WatchingRac Profile
WatchingRac

@RacWatchin8872

Followers
2K
Following
1K
Media
294
Statuses
799

Threat Intelligence. My Opinions Thanks @silentpush, @censysio, @ValidinLLC, @anyrun_app for making my research easier.

Joined May 2023
Don't wanna be here? Send us removal request.
@RacWatchin8872
WatchingRac
12 days
#Lumma #Malware ๐Ÿ‘พ12 New Lumma Domains with 0 Hits๐Ÿ‘พ Lumma was the first malware C2 I hunted After its decline I moved to Tycoon Phishing, but why not trying Lumma Again ๐Ÿšจ https://t.co/cxRGtBp4SI๐Ÿšจ Thanks for helping me @g0njxa
2
13
34
@RacWatchin8872
WatchingRac
13 days
#Tycoon2FA #Phishing ๐ŸšจAlmost 10K๐Ÿšจ https://t.co/YTVnXcDv47
2
0
2
@RacWatchin8872
WatchingRac
20 days
#Tycoon2FA - Anti-bot system got a few new features - New TLD's being used: .email (@nullwhire95 thanks for the info!!) CC: @banthisguy9349 @NDA0E @BlinkzSec @kddx0178318 @raghav127001 @DaveLikesMalwre @g0njxa @ViriBack @500mk500 @ge0lev @marsomx_ @JAMESWT_MHT @DonPasci
@NoMorePhis
NoPhishInHere
20 days
0
3
8
@orlof_v
V
1 month
Mapping Lumma's infrastructure ๐Ÿงต Key pivots: โ„น๏ธCert fingerprints connecting distribution โ†’ C2 โ„น๏ธASN clustering (Aeza, Routerhosting, Proton66) โ„น๏ธDomain patterns (.qpon, .top, .xyz, .ru) ๐Ÿ‘‰ https://t.co/Pjrwk1bKT7
1
4
11
@RacWatchin8872
WatchingRac
2 months
#Tycoon2FA #Phishing One more TLD: - .ru.com (If you know more TLD's that are not listed in the github, please DM me) CC: @banthisguy9349 @NDA0E @BlinkzSec @kddx0178318 @raghav127001 @DaveLikesMalwre @g0njxa @ViriBack @500mk500 @ge0lev @marsomx_ @JAMESWT_MHT @DonPasci
@NoMorePhis
NoPhishInHere
2 months
#Tycoon2FA #Phishing ๐ŸŸTo Many Domains Founded, Bot doesn't know the number Full List: https://t.co/OR4WQvOHAJ Tool used: @ValidinLLC CC: @RacWatchin8872 @g0njxa @500mk500
0
2
7
@RacWatchin8872
WatchingRac
2 months
#Tycoon2FA #Phishing - Using new TLD ([.]co[.]za) - New Anti-Bot System (never saw something like that) CC: @banthisguy9349 @NDA0E @BlinkzSec @kddx0178318 @raghav127001 @DaveLikesMalwre @g0njxa @ViriBack @500mk500 @ge0lev @marsomx_ @JAMESWT_MHT @DonPasci
@NoMorePhis
NoPhishInHere
2 months
#Tycoon2FA #Phishing ๐ŸŸ135 Domains related to Tycoon2FA Phishing with Low Hits on vt: https://t.co/Rp0jXZi1KW Full List: https://t.co/OR4WQvO9Lb Tool used: @ValidinLLC CC: @RacWatchin8872 @g0njxa @500mk500
2
6
26