Ginkgo (@ginkgo_g) 's Twitter Profile
Ginkgo

@ginkgo_g

Security Researcher | Mastodon: @[email protected]

ID: 1193753938073284608

calendar_today11-11-2019 04:55:01

202 Tweet

1,1K Followers

213 Following

Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT 29fe2f5692f60841366cd6b5804dcc61 IDEAS Programme Schedule 2024.pdf.chm 6e217b04bbba562cb7b722a483ae8a18 Standard_Programme.exe 192.71.249[.]194

#APT

29fe2f5692f60841366cd6b5804dcc61
IDEAS Programme Schedule 2024.pdf.chm

6e217b04bbba562cb7b722a483ae8a18
Standard_Programme.exe

192.71.249[.]194
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT #Bitter 5f9f9eed09fa48a6d53aa36e71cc4ed9 Hajj Policy 2024.pdf.chm 3d922c89c5f0f8f9a738bec3a24d0494 Policy_Formulation_Committee.exe hxxp://federalrevenueboard.com:9314/hera/initiation?whoisit=smyytbFVD4&lookup=6.3.2.5 162.252.175.131:6969

#APT #Bitter

5f9f9eed09fa48a6d53aa36e71cc4ed9
Hajj Policy 2024.pdf.chm

3d922c89c5f0f8f9a738bec3a24d0494
Policy_Formulation_Committee.exe

hxxp://federalrevenueboard.com:9314/hera/initiation?whoisit=smyytbFVD4&lookup=6.3.2.5

162.252.175.131:6969
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#Patchwork #APT d2d88224f2b82ae2afc940acc7612cb3 1985478.pdf.lnk e30d7017cf7a3784a09fca67dd2db9e8 Security_Alert-US_MISSION_TO_PAKISTAN.pdf.lnk Downloads PE: hxxps://vorm.vormliebe.club/jkdKJKH_jhdH91_djkd81JHdjJ/fdjkkjdJKH_dhJHJH81_jjd_999JH_kd

#Patchwork #APT

d2d88224f2b82ae2afc940acc7612cb3
1985478.pdf.lnk

e30d7017cf7a3784a09fca67dd2db9e8
Security_Alert-US_MISSION_TO_PAKISTAN.pdf.lnk

Downloads PE:

hxxps://vorm.vormliebe.club/jkdKJKH_jhdH91_djkd81JHdjJ/fdjkkjdJKH_dhJHJH81_jjd_999JH_kd
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#Patchwork #APT 775fc72e3d6b671fe06d7a9d7e9957ca c:\windows\tasks\libvlc.dll hxxps://avangrid.info/YcKOjLMxiwCZfSS/comrCVPEffFiPvF.php

Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT #Sidewinder 8ae6cf2d0932782784084ff0e792a85146d5073115556e8d05a225e635ec96fa SLNA_Updated_Medical_Grant_Application(1).docx hxxps://defence-lk.military-bd.org/MedicalGrantForm/11d601c6/Profile.rtf

#APT #Sidewinder

8ae6cf2d0932782784084ff0e792a85146d5073115556e8d05a225e635ec96fa
SLNA_Updated_Medical_Grant_Application(1).docx

hxxps://defence-lk.military-bd.org/MedicalGrantForm/11d601c6/Profile.rtf
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT #Patchwork 2321a22697835ca07790bce363cc4437 5187008a141d777d6268769cf008437d 国家重点研发计划重点专项项目实施工作方案.pdf.lnk hxxps://rkde.fyicompsol.xyz/jsgdevdw_3ed/hdbdewsq1_sc3 -> python312.dll hxxps://kila.fyicompsol.xyz/kfdgbcws_rf4/dcsxwer32khd_esf -> EDARK0125.dat

Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT #Sidewinder daeb41e297c215a13234dbda18e4793c CY SEC AUDIT PLAN 2025.docx hxxps://paknavy.modpak.live/audit_091206/Profile.rtf

#APT #Sidewinder

daeb41e297c215a13234dbda18e4793c
CY SEC AUDIT PLAN 2025.docx

hxxps://paknavy.modpak.live/audit_091206/Profile.rtf
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT #Sidewinder 0ffd99b46024863228e14efea8265ff2 CY SEC AUDIT PLAN 2025.docx hxxps://paknavy.modpak.live/70137347_audit/Profile.rtf

