DonPasci Profile
DonPasci

@DonPasci

Followers
260
Following
3K
Media
503
Statuses
832

Joined August 2021
Don't wanna be here? Send us removal request.
@DonPasci
DonPasci
1 month
1
0
0
@DonPasci
DonPasci
5 months
2
0
0
@TheDFIRReport
The DFIR Report
7 months
🌟New report out today!🌟 Navigating Through The Fog Analysis and reporting completed by @angelo_violetti, and reviewed by @svch0st. Audio: Available on Spotify, Apple, YouTube and more! https://t.co/aN5xFoYATD
Tweet card summary image
thedfirreport.com
Key Takeaways An open directory associated with a ransomware affiliate, likely linked to the Fog ransomware group, was discovered in December 2024. It contained tools and scripts for reconnaissance…
0
34
76
@DonPasci
DonPasci
1 year
Hi @Namecheap Can you check these domains (linked to Lumma Stealer) and registered at Namecheap: deepymouthi[.]sbs consumeroo[.]sbs ferrycheatyk[.]sbs captaitwik[.]sbs snailyeductyi[.]sbs monstourtu[.]sbs
2
0
1
@CuratedIntel
Curated Intelligence
1 year
⚠️PSA: Curated Intel DFIR has noticed a new trend among Akira Ransomware cases in Summer 2024. For a while, Akira has been exploiting Cisco ASA devices. ➡️ They are now targeting SonicWall SSL-VPNs for access with no MFA (!) and weak passwords (!). Other TTPs remain the same 🔍
0
26
51
@DonPasci
DonPasci
1 year
New #darkgate domain (eventgrids[.]online): https://t.co/yelOWFGhqt Sample: https://t.co/q7kWO4e2Ay @Namecheap can this domain be taken down?
2
0
6
@Abjuri5t
John F - abjuri5t.bsky.social
1 year
Finally published #ChartingTheIOCs - a blog post to: - help #SysAdmins defend their networks 🛡️ - explain how @SarlackLab’s mapping works - … and share my wisdom (rant) on hunting #C2 servers https://t.co/TApCzb5kge Let us know what your thoughts are! #OneTeamOneFight
Tweet card summary image
medium.com
A meta-analysis of C2 locations and tools to help you find your bearings
2
24
64
@DonPasci
DonPasci
2 years
@500mk500 @banthisguy9349 @malwrhunterteam Also getting files from 103.192.209[.]60:7474/ (like source.rar)
0
0
1
@DonPasci
DonPasci
2 years
Found an executable on http://103.192.209.60[:]8888/ C2 seems to be: cdc.ogagp[.]top:6688 and 103.192.209[.]60:7575 Virustotal is labeling it flystudio. https://t.co/wFyRTrqHmz Anyone know more about this malware? cc: @500mk500 @banthisguy9349 @malwrhunterteam
2
4
9
@DonPasci
DonPasci
2 years
New #darkgate domain (mylittlecabbage[.]net): https://t.co/qmoqQXGPms Sample: https://t.co/erMuWihtLa @Namecheap can this domain be taken down?
2
0
0
@DonPasci
DonPasci
2 years
@Namecheap @Namecheap Can you look at this?
1
0
0
@DonPasci
DonPasci
2 years
New #darkgate domain (flexiblemaria[.]com): https://t.co/YQHJ7AlUx9 Sample: https://t.co/xTtomqxdrF @Namecheap can this domain be taken down?
1
0
1
@DonPasci
DonPasci
2 years
@Namecheap Thanks in advance! More can be found here: https://t.co/SDWQO95p5k
0
0
0
@DonPasci
DonPasci
2 years
@Namecheap @Namecheap More of these from the same source: wt-api[.]top webstaticcdn[.]com counter247[.]live js-min[.]site abc-cdn[.]online 24supportkit[.]com jsdevlvr[.]info opttracker[.]online schema-forms[.]org 365analytics[.]xyz js-assets[.]cloud watchasync[.]com localadswidget[.]com
1
0
1
@DonPasci
DonPasci
2 years
In campaign https://t.co/ZirfbNuQVf there is a domain streaming.jsonmediapacks[.]com which @Namecheap is registar of that domain. Can it be taken down? See also:
2
0
0
@DonPasci
DonPasci
2 years
1
0
6