home.social

#opendir — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #opendir, aggregated by home.social.

fetched live
  1. #remcos hta and payload in an #opendir at:

    http://157.254.223\.141/25/

  2. #remcos hta and payload in an #opendir at:

    http://157.254.223\.141/25/

  3. #remus #opendir at:

    http:// apexdataserver4\.sbs/load/os1/

    c2: carogra\.biz:4219

  4. #reverseloader #remcos #opendir at:

    http://107.172.235\.213/95/ also img dir

    c2: 173.231.188\.244:14641

  5. #malware #opendir #xloader (small one works, big one not so much) at:

    https://royfils\.com/encrypt/

    2cd9b8fb88e7cbbc5c049441fb61e0aea7be23dc7aa2c109c13abefe7a2ac943

    4733feaca04e871d4e0bb052f2437a2f46f10852602ea4f8b2f0170f4838dd87

  6. Back in the rest of the #opendir, uploads/ is used by app.py, I don't see where downloads_cache is used, but similar agent-[0-9]+ structure. The SANS PDF "All-books-in-oneSANSSEC670RedTeamingTools-DevelopingCustomToolsforWindows.pdf" may be the inspiration behind app.py/agent.go

  7. Back in the rest of the #opendir, uploads/ is used by app.py, I don't see where downloads_cache is used, but similar agent-[0-9]+ structure. The SANS PDF "All-books-in-oneSANSSEC670RedTeamingTools-DevelopingCustomToolsforWindows.pdf" may be the inspiration behind app.py/agent.go

  8. Interesting #OpenDir on #QuasarRat C2 server 185.208.159[.]161:8000 . The open web directory includes source code for a backdoor + misc development artifacts.

    platform.censys.io/hosts/185.2
    search.censys.io/hosts/185.208

    #malware #thread 🧵

  9. Interesting #OpenDir on #QuasarRat C2 server 185.208.159[.]161:8000 . The open web directory includes source code for a backdoor + misc development artifacts.

    platform.censys.io/hosts/185.2
    search.censys.io/hosts/185.208

    #malware #thread 🧵

  10. #malware #opendir ultimately #venomrat + #hvnc:

    https://carltonsfile\.com/mor1/ -> https://paste\.ee/d/c7nSA2yM/0

    c2: 109.248.144.175:4449

    4541fd01a19f1e484f24eff86f42ac36ea9b30686fd405ca0a50f3e517657a61

  11. If you're not blocking trycloudflare\.com at the perimeter, now's the time: #opendir 's:

    https://em-ash-announcements-alpha.trycloudflare\.com/1DSAHJKSA/ ->
    https://did-efficiency-than-lenses.trycloudflare\.com ->
    https://reached-theoretical-regular-impact\.trycloudflare.com

  12. #webshell #opendir #netsupport #rat at:

    https://appointedtimeagriculture\.com/wp-includes/blocks/post-content/

    GatewayAddress=95.179.158.213:443
    RADIUSSecret=dgAAAPpMkI7ke494fKEQRUoablcA

  13. 💡No #opendir? Why don't you check for .DS_Store files listing the structure ?

    Our scans found 11,856,006 IPs and DNS exposing the file.

    Link: leakix.net/search?scope=leak&q
    Ref: 0day.work/parsing-the-ds_store

  14. 💡No #opendir? Why don't you check for .DS_Store files listing the structure ?

    Our scans found 11,856,006 IPs and DNS exposing the file.

    Link: leakix.net/search?scope=leak&q
    Ref: 0day.work/parsing-the-ds_store

  15. #opendir at:

    https:// superior-somalia-bs-leisure.trycloudflare\.com ->
    http:// jsnybsafva\.biz:8030

  16. #snakekelogger hta's at #opendir :

    http://192.3.176\.138/xampp/ozon
    drops
    http://192.3.176\.138/105/sahost.exe (also 106)

    d9863b7b710599bc2b308a0b78970da8c42ee5bc6d3dcda05c2de52a88125726

    exfils to: [email protected]

  17. Large #opendir at:

    http://57.180.253.244

    medium confidence msbuild.exe is #ghostrat

  18. 🚨#Chile🇨🇱: Cerca de 20000 archivos de Oftalmología expuestas en un #opendir.

    🚨Entre estos datos se exponen registros de Oftalmología, recetas de lentes.

    #misconfigurations #cybersecurity #ciberseguridad #CL

  19. 🚨#Colombia🇨🇴: Miles de archivos expuestos de una consulta médica Domiciliaria, ADOM en un #opendir.

    🚨Entre estos datos se exponen resumen de historias clínicas, PCR-Test.

    #cybersecurity #ciberseguridad #latam #co