Top Tweets for #C2Engine
A couple more linked infrastructure:
84.54.51.43
193.233.132.58
Happy Hunting!! 🫡
#moobot
🚀 Tracked by #C2Engine #KryptoKloud #KryptoCTI
🔍📊 Tracking #HooKbot, we've spotted some slight variations to be aware of.
🚀 Detected by #C2Engine #KryptoKloud #KryptoCTI

🚨 #ThreatAlert Spoofed Easy Bank & DKB Bank App Domains 🚨
Our latest intelligence reveals a new threat campaign targeting European Banking Apps.
Indicators: easy-bank[.]app, ib.dkb-bank[.]app.
Stay vigilant! #C2Engine #KryptoCTI #KryptoKloud #EasyBank #DKBBank
![TLP_R3D's tweet photo. 🚨 #ThreatAlert Spoofed Easy Bank & DKB Bank App Domains 🚨
Our latest intelligence reveals a new threat campaign targeting European Banking Apps.
Indicators: easy-bank[.]app, ib.dkb-bank[.]app.
Stay vigilant! #C2Engine #KryptoCTI #KryptoKloud #EasyBank #DKBBank https://t.co/a3Tgx4cgjp](https://pbs.twimg.com/media/F_euCjLWEAEKvI9.jpg)
🚨 Update on potential #RaaS affiliate Activity 🚨
Potential #BlackBasta #ALPHV activity! 🌐 Pivoting on the SSH key we get a nice cluster of IPs with recent activity which includes:
➡️#Meterpreter
➡️#CobaltStrike
➡️#Mythic
➡️#Pikabot
🚀 Detected by #C2Engine #KryptoKloud #KryptoCTI Tracking #ShadowSyndicate

#KryptoKloud and #C2Engine are working on a new Threat Intelligence capability to detect phishing activity pre-attack. Getting some very good results 😎and will be launching soon as part of our KryptoCTI offering. DM if you would like a pre-launch demo 😀 #KryptoCTI
🚨 Cybersecurity Alert 🚨 Phishing domains indirectly linked to #Snatch Ransomware detected! IP 51.250.13.110 located in Russia. Domains appear to target Canada Financial Services.
· simplihl[.]help - Spoofing Simplii Financial
· bmo-importantnotice[.]com - Spoofing Bank of Montreal (BMO)
· rbc-secureaccess[.]ca - Spoofing Royal Bank of Canada (RBC)
· verificationerror[.]com - Generic
· canadarevenue-agcy[.]info - Spoofing Canada Revenue Agency
· direct-gi[.]com - Unclear target
· actve-accept[.]com - Generic
· 4-easyweb-td[.]com - Spoofing TD Bank
· rbccappbnk.[.]om - Spoofing Royal Bank of Canada (RBC)
Stay vigilant and always verify links! #CyberSecurity #PhishingAlert #C2Engine #KryptoKloud
![TLP_R3D's tweet photo. 🚨 Cybersecurity Alert 🚨 Phishing domains indirectly linked to #Snatch Ransomware detected! IP 51.250.13.110 located in Russia. Domains appear to target Canada Financial Services.
· simplihl[.]help - Spoofing Simplii Financial
· bmo-importantnotice[.]com - Spoofing Bank of Montreal (BMO)
· rbc-secureaccess[.]ca - Spoofing Royal Bank of Canada (RBC)
· verificationerror[.]com - Generic
· canadarevenue-agcy[.]info - Spoofing Canada Revenue Agency
· direct-gi[.]com - Unclear target
· actve-accept[.]com - Generic
· 4-easyweb-td[.]com - Spoofing TD Bank
· rbccappbnk.[.]om - Spoofing Royal Bank of Canada (RBC)
Stay vigilant and always verify links! #CyberSecurity #PhishingAlert #C2Engine #KryptoKloud](https://pbs.twimg.com/media/F9SulrsWkAAGYFm.jpg)
🚨 Looking further at the #CISCO IoCs provided on Active Exploitation of Cisco IOS XE Software Web UI vulnerabilities.
🔍 Found these IPs sharing an identical unique HTML page. A pivot revealed even more indicators.
Stay alert! 🛡️ #C2engine #KryptoKloud #KryptoCTI
👇👇 IPs to watch:
205.185.123.]17
209.141.34.]83
154.53.63.]93
192.3.101.]111
92.223.30.]129
95.168.191.]172
192.227.196.]186
108.177.235.]177
92.38.132.]181
92.38.169.]180
192.109.119.]29
154.53.56.]231
Full details 👉https://t.co/uLAtp18UdP
![TLP_R3D's tweet photo. 🚨 Looking further at the #CISCO IoCs provided on Active Exploitation of Cisco IOS XE Software Web UI vulnerabilities.
🔍 Found these IPs sharing an identical unique HTML page. A pivot revealed even more indicators.
Stay alert! 🛡️ #C2engine #KryptoKloud #KryptoCTI
👇👇 IPs to watch:
205.185.123.]17
209.141.34.]83
154.53.63.]93
192.3.101.]111
92.223.30.]129
95.168.191.]172
192.227.196.]186
108.177.235.]177
92.38.132.]181
92.38.169.]180
192.109.119.]29
154.53.56.]231
Full details 👉https://t.co/uLAtp18UdP](https://pbs.twimg.com/media/F9IlvhwXUAATVze.jpg)
🔥 Update: The IoAs we identified on 24th Sept have now matured into IoCs, as featured in a TrendMicro report on 13th Oct! 📆
🛠 Thanks to #C2Engine and #KryptoCTI, we were weeks ahead in flagging these now-confirmed threats. 👀 🚨 Early detection remains crucial! 🗝️
#CyberSecurity #ThreatIntel #ROMCOM @TrendMicro
👉https://t.co/G5f58KWqUs

