check.o-r[.]kr i.secai.ai/research/158.2… i.secai.ai/research/ips-c…

New #phishing assets of the #Kimsuky #APT group:
#IOC:
158.247.192[.]105
ips-check.o-r[.]kr
i.secai.ai/research/158.2…
i.secai.ai/research/ips-c…
SecAI (@secai_ai) 's Twitter Profile Photo

Looking forward to RSAConference 2025? Stop by booth #Booth N-6570 to meet our team and check out our TI-enriched and AI-driven cybersecurity solutions. You're just one step away from levelling up your security operation. If you don't have a pass. Don't worry! Here is the

Looking forward to <a href="/RSAConference/">RSAConference</a> 2025? Stop by booth #Booth N-6570 to meet our team and check out our TI-enriched and AI-driven cybersecurity solutions. You're just one step away from levelling up your security operation. 
If you don't have a pass. Don't worry! Here is the
SecAI (@secai_ai) 's Twitter Profile Photo

šŸš€ The new version of SecAI is live! We’ve made major upgrades to help you analyze IPs and domains more effectively: āœ… Clear Verdicts – Malicious, Suspicious, Unknown, or Benign — based on multi-source intelligence šŸ·ļø Multi-layered Labels – Threat types, malware linkage,

šŸš€ The new version of SecAI is live!
We’ve made major upgrades to help you analyze IPs and domains more effectively:
āœ… Clear Verdicts – Malicious, Suspicious, Unknown, or Benign — based on multi-source intelligence
šŸ·ļø Multi-layered Labels – Threat types, malware linkage,
SecAI (@secai_ai) 's Twitter Profile Photo

New #phishing assets of the #Kimsuky #APT group: #IOC: 158.247.202[.]109 portiondoc.o-r[.]kr i.secai.ai/research/158.2… i.secai.ai/research/porti…

New #phishing assets of the #Kimsuky #APT group: #IOC: 
158.247.202[.]109
portiondoc.o-r[.]kr
i.secai.ai/research/158.2…
i.secai.ai/research/porti…
SecAI (@secai_ai) 's Twitter Profile Photo

Recently, the #Konni #APT group has used a large number of #compromised websites to transmit information of infected hosts. ausbildungsbuddy[.]de i.secai.ai/research/ausbi……absongkhla[.]com i.secai.ai/research/abson… beldy[.]ma i.secai.ai/research/beldy… go2kgstan[.]com

Recently, the #Konni #APT group has used a large number of #compromised websites to transmit information of infected hosts. 
ausbildungsbuddy[.]de i.secai.ai/research/ausbi……absongkhla[.]com i.secai.ai/research/abson…
beldy[.]ma 
i.secai.ai/research/beldy…
go2kgstan[.]com
SecAI (@secai_ai) 's Twitter Profile Photo

New #phishing assets of the #Kimsuky #APT group: 210.114.14.234 i.secai.ai/research/210.1… secinput.n-e[.]kr i.secai.ai/research/secin… secuinput.r-e[.]kr i.secai.ai/research/secui… secinput.o-r[.]kr i.secai.ai/research/secin… 158.247.243.223 i.secai.ai/research/158.2… updateinfo.r-e[.]kr

New #phishing assets of the #Kimsuky #APT group:
210.114.14.234
i.secai.ai/research/210.1…
secinput.n-e[.]kr
i.secai.ai/research/secin…
secuinput.r-e[.]kr
i.secai.ai/research/secui…
secinput.o-r[.]kr
i.secai.ai/research/secin…
158.247.243.223
i.secai.ai/research/158.2…
updateinfo.r-e[.]kr
SecAI (@secai_ai) 's Twitter Profile Photo

The #Konni #APT group uses the #compromised site holosformations[.]fr to download files. C2: 49.12.47[.]155:443 i.secai.ai/research/holos… i.secai.ai/research/49.12… Hash: 869705fd4dd777d4ab5c662806b42fe43bff6b58e085a64804486326b35fee47 It is related to #ChatGPT, uses an #AutoIt

The #Konni #APT group uses the #compromised site holosformations[.]fr to download files.
C2: 49.12.47[.]155:443
i.secai.ai/research/holos…
i.secai.ai/research/49.12…
Hash: 869705fd4dd777d4ab5c662806b42fe43bff6b58e085a64804486326b35fee47  
It is related to #ChatGPT, uses an #AutoIt
SecAI (@secai_ai) 's Twitter Profile Photo

New #phishing assets of #Kimsuky #APT group: 158.247.247[.]157 i.secai.ai/research/158.2… mexc-signin.kro[.]kr i.secai.ai/research/mexc-… yourinfo.kro[.]kr i.secai.ai/research/youri… 141.164.53[.]3 i.secai.ai/research/141.1… userdoc-sign.kro[.]kr i.secai.ai/research/userd…

New #phishing assets of #Kimsuky #APT group:
158.247.247[.]157
i.secai.ai/research/158.2…
mexc-signin.kro[.]kr
i.secai.ai/research/mexc-…
yourinfo.kro[.]kr
i.secai.ai/research/youri…
141.164.53[.]3
i.secai.ai/research/141.1…
userdoc-sign.kro[.]kr
i.secai.ai/research/userd…
SecAI (@secai_ai) 's Twitter Profile Photo

Just 1 more day to GISEC GLOBAL! Come find SecAI at Booth P48 to have an hands-on experience of faster, smarter threat investigations powered by AI. Plus, try your luck at our onsite Lucky Draw! šŸŽ See you then!

