Top Tweets for #NotepadPlusPlusCompromise
More reports regarding the Notepad++ compromise
@Securelist
https://t.co/3s5G3asUkP
@kucher1n
https://t.co/7ZZpQ7pY2J
@ValidinLLC
https://t.co/EYEEOoXUbK
#NotepadPlusPlusCompromise
Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs
- update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe
- file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll
- network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114
by @rapid7
https://t.co/rrespJ9Ju0
![cyb3rops's tweet photo. Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs
- update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe
- file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll
- network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114
by @rapid7
https://t.co/rrespJ9Ju0](https://pbs.twimg.com/media/HAKoUZzXMAQFKph.jpg)
The #NotepadPlusPlusCompromise @rapid7 report included network indicators. 💪 We uncover additional related infrastructure to look out for including a possible additional initial access IP, C2 IPs, and C2 domain names.
Follow our analysis + indicators:
https://t.co/qu5yb4pxyK
Oh man, check this out
https://t.co/wEEs2tMbZh
#NotepadPlusPlusCompromise

This is bad.
Putty level bad.
https://t.co/3w1C8YiBu8

Yes, it's basically this
#NotepadPlusPlusCompromise

This is bad.
Putty level bad.
https://t.co/3w1C8YiBu8

Last Seen Hashtags on Sotwe
เย็ดคนท้อง
Seen from Thailand
トリーケリー
Seen from Japan
ankaraescort
Seen from Turkey
kuinasazanami
Seen from United Kingdom
gayfart
Seen from Italy
nolimit() +filter:native_video
Seen from Netherlands
furryshoulders
Seen from United States
dandysworldnsfw
Seen from Vietnam
ديوت_بدوي
Seen from Kuwait
협박플
Seen from United States
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109.2M followers

Narendra Modi 
@narendramodi
106.9M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
87M followers

Taylor Swift 
@taylorswift13
80.8M followers

Lady Gaga 
@ladygaga
72.3M followers

Kim Kardashian 
@kimkardashian
69.5M followers

Virat Kohli 
@imvkohli
68.8M followers

YouTube 
@youtube
68.6M followers

Bill Gates 
@billgates
63.5M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.4M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60.1M followers

![cyb3rops's tweet photo. Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs
- update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe
- file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll
- network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114
by @rapid7
https://t.co/rrespJ9Ju0](https://pbs.twimg.com/media/HAKoUZyWsAAUNoZ.jpg)
![cyb3rops's tweet photo. Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs
- update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe
- file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll
- network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114
by @rapid7
https://t.co/rrespJ9Ju0](https://pbs.twimg.com/media/HAKoUZwXMAIGkD3.jpg)

