#keitarotds — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #keitarotds, aggregated by home.social.
-
Malicious ISO File Used in Romance Scam Targeting German Speakers https://hackread.com/malicious-iso-file-romance-scam-on-german-speakers/ #SublimeSecurity #ScamsandFraud #Cybersecurity #CyberAttack #RomanceScam #KeitaroTDS #Security #Germany #Malware #Fraud
-
Malicious ISO File Used in Romance Scam Targeting German Speakers https://hackread.com/malicious-iso-file-romance-scam-on-german-speakers/ #SublimeSecurity #ScamsandFraud #Cybersecurity #CyberAttack #RomanceScam #KeitaroTDS #Security #Germany #Malware #Fraud
-
Malicious ISO File Used in Romance Scam Targeting German Speakers – Source:hackread.com https://ciso2ciso.com/malicious-iso-file-used-in-romance-scam-targeting-german-speakers-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #SublimeSecurity #cybersecurity #ScamsandFraud #CyberAttack #RomanceScam #KeitaroTDS #Hackread #security #Germany #malware #Fraud
-
Malicious ISO File Used in Romance Scam Targeting German Speakers – Source:hackread.com https://ciso2ciso.com/malicious-iso-file-used-in-romance-scam-targeting-german-speakers-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #SublimeSecurity #cybersecurity #ScamsandFraud #CyberAttack #RomanceScam #KeitaroTDS #Hackread #security #Germany #malware #Fraud
-
Most TDSes used by cybercriminals – BlackTDS, Prometheus, Parrot, 404 – are underground/black market tools. #KeitaroTDS is different. It's a commercial offering from a software company in Estonia that is viewed as legitimate by vendors like Microsoft.
-
#KeitaroTDS domains finally moved from AS216419 Matrix Telecom to various other IPs / networks, such as:
-
Hmm, what is this? Noticed another #KeitaroTDS that appears to be using the same template at #FakeSG
advertising-cdn[.]com/Y34dw7
Also of note is this victim site is a .gov. I tend to think of those as generally safe. I suppose this is an example of even .gov sites are not impervious.
The path that got me to this originally came from another domain name on the same host.
new-adversting[.]com/P6g7Hh
Both have been out there since last year.
-
Hmm, what is this? Noticed another #KeitaroTDS that appears to be using the same template at #FakeSG
advertising-cdn[.]com/Y34dw7
Also of note is this victim site is a .gov. I tend to think of those as generally safe. I suppose this is an example of even .gov sites are not impervious.
The path that got me to this originally came from another domain name on the same host.
new-adversting[.]com/P6g7Hh
Both have been out there since last year.
-
Anybody ever try reporting the various #KeitaroTDS used by #SocGholish and others?
-
Anybody ever try reporting the various #KeitaroTDS used by #SocGholish and others?
-
@mithrandir is it just me or is the #KeitaroTDS struggling? Over the last two days I'm seeing lots of no connections. A few sneak through and I'll get the TDS. Haven't seen it make it to the JS C2 today.
-
@mithrandir is it just me or is the #KeitaroTDS struggling? Over the last two days I'm seeing lots of no connections. A few sneak through and I'll get the TDS. Haven't seen it make it to the JS C2 today.
-
@bongoknight Good point. What surprised us is that the domain is behind Cloudflare, which isn't the pattern for e.g. #KeitaroTDS or other SocGholish domains.
-
After a break, a new #KeitaroTDS domain appeared on 47.91.94[.]97: libertader[.]org.
The associated #SocGholish TDS is specific.autonerdmobilerepairs[.]com hosted on 35.176.231[.]198 (previously #SocGholish C2 *.reseller.wonderfulworldblog[.]com)
-
Hmm, there's something on here:
That makes a call to here:
sarcoma[.]space/js/min.main.js
or here:
sarcoma[.]space/VJVGbW
It's got my attention because it's a #KeitaroTDS, but different from the one I've been poking at. Very curious.
