Daniel López (@0xdaniellopez) 's Twitter Profile
Daniel López

@0xdaniellopez

Cyber Threat Researcher | @CuratedIntel member

ID: 372786765

linkhttps://daniel.tools calendar_today13-09-2011 12:24:05

1,1K Tweet

2,2K Takipçi

418 Takip Edilen

Germán Fernández (@1zrr4h) 's Twitter Profile Photo

🚨🇪🇸 Sitio web https://sede-informatica.certificado-aeta[.]us/ suplanta a la Agencia Tributaria (AEAT) española para distribuir el malware #LummaStealer. El señuelo: "VeriFactu: Instala tu certificado de facturación electrónica." ⚠️ * VeriFactu es una iniciativa legítima

🚨🇪🇸 Sitio web https://sede-informatica.certificado-aeta[.]us/ suplanta a la Agencia Tributaria (AEAT) española para distribuir el malware #LummaStealer.

El señuelo: "VeriFactu: Instala tu certificado de facturación electrónica." ⚠️ 

* VeriFactu es una iniciativa legítima
Josep Albors (@josepalbors) 's Twitter Profile Photo

Más información acerca de esta nueva campaña de phishing en el blog de Ontinet.com: ➡️ ontinet.com/blog/protegers…

Cádiz Directo (@cadizdirecto) 's Twitter Profile Photo

Amenazas y chulería. LaLiga responde al estilo Tebas al intento de Cádiz Directo de resolver por la vía del diálogo su bloqueo tan injustificable como injustificado. cadizdirecto.com/noticias/cadiz…

Will (@bushidotoken) 's Twitter Profile Photo

Have you ever wondered "How do I found out who owns an IP address?" or "Who is the owner of these IP addresses?" A new Curated Intelligence resource is available. Check it out 👇 github.com/curated-intel/…

Germán Fernández (@1zrr4h) 's Twitter Profile Photo

🛑 Attention to this, I searched for "rvtools download" in Microsoft #Bing and Microsoft #Copilot itself recommended the rvtools[.]org site (x.com/tsnikle/status…) which leads to the Bumblebee download (+signed) 🤦‍♂️ As we have said many times, DO NOT BLINDLY TRUST the

🛑 Attention to this, I searched for "rvtools download" in Microsoft #Bing and Microsoft #Copilot itself recommended the rvtools[.]org site (x.com/tsnikle/status…) which leads to the Bumblebee download (+signed) 🤦‍♂️

As we have said many times, DO NOT BLINDLY TRUST the
BandaAncha (@bandaanchaeu) 's Twitter Profile Photo

Advertencia de Matthew Prince, CEO de ☁️ Cloudflare ➡️ Se están bloqueando recursos de 🆘 emergencia vitales en España ➡️ Es cuestión de tiempo que los bloqueos del ⚽️ fútbol pongan vidas en riesgo 👇 bandaancha.eu/articulos/ceo-…

Germán Fernández (@1zrr4h) 's Twitter Profile Photo

🚩 #Bumblebee is still spreading through SEO poisoning, signed malware and fake IT tools targeting mainly network/system administrators. In addition, Microsoft's ecosystem fails at 3 different layers: search, AI and protection ⚠️ 1.- Bing, shows as first result a fake NetCrunch

🚩 #Bumblebee is still spreading through SEO poisoning, signed malware and fake IT tools targeting mainly network/system administrators.

In addition, Microsoft's ecosystem fails at 3 different layers: search, AI and protection ⚠️

1.- Bing, shows as first result a fake NetCrunch
Will (@bushidotoken) 's Twitter Profile Photo

⚠️ IntelBroker was arrested in France 🇫🇷 in February 2025, and the US 🇺🇸 is seeking his extradition. How did Law Enforcement Deanonymize IntelBroker? 🔍 TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy 💰 justice.gov/usao-sdny/medi…

⚠️ IntelBroker was arrested in France 🇫🇷 in February 2025, and the US 🇺🇸 is seeking his extradition.

How did Law Enforcement Deanonymize IntelBroker? 🔍 

TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy 💰 

justice.gov/usao-sdny/medi…
Will (@bushidotoken) 's Twitter Profile Photo

Sending out vulnerability notifications is always difficult. But Friday afternoons, while the US is off on a national holiday, makes things much harder. Curated Intelligence members are doing gods work behind the scenes to stop the next wave of ransomware attacks as best we can 🫡

Mikhail Kasimov (@500mk500) 's Twitter Profile Photo

Nice catch! title: TOP-FIXER/TOP-HALPER: 2yolk\.com fixpricemoving\.com fixpromax\.com fixups4sale\.com top-halper\.com #osx #amos [1/n]

Nice catch!

title: TOP-FIXER/TOP-HALPER:

2yolk\.com
fixpricemoving\.com
fixpromax\.com
fixups4sale\.com
top-halper\.com

#osx #amos

[1/n]
Germán Fernández (@1zrr4h) 's Twitter Profile Photo

🔸 http://196.251.71[.]46/ #opendir The HTML pages abuse Microsoft's search-ms URI protocol to open a remote WebDAV server at 45.151.62[.]238 and initiate the infection chain via LNK files that look like PDF's 😏 [+] "Adobe Acrobat.exe": bazaar.abuse.ch/sample/1cdce73…

🔸 http://196.251.71[.]46/ #opendir

The HTML pages abuse Microsoft's search-ms URI protocol to open a remote WebDAV server at 45.151.62[.]238 and initiate the infection chain via LNK files that look like PDF's 😏

[+] "Adobe Acrobat.exe": bazaar.abuse.ch/sample/1cdce73…
Daniel López (@0xdaniellopez) 's Twitter Profile Photo

"Me acaban de poner una multa" escucho a un familiar. 👉🏻 /multas-consultar.com Dominio simple pero efectivo, frontend cuidado y el mensaje entra en el mismo hilo de SMS legítimos anteriores de la Dir. Gral. Tráfico • Multas de la DGT 💀 • Pagos por paquetes en aduanas 💀 • Hacienda 💀

"Me acaban de poner una multa" escucho a un familiar.

👉🏻 /multas-consultar.com

Dominio simple pero efectivo, frontend cuidado y el mensaje entra en el mismo hilo de SMS legítimos anteriores de la <a href="/DGTes/">Dir. Gral. Tráfico</a> 

• Multas de la DGT 💀
• Pagos por paquetes en aduanas 💀
• Hacienda 💀
MalwareHunterTeam (@malwrhunterteam) 's Twitter Profile Photo

"ai.exe": 052d5220529b6bd4b01e5e375b5dc3ffd50c4b137e242bbfb26655fd7f475ac6 There is OpenAI API traffic and logs like: "[*] AI-powered stealth payload started." "[*] Decision: false (confidence 0.90): Presence of sysmon.exe suggests potential system monitoring and could pose a

"ai.exe": 052d5220529b6bd4b01e5e375b5dc3ffd50c4b137e242bbfb26655fd7f475ac6
There is OpenAI API traffic and logs like:
"[*] AI-powered stealth payload started."
"[*] Decision: false (confidence 0.90): Presence of sysmon.exe suggests potential system monitoring and could pose a