home.social

#keitarotds — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #keitarotds, aggregated by home.social.

fetched live
  1. Most TDSes used by cybercriminals – BlackTDS, Prometheus, Parrot, 404 – are underground/black market tools. #KeitaroTDS is different. It's a commercial offering from a software company in Estonia that is viewed as legitimate by vendors like Microsoft.

  2. #KeitaroTDS domains finally moved from AS216419 Matrix Telecom to various other IPs / networks, such as:

  3. Hmm, what is this? Noticed another #KeitaroTDS that appears to be using the same template at #FakeSG

    advertising-cdn[.]com/Y34dw7

    Also of note is this victim site is a .gov. I tend to think of those as generally safe. I suppose this is an example of even .gov sites are not impervious.

    The path that got me to this originally came from another domain name on the same host.

    new-adversting[.]com/P6g7Hh

    Both have been out there since last year.

  4. Hmm, what is this? Noticed another #KeitaroTDS that appears to be using the same template at #FakeSG

    advertising-cdn[.]com/Y34dw7

    Also of note is this victim site is a .gov. I tend to think of those as generally safe. I suppose this is an example of even .gov sites are not impervious.

    The path that got me to this originally came from another domain name on the same host.

    new-adversting[.]com/P6g7Hh

    Both have been out there since last year.

  5. @mithrandir is it just me or is the #KeitaroTDS struggling? Over the last two days I'm seeing lots of no connections. A few sneak through and I'll get the TDS. Haven't seen it make it to the JS C2 today.

  6. @mithrandir is it just me or is the #KeitaroTDS struggling? Over the last two days I'm seeing lots of no connections. A few sneak through and I'll get the TDS. Haven't seen it make it to the JS C2 today.

  7. @bongoknight Good point. What surprised us is that the domain is behind Cloudflare, which isn't the pattern for e.g. #KeitaroTDS or other SocGholish domains.

  8. After a break, a new #KeitaroTDS domain appeared on 47.91.94[.]97: libertader[.]org.

    The associated #SocGholish TDS is specific.autonerdmobilerepairs[.]com hosted on 35.176.231[.]198 (previously #SocGholish C2 *.reseller.wonderfulworldblog[.]com)

  9. Hmm, there's something on here:

    www.greendalept[.]com

    That makes a call to here:

    sarcoma[.]space/js/min.main.js

    or here:

    sarcoma[.]space/VJVGbW

    It's got my attention because it's a #KeitaroTDS, but different from the one I've been poking at. Very curious.

  10. Hmm, there's something on here:

    www.greendalept[.]com

    That makes a call to here:

    sarcoma[.]space/js/min.main.js

    or here:

    sarcoma[.]space/VJVGbW

    It's got my attention because it's a #KeitaroTDS, but different from the one I've been poking at. Very curious.

  11. Ahh, found the new #KeitaroTDS domain.

    greedyfines[.]org

  12. Ahh, found the new #KeitaroTDS domain.

    greedyfines[.]org

  13. New second stage TDS and C2 for #SocGholish coming from #KeitaroTDS

    TDS stage 2
    static.laytonroadconstruction[.]com

    C2
    *.nodes.gammalambdalambda[.]org
    102.223.180[.]164

    There appears to be a new KetiaroTDS host as well, but haven't seen it show up yet.

  14. New second stage TDS and C2 for #SocGholish coming from #KeitaroTDS

    TDS stage 2
    static.laytonroadconstruction[.]com

    C2
    *.nodes.gammalambdalambda[.]org
    102.223.180[.]164

    There appears to be a new KetiaroTDS host as well, but haven't seen it show up yet.

  15. New second stage TDS for #SocGholish coming from #KeitaroTDS.

    masterclass.teamupnetwork[.]org

    Infection path observed:

    {compromised site}

    KeitaroTDS
    cancelledfirestarter[.]org
    dailytickyclock[.]org
    deeptrickday[.]org

    Second stage TDS
    masterclass.teamupnetwork[.]org

    C2
    cywu.offer.rpacxtaxappeal[.]com

  16. New second stage TDS for #SocGholish coming from #KeitaroTDS.

    masterclass.teamupnetwork[.]org

    Infection path observed:

    {compromised site}

    KeitaroTDS
    cancelledfirestarter[.]org
    dailytickyclock[.]org
    deeptrickday[.]org

    Second stage TDS
    masterclass.teamupnetwork[.]org

    C2
    cywu.offer.rpacxtaxappeal[.]com

  17. So the #KeitaroTDS offers up at least two paths. One is #SocGholish that I've been tracking and the other is some notification malware that I've seen before but didn't realize they're connected.

    When I go to an infected site, I only get served SocGholish. But I see when urlscan goes to it, they get this other scam. What's handy is I can go directly to the KeitaroTDS URLs associated with those scams and see that other path.

    backendjs[.]org/kb3xCR3d
    cancelledfirestarter[.]org/Qw6YdVL
    dailytickyclock[.]org/H9nZW3yw
    deeptrickday[.]org/xTHcrXYN
    devqeury[.]org/XdQJSbwV
    devqeury[.]org/VjCTRDTQ
    jqscr[.]com/GPfymwFy
    jqscr[.]com/MFkkBGCh
    jqueryns[.]com/jbMbKDPn
    jsqur[.]com/97rmMy8V

    Anybody have a name for this notification scam?

  18. So the #KeitaroTDS offers up at least two paths. One is #SocGholish that I've been tracking and the other is some notification malware that I've seen before but didn't realize they're connected.