👀 Scrutinising a few servers for potential #ROMCOM - Caution advised! 🚨
🤔 45.137.155.163 - No flags, 0/88 on VirusTotal
🤔 wirelessvezion[.]com - A blip at 1/89 on VirusTotal
🛠 ISP: STARK INDUSTRIES
🤔 185.250.150.204 - Not flagged, 0/88 on VirusTotal
🤔 netstaticsinformation[.]com - Zero alerts, 0/89 on VirusTotal
🛠 ISP: STARK INDUSTRIES
🕵️ Bonus: IP 185.250.150.204 spotted on Shodan with hostname ergeg[.]fbfb. Which is also an acronym used for the "European Regulators Group for Electricity and Gas" (ERGEG)! 🔍
Stay alert! 🚨 #C2Engine
![TLP_R3D's tweet photo. 👀 Scrutinising a few servers for potential #ROMCOM - Caution advised! 🚨
🤔 45.137.155.163 - No flags, 0/88 on VirusTotal
🤔 wirelessvezion[.]com - A blip at 1/89 on VirusTotal
🛠 ISP: STARK INDUSTRIES
🤔 185.250.150.204 - Not flagged, 0/88 on VirusTotal
🤔 netstaticsinformation[.]com - Zero alerts, 0/89 on VirusTotal
🛠 ISP: STARK INDUSTRIES
🕵️ Bonus: IP 185.250.150.204 spotted on Shodan with hostname ergeg[.]fbfb. Which is also an acronym used for the "European Regulators Group for Electricity and Gas" (ERGEG)! 🔍
Stay alert! 🚨 #C2Engine](https://pbs.twimg.com/media/F6yhQlWXsAAzh29.jpg)
🚨🐍 #APTSidewinder - New C2 discovered
🔹 IP: 193.42.36.66 | Port: 443
🔒 Cert: *.pak-army[.]com
#ThreatIntel #Sidewinder #Pakistan #C2Engine
![TLP_R3D's tweet photo. 🚨🐍 #APTSidewinder - New C2 discovered
🔹 IP: 193.42.36.66 | Port: 443
🔒 Cert: *.pak-army[.]com
#ThreatIntel #Sidewinder #Pakistan #C2Engine https://t.co/GpPJDpBlo5](https://pbs.twimg.com/media/F7cHRjJW4AAqPcw.jpg)
Last Seen Hashtags on Sotwe
Most Popular Users

