The Flask app uses sandboxed Jinja2. The operator intentionally leaked JWT_SECRET through template rendering but blocked direct #RCE methods, protecting their own infrastructure from other attackers while still exposing sensitive config values.
An open directory on 124.223.221[.]83:9999 (Tencent Cloud, Shanghai) exposes a full #offensive toolkit. #CobaltStrike 4.7, Chrome XXE #exploit, internal network scan results, a web shell, and a custom #C2. Let's break it down. 🧵👇
Found via @Huntio
PHISHING INFRASTRUCTURE ALIVE 🚨
A # leads to multiple nodes hosting the same site
IOCS:
fbi-investingationunit[.]com
digitalassetsreclaim[.]com
www.fbi-sec.globalfundrecoveryunit[.]com
auracyber-investigation[.]com
198.251.84[.]200
172.67.162[.]245
66.85.46[.]67
51.195.95[.]80
Observed new domain: coliseumdlc[.]xyz distributing a Windows executable #ShinyLoader.exe with #trojan characteristics, including defense evasion and discovery behavior. It currently has 0 detections on #VirusTotal & #QiAnXin
Day 05 of posting #CTI findings everyday for 30 days
A #CobaltStrike teamserver operation is exposed on 101.42.136[.]73 (Tencent Cloud, Beijing). The #opendirectory contains #beacon keys, #teamserver config, subdomain wordlists, and post-exploitation tooling.
Credits @Huntio
Day 3 of posting #CTI findings everyday for 30 days
Suspicious ScreenConnect instance at holtermediainc[.]screenconnect[.]com (15.204.108.63) serving /Bin/ScreenConnect.ClientSetup.exe?e=Access&y=Guest.
Flagged as #HackTool/#RemoteAdmin/#Trojan#ScreenConnect#ThreatIntel