-
Hmm, there's something on here:
That makes a call to here:
sarcoma[.]space/js/min.main.js
or here:
sarcoma[.]space/VJVGbW
It's got my attention because it's a #KeitaroTDS, but different from the one I've been poking at. Very curious.
-
-
-
New second stage TDS and C2 for #SocGholish coming from #KeitaroTDS
TDS stage 2
static.laytonroadconstruction[.]comC2
*.nodes.gammalambdalambda[.]org
102.223.180[.]164There appears to be a new KetiaroTDS host as well, but haven't seen it show up yet.
-
New second stage TDS and C2 for #SocGholish coming from #KeitaroTDS
TDS stage 2
static.laytonroadconstruction[.]comC2
*.nodes.gammalambdalambda[.]org
102.223.180[.]164There appears to be a new KetiaroTDS host as well, but haven't seen it show up yet.
-
New second stage TDS for #SocGholish coming from #KeitaroTDS.
masterclass.teamupnetwork[.]org
Infection path observed:
{compromised site}
KeitaroTDS
cancelledfirestarter[.]org
dailytickyclock[.]org
deeptrickday[.]orgSecond stage TDS
masterclass.teamupnetwork[.]orgC2
cywu.offer.rpacxtaxappeal[.]com -
New second stage TDS for #SocGholish coming from #KeitaroTDS.
masterclass.teamupnetwork[.]org
Infection path observed:
{compromised site}
KeitaroTDS
cancelledfirestarter[.]org
dailytickyclock[.]org
deeptrickday[.]orgSecond stage TDS
masterclass.teamupnetwork[.]orgC2
cywu.offer.rpacxtaxappeal[.]com -
So the #KeitaroTDS offers up at least two paths. One is #SocGholish that I've been tracking and the other is some notification malware that I've seen before but didn't realize they're connected.
When I go to an infected site, I only get served SocGholish. But I see when urlscan goes to it, they get this other scam. What's handy is I can go directly to the KeitaroTDS URLs associated with those scams and see that other path.
backendjs[.]org/kb3xCR3d
cancelledfirestarter[.]org/Qw6YdVL
dailytickyclock[.]org/H9nZW3yw
deeptrickday[.]org/xTHcrXYN
devqeury[.]org/XdQJSbwV
devqeury[.]org/VjCTRDTQ
jqscr[.]com/GPfymwFy
jqscr[.]com/MFkkBGCh
jqueryns[.]com/jbMbKDPn
jsqur[.]com/97rmMy8VAnybody have a name for this notification scam?
-
So the #KeitaroTDS offers up at least two paths. One is #SocGholish that I've been tracking and the other is some notification malware that I've seen before but didn't realize they're connected.
When I go to an infected site, I only get served SocGholish. But I see when urlscan goes to it, they get this other scam. What's handy is I can go directly to the KeitaroTDS URLs associated with those scams and see that other path.
backendjs[.]org/kb3xCR3d
cancelledfirestarter[.]org/Qw6YdVL
dailytickyclock[.]org/H9nZW3yw
deeptrickday[.]org/xTHcrXYN
devqeury[.]org/XdQJSbwV
devqeury[.]org/VjCTRDTQ
jqscr[.]com/GPfymwFy
jqscr[.]com/MFkkBGCh
jqueryns[.]com/jbMbKDPn
jsqur[.]com/97rmMy8VAnybody have a name for this notification scam?
-
New #KeitaroTDS domain used for #SocGholish.
cancelledfirestarter[.]org/tT2NCZN5
🚫🔥@threatcat_ch I see that the domains_count from the API now shows 19. 👀
-
New #KeitaroTDS domain used for #SocGholish.
cancelledfirestarter[.]org/tT2NCZN5
🚫🔥@threatcat_ch I see that the domains_count from the API now shows 19. 👀
-
While poking at the #KeitaroTDS used by #SocGholish I noticed a different path. Using torsocks in the hopes of getting different responses, this known #KeitaroTDS URL
dailytickyclock[.]org/Rz7kFbxJ
would return a redirect I haven't noticed.
dailytickyclock[.]org/H9nZW3yw
That in turn was redirecting to here.
greatbonushere[.]life/?u=4dkpaew&o=81yk607&cid=vi0n933mcrfi
That led to a couple of scams. Mostly I got a fake iPhone prize scam that tries to dup you into providing your address and CC info.