    When I go to an infected site, I only get served SocGholish. But I see when urlscan goes to it, they get this other scam. What's handy is I can go directly to the KeitaroTDS URLs associated with those scams and see that other path.

    backendjs[.]org/kb3xCR3d
    cancelledfirestarter[.]org/Qw6YdVL
    dailytickyclock[.]org/H9nZW3yw
    deeptrickday[.]org/xTHcrXYN
    devqeury[.]org/XdQJSbwV
    devqeury[.]org/VjCTRDTQ
    jqscr[.]com/GPfymwFy
    jqscr[.]com/MFkkBGCh
    jqueryns[.]com/jbMbKDPn
    jsqur[.]com/97rmMy8V

    Anybody have a name for this notification scam?

  19. New #KeitaroTDS domain used for #SocGholish.

    cancelledfirestarter[.]org/tT2NCZN5
    🚫​🔥

    @threatcat_ch I see that the domains_count from the API now shows 19. 👀

    #ThreatIntel

  20. New #KeitaroTDS domain used for #SocGholish.

    cancelledfirestarter[.]org/tT2NCZN5
    🚫​🔥

    @threatcat_ch I see that the domains_count from the API now shows 19. 👀

    #ThreatIntel

  21. While poking at the #KeitaroTDS used by #SocGholish I noticed a different path. Using torsocks in the hopes of getting different responses, this known #KeitaroTDS URL

    dailytickyclock[.]org/Rz7kFbxJ

    would return a redirect I haven't noticed.

    dailytickyclock[.]org/H9nZW3yw

    That in turn was redirecting to here.

    greatbonushere[.]life/?u=4dkpaew&o=81yk607&cid=vi0n933mcrfi

    That led to a couple of scams. Mostly I got a fake iPhone prize scam that tries to dup you into providing your address and CC info.

    Pivoting off the IP for the domain out popped 78 more domains. Block them nasties! 🚫​

    gist.github.com/rmceoin/9e3fb7

  22. While poking at the #KeitaroTDS used by #SocGholish I noticed a different path. Using torsocks in the hopes of getting different responses, this known #KeitaroTDS URL

    dailytickyclock[.]org/Rz7kFbxJ

    would return a redirect I haven't noticed.

    dailytickyclock[.]org/H9nZW3yw

    That in turn was redirecting to here.

    greatbonushere[.]life/?u=4dkpaew&o=81yk607&cid=vi0n933mcrfi

    That led to a couple of scams. Mostly I got a fake iPhone prize scam that tries to dup you into providing your address and CC info.

    Pivoting off the IP for the domain out popped 78 more domains. Block them nasties! 🚫​

    gist.github.com/rmceoin/9e3fb7

  23. New #SocGholish TDS on 91.208.184[.]14 (ALEXHOST) is archives.finanpress[.]com, found referenced by #KeitaroTDS dailytickyclock[.]org . SocGholish C2 still on *.offer.rpacxtaxappeal[.]com / 190.211.254[.]31 (Private Layer)

  24. Now also on 88.119.169[.]146 (IST) we have new #SocGholish TDS booty.midatlanticlaw[.]org witnessed in #KeitaroTDS redirects.

  25. Now also on 88.119.169[.]146 (IST) we have new #SocGholish TDS booty.midatlanticlaw[.]org witnessed in #KeitaroTDS redirects.

  26. #TA569 #KeitaroTDS TDS domain are now on 91.203.193[.]124, including new domain dailytickyclock[.]org (inject seen in the wild: hXXps://dailytickyclock[.]org/Rz7kFbxJ ) redirecting to #SocGholish TDS commercial.tedgorka[.]com hosted on 88.119.169[.]146 as already noticed by @rmceoin

    infosec.exchange/@rmceoin/1104

  27. #TA569 #KeitaroTDS TDS domain are now on 91.203.193[.]124, including new domain dailytickyclock[.]org (inject seen in the wild: hXXps://dailytickyclock[.]org/Rz7kFbxJ ) redirecting to #SocGholish TDS commercial.tedgorka[.]com hosted on 88.119.169[.]146 as already noticed by @rmceoin

    infosec.exchange/@rmceoin/1104

  28. Today's new #TA569 #KeitaroTDS TDS domain, still hosted on the same IP as the others, is deeptrickday[.]org - e.g. hXXps://deeptrickday[.]org/fMYD7fFx seen in wild.

    2nd stage SocGholish TDS remains trackrecord[.]wheresbecky[.]com but finally we also witness new SocGholish C2 *[.]score[.]symposiumhaiti[.]com on 5.255.119[.]147 :

    infosec.exchange/@rmceoin/1102

  29. New #TA569 #KeitaroTDS TDS neworderspath[.]org - hXXps://neworderspath[.]org/k4WP6NP9 spotted in the wild.

    Will share all these IOCs via Threatfox of @abuse_ch as soon as its login is working again!

  30. Summer is coming - or at least the new #TA569 #KeitaroTDS TDS domains hosted on 47.90.178[.]252 keep on giving!

    Today's new entry is
    - hXXps://lemonicecold[.]org/cd5fkZwv

    How many of these injections can be found in the wild? Check yourself on urlscan.io : urlscan.io/search/#ip%3A47.90.

    :blobcatheart:​

  31. New #TA569 #KeitaroTDS TDS domains observed in the wild, still hosted 47.90.178[.]252:
    hXXps://greenpapers[.]org/6gjyRhhQ
    hXXps://waterlinesheet[.]org/bDrVdw9c

    Victims accepted by these TDS are redirected toward SocGholish TDS trackrecord.wheresbecky[.]com .

    SocGolish C2 observed for the payload remains on *.reseller.wonderfulworldblog[.]com / 35.176.231[.]198 (Amazon)