Chris Duggan (@tlp_r3d) 's Twitter Profile
Chris Duggan

@tlp_r3d

Malware Geek | Curated Intel Member | Threat Intelligence Expert Extraordinaire

ID: 988366529162022912

linkhttp://tlp-r3d.com calendar_today23-04-2018 10:38:38

788 Tweet

6,6K Followers

2,2K Following

SpyoSecure (@spyosecure) 's Twitter Profile Photo

🚨Possible DDoS Alert🚨 The official website of Shodan (shodan.io), a well-known search engine for internet-connected devices, is currently showing a 503 Service Temporarily Unavailable error. No group has claimed responsibility for the takedown I am not sure how

🚨Possible DDoS Alert🚨

The official website of Shodan (shodan.io), a well-known search engine for internet-connected devices, is currently showing a 503 Service Temporarily Unavailable error.

No group has claimed responsibility for the takedown
I am not sure how
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

🚨 Keepass Campaign 🔥Domain: kee-password[.]com (0/94 VT) 🔥Redirects to: keepass-download[.]com (0/94 VT) 🔥Links to malicious Github repo: hxxps://github[.]com/keeppasss/keepass/raw/refs/heads/main/KeePass-2.56-Setup[.]exe 🔥Drops:

🚨 Keepass Campaign

🔥Domain: kee-password[.]com (0/94 VT)
🔥Redirects to: keepass-download[.]com (0/94 VT)

🔥Links to malicious Github repo:
hxxps://github[.]com/keeppasss/keepass/raw/refs/heads/main/KeePass-2.56-Setup[.]exe

🔥Drops:
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

🕵️‍♂️ Spotted something interesting in the Talos report: 🔍 IP 192.210.239[.]172 looks like a Cobalt Strike redirector. Got curious... are there more redirectors on the same ASN? Let's hunt. 👇 🛰️ Query: asn:"AS36352" HTTP/1.1 302 Moved Temporarily Server: Server Location:

🕵️‍♂️ Spotted something interesting in the Talos report:
🔍 IP 192.210.239[.]172 looks like a Cobalt Strike redirector.

Got curious... are there more redirectors on the same ASN? Let's hunt. 👇

🛰️ Query:
asn:"AS36352"
HTTP/1.1 302 Moved Temporarily
Server: Server
Location:
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

🇮🇳🐍Potential Sidewinder Cobalt Strike Redirectors in Action 🐍185.159.128.117 0/94 in VT 🔥Suspect Domain: islamabadpolice[.]net 0/94 in VT - hosted on Cloudflare Spoofing legit domain: fir.islamabadpolice[.]gov[.]pk 🐍31.15.17.230 0/94 in VT 🔥Suspect Domain:

🇮🇳🐍Potential Sidewinder Cobalt Strike Redirectors in Action

🐍185.159.128.117 0/94 in VT
🔥Suspect Domain: islamabadpolice[.]net 0/94 in VT - hosted on Cloudflare
Spoofing legit domain: fir.islamabadpolice[.]gov[.]pk

🐍31.15.17.230 0/94 in VT
🔥Suspect Domain:
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

🤔Another Interesting Potential Cobalt Redirector 82.118.22.60 0/94 in VT Suspect Domain: oicm[.]org 0/94 in VT - hosted on Cloudflare Redirects to legit domain: oic-cert[.]org The website oic-cert[.]org is the official platform of the OIC-CERT, a cybersecurity initiative under

🤔Another Interesting Potential Cobalt Redirector

82.118.22.60 0/94 in VT
Suspect Domain: oicm[.]org 0/94 in VT - hosted on Cloudflare
Redirects to legit domain: oic-cert[.]org

The website oic-cert[.]org is the official platform of the OIC-CERT, a cybersecurity initiative under
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

Arcserve, a data protection leader, is potentially being spoofed using Cobalt Strike redirectors! IP : 45[.]67[.]228[.]243 Domain: downloads[.]arcservecdn[.]com Provider: STARK INDUSTRIES SOLUTIONS LTD (Netherlands) SSL: CloudFlare Redirect to

Arcserve, a data protection leader, is potentially being spoofed using Cobalt Strike redirectors!  

IP : 45[.]67[.]228[.]243  
Domain: downloads[.]arcservecdn[.]com  
Provider: STARK INDUSTRIES SOLUTIONS LTD  (Netherlands)  
SSL: CloudFlare 
Redirect to
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

Interesting find reference Cobalt Redirectors spoofing Adidas 🤔 104.168.134[.]112 1/94 in VirusTotal adldas[.]top 1/94 in VirusTotal 23.254.202[.]110 0/94 in VirusTotal 104.168.253[.]136 1/94 in VirusTotal addes[.]top 0/94 in VirusTotal

Interesting find reference Cobalt Redirectors spoofing Adidas 🤔

104.168.134[.]112 1/94 in VirusTotal
adldas[.]top 1/94 in VirusTotal

23.254.202[.]110 0/94 in VirusTotal
104.168.253[.]136 1/94 in VirusTotal
addes[.]top 0/94 in VirusTotal
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

Interesting DNS Finds and Pivots DNS Analysis: ns1.internettoday[.]nl sophos-telemetry[.]com 0/94 in VT 64.225.72.116 DIGITALOCEAN 0/94 in VT api.cloud-oracle[.]net 0/94 in VT 161.35.83.216 DIGITALOCEAN 0/94 in VT gchq-github[.]com 0/94 in VT 152.42.142.116 DIGITALOCEAN 1/94

Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

Nice report from Proofpoint on TA4557! I noticed that you can hunt for Resume Profiles dropping More_Eggs backdoor: http.title:"Resume" HTTP/1.1 200 OK Date: GMT Server: Apache/2.4.58 (Ubuntu) Vary: Accept-Encoding Content-Length: Content-Type: text/html; charset=UTF-8 Happy

Nice report from Proofpoint on TA4557!

I noticed that you can hunt for Resume Profiles dropping More_Eggs backdoor:

http.title:"Resume" HTTP/1.1 200 OK Date: GMT Server: Apache/2.4.58 (Ubuntu) Vary: Accept-Encoding Content-Length: Content-Type: text/html; charset=UTF-8
 
Happy
Chris Duggan (@tlp_r3d) 's Twitter Profile Photo

⏰Interesting Post and you can hunt C2 Dev Tunnels in shodan: HTTP/1.1 404 Not Found Date: GMT Content-Type: text/html Content-Length: 548 Connection: keep-alive X-Served-By: Strict-Transport-Security: max-age=31536000; includeSubDomains

⏰Interesting Post and you can hunt  C2 Dev Tunnels in shodan:

HTTP/1.1 404 Not Found Date: GMT Content-Type: text/html Content-Length: 548 Connection: keep-alive X-Served-By:  Strict-Transport-Security: max-age=31536000; includeSubDomains