ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท (@smashthekernel) 's Twitter Profile
ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท

@smashthekernel

Stoic.
Principle Security Engineer
I break stuff to make the world a safer place ๐Ÿ—ก๏ธ

ID: 1335208362

linkhttps://about.me/oguzhanakkaya calendar_today07-04-2013 22:24:09

1,1K Tweet

2,2K Followers

956 Following

ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท (@smashthekernel) 's Twitter Profile Photo

An Anubis Botnet Incident Turkey๐Ÿ‡น๐Ÿ‡ท IOC From: evdekal-hediye-20gbnet[.]com Name: 20gb_hediye_internet.apk Hash:"7abe646fc8416e0f969a8b3c6ecf32140faf50f83af107192c9c2d2fe0b7b052" C&C: hxxp://ozkandan.com/o1o/a4.php virustotal.com/gui/file/7abe6โ€ฆ MalwareHunterTeam Lukas Stefanko #Anubis

An Anubis Botnet Incident Turkey๐Ÿ‡น๐Ÿ‡ท

IOC
From: evdekal-hediye-20gbnet[.]com
Name: 20gb_hediye_internet.apk
Hash:"7abe646fc8416e0f969a8b3c6ecf32140faf50f83af107192c9c2d2fe0b7b052"
C&C: hxxp://ozkandan.com/o1o/a4.php

virustotal.com/gui/file/7abe6โ€ฆ

<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/LukasStefanko/">Lukas Stefanko</a> #Anubis
ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท (@smashthekernel) 's Twitter Profile Photo

A Covid-19 Cerberus Botnet Incident IOC From: virus-covid[.]online Name: covidMappia_v1.0.3.apk Hash:"70439d393cca65ede64971d923ed61c0dd332dad5e2c31fdf8d225db1cf933e8" virustotal.com/gui/file/70439โ€ฆ MalwareHunterTeam Lukas Stefanko #Cerberus #Android #Malware

A Covid-19 Cerberus Botnet Incident

IOC
From: virus-covid[.]online
Name: covidMappia_v1.0.3.apk
Hash:"70439d393cca65ede64971d923ed61c0dd332dad5e2c31fdf8d225db1cf933e8"

virustotal.com/gui/file/70439โ€ฆ

<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/LukasStefanko/">Lukas Stefanko</a>
 
#Cerberus #Android #Malware
Lukas Stefanko (@lukasstefanko) 's Twitter Profile Photo

Anubis banking Trojan targets #Italy ๐Ÿ‡ฎ๐Ÿ‡น as Coronavirus map -campaign active from 21.03.2020 -server includes APK builder, with 130 already built APKs -~177 victims -C&C: https://files[.]ug

Anubis banking Trojan targets #Italy ๐Ÿ‡ฎ๐Ÿ‡น as Coronavirus map

-campaign active from 21.03.2020
-server includes APK builder, with 130 already built APKs
-~177 victims
-C&amp;C: https://files[.]ug
ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท (@smashthekernel) 's Twitter Profile Photo

Indicator of Attack(IOA) vs. Indicator of Compromises(IOC) includes assets. The combination formed in the shadow of this conflict is Indicator of Pivoting (IOP) bit.ly/2YJnGPe #ThreatHunting #Threatanalysis #infosec

Indicator of Attack(IOA) vs. Indicator of Compromises(IOC) includes assets. The combination formed in the shadow of this conflict is Indicator of Pivoting (IOP)

bit.ly/2YJnGPe

#ThreatHunting #Threatanalysis #infosec
ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท (@smashthekernel) 's Twitter Profile Photo

Android Banker Incident Froms: sen-evdekal20gbkazan[.]com bitbucket[.]org/emreadamol/emreadamol34/downloads/20gbinternet-evdekal.apk 82d7f887ec682ef752f71119c5a31a415bd907864e0d207943a68916ec96b7b3 virustotal.com/gui/file/82d7fโ€ฆ C2: besieged[.]top MalwareHunterTeam Lukas Stefanko

Android Banker Incident

Froms: 
sen-evdekal20gbkazan[.]com
bitbucket[.]org/emreadamol/emreadamol34/downloads/20gbinternet-evdekal.apk

82d7f887ec682ef752f71119c5a31a415bd907864e0d207943a68916ec96b7b3

virustotal.com/gui/file/82d7fโ€ฆ

C2: besieged[.]top

<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/LukasStefanko/">Lukas Stefanko</a>
ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท (@smashthekernel) 's Twitter Profile Photo

Android Banker Incident From: yuklesm[.]org Name: 20gb_hediye_internet.apk Hash"d0c73e7bb87c22cac394ed5691b6557648152486362c5d8cf78cf7aaa088908c" virustotal.com/gui/file/d0c73โ€ฆ Target:๐Ÿ‡น๐Ÿ‡ท C2: binsletr[.]net MalwareHunterTeam Lukas Stefanko JAMESWT_MHT #android #banker #malware

Android Banker Incident

From: yuklesm[.]org
Name: 20gb_hediye_internet.apk

Hash"d0c73e7bb87c22cac394ed5691b6557648152486362c5d8cf78cf7aaa088908c"

virustotal.com/gui/file/d0c73โ€ฆ

Target:๐Ÿ‡น๐Ÿ‡ท
C2: binsletr[.]net

<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/LukasStefanko/">Lukas Stefanko</a> <a href="/JAMESWT_MHT/">JAMESWT_MHT</a> 
#android #banker #malware
ไพ ๐‘ถ๐’ˆ๐’–๐’›๐’‰๐’‚๐’ ๐‘จ. ๐Ÿ‡น๐Ÿ‡ท (@smashthekernel) 's Twitter Profile Photo

Hi my friends in the cyber security ecosystem, my X account, which was suspended for about 4 years without knowing the reason, has been reactivated.Of course, there had to be retaliation by actors against the contributions made to this ecosystem. Here again and stronger than ever