Ginkgo (@ginkgo_g) 's Twitter Profile Photo

🚨#APT #Bitter Alert🚨 📁 c12ea05baf94ef6f0ea73470d70db3b2 M6XA.rar Lure: "Details of Courses for Special Forces, Details of All Arms Courses" Contains: PDF, LNK, & batch files Exploits CVE-2023-38831 🔗 C2: hxxp://149.154.153.184/loccs.php?cn=%computername%--%username%

🚨#APT #Bitter Alert🚨

📁 c12ea05baf94ef6f0ea73470d70db3b2
M6XA.rar

Lure: "Details of Courses for Special Forces, Details of All Arms Courses"

Contains: PDF, LNK, & batch files

Exploits CVE-2023-38831

🔗 C2: hxxp://149.154.153.184/loccs.php?cn=%computername%--%username%
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

🚨#APT #Bitter Alert🚨 📁 8650fff81d597e1a3406baf3bb87297f 2025-013-PAK-MoD-Invitation_the_UN_Peacekeeping.rar Lure: "Invitation to the UN Peacekeeping Ministerial on 13th and 14th May 2025" Shares LNK file from the first sample

🚨#APT #Bitter Alert🚨

📁 8650fff81d597e1a3406baf3bb87297f
2025-013-PAK-MoD-Invitation_the_UN_Peacekeeping.rar

Lure: "Invitation to the UN Peacekeeping Ministerial on 13th and 14th May 2025"

Shares LNK file from the first sample
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT #Bitter #MysteriousElephant 540319431f56998f281c35ca7f41981f Kashmir Solidarity Day 2025 MoM.pdf.chm #GEOShell 5753bc214cf0119e283ee88d4fb5d783 hxxp://158.255.215.45:8899/nina/anotherLife?credPart=xrmnms43Z6&dumbPart=3.2.3.6 193.29.56.86:8649

#APT #Bitter #MysteriousElephant

540319431f56998f281c35ca7f41981f
Kashmir Solidarity Day 2025 MoM.pdf.chm

#GEOShell
5753bc214cf0119e283ee88d4fb5d783
hxxp://158.255.215.45:8899/nina/anotherLife?credPart=xrmnms43Z6&dumbPart=3.2.3.6

193.29.56.86:8649
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#APT #Patchwork LNK attack: 4cc371651f43e31df87b9f08013a14f6 8754444113.pdf.lnk DLs: PDF (hxxps://mingom.breatlee.org/...) Winver.exe (hxxps://mianyo.breatlee.org/...) Mal cfg (hxxps://mingo.breatlee.org/...) Persistence: "GoogleErrorReport" task

#APT #Patchwork

LNK attack: 4cc371651f43e31df87b9f08013a14f6
8754444113.pdf.lnk

DLs:

PDF (hxxps://mingom.breatlee.org/...)

Winver.exe (hxxps://mianyo.breatlee.org/...)

Mal cfg (hxxps://mingo.breatlee.org/...)

Persistence: "GoogleErrorReport" task
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

🐰 waves Found another #APT sample like this! 🔍 Hash: 667549ae95d4e0d8d04892f5246173bf 🌐 URL: hxxps://gofinancially.com/images/upload/0424.png Would anyone be sweet enough to share if they've grabbed the payload? 🥺 I'd be super grateful! 💖

🐰 waves
Found another #APT sample like this!

🔍 Hash: 667549ae95d4e0d8d04892f5246173bf
🌐 URL: hxxps://gofinancially.com/images/upload/0424.png

Would anyone be sweet enough to share if they've grabbed the payload? 🥺
I'd be super grateful! 💖
Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#Patchwork #APT New sample detected: 2faca6a64068e484779f2ba4a44753f9 libvlc.dll hxxps://foundersthub[.]org/bIHTfcVHegEoMrv/WCcod7JY3zwUpDH.php FOFA revealed Patchwork another C2 link: 👉musickeepers[.]org

Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#Bitter #APT New sample detected: 8af2d392181c359ce04e38ab113e22e526eae4c6f715d26462e439a3db1eb948 MoU_updated_27643_ERD.pdf.chm hxxps://www.inhostnetservice.com/cndrll.php?er=

Ginkgo (@ginkgo_g) 's Twitter Profile Photo

#Patchwork #APT #Spyder #IOC 0a109674d13280949787d2793016a2f5 AMPO_Conference_2025.pdf.lnk hxxps://bluefileshare.com/B40/21.zip d70a78f4aa1e792deaa541293af9d823 21 .zip f47aeb1e4bb33ccdff56909b6f6c71bf F12Chose.exe hxxp://bizzshared.com/gandalf/cane.php