home.social

#parrottds — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #parrottds, aggregated by home.social.

fetched live
  1. Following up on the Parrot TDS domains, I was looking at the name servers they are using. Here's some of the other domains in their neighborhood. Nothing sus here. I don't recommend this hosting provider lol. #ParrotTDS #dns #lookalike #phishing #malware #cybercrime developersbb[.]com,myinfotech[.]online,devbeyondborders[.]com,galaxynote4manual[.]com,galaxys3manual[.]com,galaxys5manuals[.]com,galaxys6manuals[.]net,iphone6manualib[.]com,letspallets[.]de,letspallets[.]lt,letspallets[.]lv,letspallets[.]pl,samsunggalaxys4manual[.]com,senateexplorer[.]info

  2. @rmceoin @cyberamateur thank you both. i had read the avast article but not that latest. this is very helpful. Based on the DNS these domains are all Parrot TDS although not all are in urlscan. Their DNS records are surprisingly inconsistent, but the name servers they use are small and sus. Based on how varied VexTrio activities are, i wouldn't be surprised if Parrot owned one of these "hosting" companies. Several of these you already posted. #ParrotTDS cachespace[.]net,resourcehost[.]net,webappclick[.]net,webcachespace[.]net,webcachestorage[.]com,webfiledata[.]com,googlecloudad[.]com,googlecloudns[.]com,googlecloudstream[.]com

  3. @monitorsg i was looking at a few of the domains you and @rmceoin posted recently as #ParrotTDS to see what they look like in our data.. which led me to poke about a bit. so it seems like ping.cachspace[.]net is part of the TDS which redirected to https://standard.architech3[.]com/h6HyhfyDkezjg8i3spHep/WDyKfwxJjq89eCp/o= with another obfuscated script.... i can start to see their DNS setup more clearly, but I'm not used to digging into the delivered scripts... can one of you (or anyone else lol) point me to what code led to loading from ping.cachepace[.]net? I am looking at this urlscan result to see the original site, the TDS, and the landing page. urlscan.io/result/0d6f54d4-a99

  4. #FakeSG seems a bit quiet lately so digging around I stumbled into yet another site with multiple fakeupdates. At this site the #ParrotTDS is still operational and sent the potential user to #SocGholish

    Does make you wonder if it's all the same actor just trying out very different approaches? They got a new employee who was tasked with trying something different.

    ¯_(ツ)_/¯

  5. Bingo! Got the #ParrotTDS to send me to the #SocGholish C2 that I already know.

  6. Been a while since I reversed a #ParrotTDS injection. But was inspired to do a round today. Surprise surprise, out popped a domain that wasn't already blocked. It came online Aug 5th. Blocking that bad boy now.

    storage.webfiledata[.]com

    I couldn't get the victim site to actually call the TDS. But if you call it directly it responds with the cookie the TDS likes to set.