#opendir — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #opendir, aggregated by home.social.
-
-
Malicious #simplehelp #rmm #opendir at:
https://katz.adv\.br/dhl/
-
Malicious #simplehelp #rmm #opendir at:
https://katz.adv\.br/dhl/
-
#reverseloader #xworm #opendir at:
http://158.94.211\.63/dealer/
-
#reverseloader #xworm #opendir at:
http://158.94.211\.63/dealer/
-
#webshell #opendir #netsupport #rat at:
https://appointedtimeagriculture\.com/wp-includes/blocks/post-content/
GatewayAddress=95.179.158.213:443
RADIUSSecret=dgAAAPpMkI7ke494fKEQRUoablcA -
http://trackingshipmentt\.xyz:9394/
http://trackmyshipeng\.site:9094/https://app.any.run/tasks/086f767d-cb57-46d0-80f6-1d771148444e/
-
#snakekelogger hta's at #opendir :
http://192.3.176\.138/xampp/ozon
drops
http://192.3.176\.138/105/sahost.exe (also 106)d9863b7b710599bc2b308a0b78970da8c42ee5bc6d3dcda05c2de52a88125726
exfils to: [email protected]
-
-
📥 Interesting #opendir
45.84.1[.]161:8081
Hosted at AS44477 Stark Industries Solutions Ltd. 🗑️Obf. #Sliver Linux #Implant and a Powershell script which tries to bypass AMSI and runs #Sharphound
From the choice of hosting provider we infer malicious intent rather than #RedTeam
Artifacts (#IoC)
ff32a69075d9eb59ea5d25207d3ee775 rtn_default
2fe7fb5ff2679de37673997b96958d08 rtn_info.ps1Samples available @abuse_ch Bazaar:
https://bazaar.abuse.ch/sample/763bd227a5aef5ef98cd6b79649cb8737f8845fcc2a92e69109f042c975e4a4b/ -
📥 Interesting #opendir
45.84.1[.]161:8081
Hosted at AS44477 Stark Industries Solutions Ltd. 🗑️Obf. #Sliver Linux #Implant and a Powershell script which tries to bypass AMSI and runs #Sharphound
From the choice of hosting provider we infer malicious intent rather than #RedTeam
Artifacts (#IoC)
ff32a69075d9eb59ea5d25207d3ee775 rtn_default
2fe7fb5ff2679de37673997b96958d08 rtn_info.ps1Samples available @abuse_ch Bazaar:
https://bazaar.abuse.ch/sample/763bd227a5aef5ef98cd6b79649cb8737f8845fcc2a92e69109f042c975e4a4b/ -
📥 Interesting #opendir
45.84.1[.]161:8081
Hosted at AS44477 Stark Industries Solutions Ltd. 🗑️Obf. #Sliver Linux #Implant and a Powershell script which tries to bypass AMSI and runs #Sharphound
From the choice of hosting provider we infer malicious intent rather than #RedTeam
Artifacts (#IoC)
ff32a69075d9eb59ea5d25207d3ee775 rtn_default
2fe7fb5ff2679de37673997b96958d08 rtn_info.ps1Samples available @abuse_ch Bazaar:
https://bazaar.abuse.ch/sample/763bd227a5aef5ef98cd6b79649cb8737f8845fcc2a92e69109f042c975e4a4b/ -
Hive... again!
Detected by Stalkphish.io
Targeting @USPS @swisspost
#phishingkit #phishing #soc
#cybersecurity #scam #stalkphish #opendir -
Hive... again!
Detected by Stalkphish.io
Targeting @USPS @swisspost
#phishingkit #phishing #soc
#cybersecurity #scam #stalkphish #opendir -
Hive... again!
Detected by Stalkphish.io
Targeting @USPS @swisspost
#phishingkit #phishing #soc
#cybersecurity #scam #stalkphish #opendir -
Hive... again!
Detected by Stalkphish.io
Targeting @USPS @swisspost
#phishingkit #phishing #soc
#cybersecurity #scam #stalkphish #opendir