Pivoting off the IP for the domain out popped 78 more domains. Block them nasties! 🚫
https://gist.github.com/rmceoin/9e3fb77686a660374409df467d9711ca
-
While poking at the #KeitaroTDS used by #SocGholish I noticed a different path. Using torsocks in the hopes of getting different responses, this known #KeitaroTDS URL
dailytickyclock[.]org/Rz7kFbxJ
would return a redirect I haven't noticed.
dailytickyclock[.]org/H9nZW3yw
That in turn was redirecting to here.
greatbonushere[.]life/?u=4dkpaew&o=81yk607&cid=vi0n933mcrfi
That led to a couple of scams. Mostly I got a fake iPhone prize scam that tries to dup you into providing your address and CC info.
Pivoting off the IP for the domain out popped 78 more domains. Block them nasties! 🚫
https://gist.github.com/rmceoin/9e3fb77686a660374409df467d9711ca
-
New #SocGholish TDS on 91.208.184[.]14 (ALEXHOST) is archives.finanpress[.]com, found referenced by #KeitaroTDS dailytickyclock[.]org . SocGholish C2 still on *.offer.rpacxtaxappeal[.]com / 190.211.254[.]31 (Private Layer)
-
Now also on 88.119.169[.]146 (IST) we have new #SocGholish TDS booty.midatlanticlaw[.]org witnessed in #KeitaroTDS redirects.
-
Now also on 88.119.169[.]146 (IST) we have new #SocGholish TDS booty.midatlanticlaw[.]org witnessed in #KeitaroTDS redirects.
-
#TA569 #KeitaroTDS TDS domain are now on 91.203.193[.]124, including new domain dailytickyclock[.]org (inject seen in the wild: hXXps://dailytickyclock[.]org/Rz7kFbxJ ) redirecting to #SocGholish TDS commercial.tedgorka[.]com hosted on 88.119.169[.]146 as already noticed by @rmceoin
-
#TA569 #KeitaroTDS TDS domain are now on 91.203.193[.]124, including new domain dailytickyclock[.]org (inject seen in the wild: hXXps://dailytickyclock[.]org/Rz7kFbxJ ) redirecting to #SocGholish TDS commercial.tedgorka[.]com hosted on 88.119.169[.]146 as already noticed by @rmceoin
-
Today's new #TA569 #KeitaroTDS TDS domain, still hosted on the same IP as the others, is deeptrickday[.]org - e.g. hXXps://deeptrickday[.]org/fMYD7fFx seen in wild.
2nd stage SocGholish TDS remains trackrecord[.]wheresbecky[.]com but finally we also witness new SocGholish C2 *[.]score[.]symposiumhaiti[.]com on 5.255.119[.]147 :
-
New #TA569 #KeitaroTDS TDS neworderspath[.]org - hXXps://neworderspath[.]org/k4WP6NP9 spotted in the wild.
Will share all these IOCs via Threatfox of @abuse_ch as soon as its login is working again!
-
Summer is coming - or at least the new #TA569 #KeitaroTDS TDS domains hosted on 47.90.178[.]252 keep on giving!
Today's new entry is
- hXXps://lemonicecold[.]org/cd5fkZwvHow many of these injections can be found in the wild? Check yourself on urlscan.io : https://urlscan.io/search/#ip%3A47.90.178.252
:blobcatheart:
-
New #TA569 #KeitaroTDS TDS domains observed in the wild, still hosted 47.90.178[.]252:
hXXps://greenpapers[.]org/6gjyRhhQ
hXXps://waterlinesheet[.]org/bDrVdw9cVictims accepted by these TDS are redirected toward SocGholish TDS trackrecord.wheresbecky[.]com .
SocGolish C2 observed for the payload remains on *.reseller.wonderfulworldblog[.]com / 35.176.231[.]198 (Amazon)