Just 1 more day to <a href="/GISECGlobal/">GISEC GLOBAL</a>! Come find <a href="/SecAI_AI/">SecAI</a> at Booth P48 to have an hands-on experience of faster, smarter threat investigations powered by AI. 

Plus, try your luck at our onsite Lucky Draw! šŸŽ

See you then!
SecAI (@secai_ai) 's Twitter Profile Photo

The #Konni #APT group used the #compromised site to download files. #IOC: deliberatecollaboration[.]com i.secai.ai/research/delib…

The #Konni #APT group used the #compromised site to download files.
#IOC: deliberatecollaboration[.]com
i.secai.ai/research/delib…
SecAI (@secai_ai) 's Twitter Profile Photo

Day 2 at GISEC GLOBAL! Stop by Booth P48 to see why SecAI Investigator is making waves in Threat Intel. We're giving away 15-day Pro access codes—grab yours and see the power for yourself.

SecAI (@secai_ai) 's Twitter Profile Photo

The #Kimsuky #APT group used the #BabyShark trojan to connect to its C2 server via a revoked TLS certificate. #sha256: 8503a57fa9e3424cc1cb39f8cd15419840eaa73277e9fe383a1bebb518ef9ede(RemoteControl.dll) #C2: first.pokerstarus.kro[.]kr i.secai.ai/research/poker… Domain resolved to IP

The #Kimsuky #APT group used the #BabyShark trojan to connect to its C2 server via a revoked TLS certificate.
#sha256: 8503a57fa9e3424cc1cb39f8cd15419840eaa73277e9fe383a1bebb518ef9ede(RemoteControl.dll)
#C2: first.pokerstarus.kro[.]kr
i.secai.ai/research/poker…
Domain resolved to IP
SecAI (@secai_ai) 's Twitter Profile Photo

Last chance to meet us at GISEC GLOBAL! The SecAI Booth at P48 is open for one more day. Find out how AI-powered threat intelligence can give your security team a critical edge. See you there!

Last chance to meet us at <a href="/GISECGlobal/">GISEC GLOBAL</a>! The <a href="/SecAI_AI/">SecAI</a> Booth at P48 is open for one more day.
Find out how AI-powered threat intelligence can give your security team a critical edge. 

See you there!
SecAI (@secai_ai) 's Twitter Profile Photo

The #Konni #APT group used #compromised websites to deliver information. #IOC: bergaeroworks[.]co[.]za sitisrlweb[.]com seacura[.]com i.secai.ai/research/berga… i.secai.ai/research/sitis… i.secai.ai/research/seacu…

The #Konni #APT group used #compromised websites to deliver information.
#IOC:
bergaeroworks[.]co[.]za
sitisrlweb[.]com
seacura[.]com
i.secai.ai/research/berga…
i.secai.ai/research/sitis…
i.secai.ai/research/seacu…
SecAI (@secai_ai) 's Twitter Profile Photo

The #Kimsuky #APT group conducted #phishing using a Korean domain that means "Ministry of the Interior and Safety notification." #IOC: 27.102.138.155 ķ–‰ģ •ģ•ˆģ „ė¶€ķ†µģ§€ģ„œ.ķ™ˆķŽ˜ģ“ģ§€.ķ•œźµ­ ėø”ė”œź·øģ‹ ź³ ģ•ˆė‚“.ė©”ģø.ķ•œźµ­ i.secai.ai/research/27.10… i.secai.ai/research/xn--o… i.secai.ai/research/xn--2…

The #Kimsuky #APT group conducted #phishing using a Korean domain that means "Ministry of the Interior and Safety notification."
#IOC:
27.102.138.155
ķ–‰ģ •ģ•ˆģ „ė¶€ķ†µģ§€ģ„œ.ķ™ˆķŽ˜ģ“ģ§€.ķ•œźµ­
ėø”ė”œź·øģ‹ ź³ ģ•ˆė‚“.ė©”ģø.ķ•œźµ­
i.secai.ai/research/27.10…
i.secai.ai/research/xn--o…
i.secai.ai/research/xn--2…
SecAI (@secai_ai) 's Twitter Profile Photo

The #Konni #APT group used #compromised websites for command and control. #IOC: yukiicreatives[.]com rayanlynch[.]com i.secai.ai/research/yukii… i.secai.ai/research/rayan…

The #Konni #APT group used #compromised websites for command and control.
#IOC:
yukiicreatives[.]com
rayanlynch[.]com
i.secai.ai/research/yukii…
i.secai.ai/research/rayan…
SecAI (@secai_ai) 's Twitter Profile Photo

New #phishing assets of the #Kimsuky #APT group: #IOC: 141.164.56[.]44 taxdeliveryservice.kro[.]kr userauthoritydoc.p-e[.]kr i.secai.ai/research/141.1… i.secai.ai/research/taxde… i.secai.ai/research/usera…

New #phishing assets of the #Kimsuky #APT group:
#IOC:
141.164.56[.]44
taxdeliveryservice.kro[.]kr
userauthoritydoc.p-e[.]kr
i.secai.ai/research/141.1…
i.secai.ai/research/taxde…
i.secai.ai/research/usera…