#opendir leads to disclosure of an unknown C&C Panel that goes with the name "NITRATO C&C - MASTER" wide open without Authorization.
Targets: Android Devices, Windows Systems.
Malware Type: Spyware, keylogger
Malware Capability for both Windows and Android:
- Real-time keylogging
- Screen capture targeting
- User session reconstruction
- Scheduled data exfiltration
- Anti-forensics cleanup behavior
hxxp[:]//148[.]113[.]136[.]44/ do your thing😆
New from @censysio: Uncover attacker infrastructure hiding in plain sight.
Our latest Threat Hunting upgrade adds Open Directory Intelligence, exposing files & tools - giving you early insights into future attack patterns.
Learn more: https://t.co/0I7fyJKXUl
#ThreatHunting
🔴 Redline Stealer through Fake Minecraft Cheats and other tools by the adversary:
- hxxp[:]//107.189.20.81/
- Minecraft_Cheat_v2.8.exe
- RedLine%20Stealer%20Cracked.rar
#Redline#stealer#Censys
Bybit’s $1.5B hack is bullish - Lazarus has diamond hands.
Led by Park Jin Hyok, now wanted by the FBI.
They’ve just drained $1.46B in staked ETH & ERC-20 tokens from Bybit, making it the biggest crypto hack ever, twice the size of the second-largest breach.
How did they pull it off? Let’s break it down. 🧵👇
- worked on the apollo missions
- killed his dad
- started mcafee software
- forbes top 100
- presidential candidate
- wanted in 3 countries
- survived 50+ assassination attempts
- married a prostitute who was hired to kill him
- behind edward snowden
- bitcoin billionaire
- hacked hillary clinton’s office by sending her staff free computers
- killed a few people in belize
- lived on a boat in the caribbean sea with armed guards
- never paid income tax because he blackmails the us gov
- escaped captivity in guatemala by faking a heart attack
- committed suicide in a spanish prison
- may still be alive
Our new Unleash the Power of Censys Search Handbook covers regex queries, matched services, historical data, and more to help you track threats faster. Grab your copy to learn more and explore other #CensysSearch best practices! https://t.co/hGxRu5E1bu
Further Evil Corp cyber criminals exposed following NCA investigation, one unmasked as LockBit affiliate, as UK, US and Australia unveil sanctions.
Read the full story ➡️ https://t.co/MVHye4QU2T
⚠️#Opendirectory Detected!
URL: hxxp://213.109.147.108:4242/
The adversary storing scanning python tools for several CVEs Vulnerabilities with txt file contains possible vulnerable domains.
Censys Query:
services.http.response.body_hashes="sha256:4d8a75f80f81a84c6b39d0162f7a678137b0e3b1fc6a8b207f0fabb4dd45831d" or https://t.co/FgWa4BfuDu.product=`Poseidon`