Elon Musk 
@elonmusk
240.4M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.7M followers

Cristiano Ronaldo 
@cristiano
110.2M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.6M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.8M followers

KATY PERRY 
@katyperry
87.5M followers

Taylor Swift 
@taylorswift13
81.3M followers

Lady Gaga 
@ladygaga
72.8M followers

Kim Kardashian 
@kimkardashian
69.7M followers

Virat Kohli 
@imvkohli
69.6M followers

YouTube 
@youtube
68.7M followers

Bill Gates 
@billgates
63.8M followers

The Ellen Show
@theellenshow
62.5M followers

Neymar Jr 
@neymarjr
62.3M followers

CNN 
@cnn
61.9M followers

X 
@x
60.8M followers

Selena Gomez 
@selenagomez
60.6M followers


![banthisguy9349's tweet photo. #moobot c2
84.54.51.103:6666
87.121.58.103:6666
#mirai
84.54.51.103:32105
87.121.58.103:32105
IOC: nekololis[.]ovh
Hosted on PFcloud[.]io
Abuse reports are not being handled by pfcloud.
hxxps://t.me/nekobotnet https://t.co/K6lYjBY2ek](https://pbs.twimg.com/media/GH_FhOkWwAAZ9BJ.jpg)
![banthisguy9349's tweet photo. #moobot c2
84.54.51.103:6666
87.121.58.103:6666
#mirai
84.54.51.103:32105
87.121.58.103:32105
IOC: nekololis[.]ovh
Hosted on PFcloud[.]io
Abuse reports are not being handled by pfcloud.
hxxps://t.me/nekobotnet https://t.co/K6lYjBY2ek](https://pbs.twimg.com/media/GH_FCxIWEAA09mU.jpg)
![banthisguy9349's tweet photo. #moobot c2
84.54.51.103:6666
87.121.58.103:6666
#mirai
84.54.51.103:32105
87.121.58.103:32105
IOC: nekololis[.]ovh
Hosted on PFcloud[.]io
Abuse reports are not being handled by pfcloud.
hxxps://t.me/nekobotnet https://t.co/K6lYjBY2ek](https://pbs.twimg.com/media/GH_E2NuXgAACyKN.png)
![TLP_R3D's tweet photo. 👀 Scrutinising a few servers for potential #ROMCOM - Caution advised! 🚨
🤔 45.137.155.163 - No flags, 0/88 on VirusTotal
🤔 wirelessvezion[.]com - A blip at 1/89 on VirusTotal
🛠 ISP: STARK INDUSTRIES
🤔 185.250.150.204 - Not flagged, 0/88 on VirusTotal
🤔 netstaticsinformation[.]com - Zero alerts, 0/89 on VirusTotal
🛠 ISP: STARK INDUSTRIES
🕵️ Bonus: IP 185.250.150.204 spotted on Shodan with hostname ergeg[.]fbfb. Which is also an acronym used for the "European Regulators Group for Electricity and Gas" (ERGEG)! 🔍
Stay alert! 🚨 #C2Engine](https://pbs.twimg.com/media/F6yePOOW0AAMNYb.jpg)
![TLP_R3D's tweet photo. 🚨🐍 #APTSidewinder - New C2 discovered
🔹 IP: 193.42.36.66 | Port: 443
🔒 Cert: *.pak-army[.]com
#ThreatIntel #Sidewinder #Pakistan #C2Engine https://t.co/GpPJDpBlo5](https://pbs.twimg.com/media/F7cHRjJWAAAdst6.jpg)