
StrikeReady Labs
@StrikeReadyLabs
Followers
2K
Following
93
Media
348
Statuses
572
MoD_09-01-2025.chm #apt .e85d1e95fa10fcddd7c1e4a095c41744b5aa3952e31c77b8a6c29b8384426e58.-> d259aaa5d49dc2bd00baf4418343d8665afa7a87ed3a4d06736271d4f3b38d90.-> .158.255.215[.]45:8899/nina/anotherLife
1
9
26
#dailyphish it's 10pm, do you know how your gateway handles ".searchConnector-ms" extensions? ."Mechanism of data sharing with IBD Offices.pdf.searchConnector-ms" -> ebbausersupport[.]com.b6e77578cb4aeaedabc0fa3a465a50a0b18e4c8b9bcffc9d2e24752eab02a1da
1
6
13
NDC65-Updated-Schedule. zip.97e9fc3d3bbbcbdea3b3ea57953db9aad5e6f4f9d7f9d71e9309989ce26a8563.same lnk name (desktop-ey8nc5b).Just hit VT, but looks like perhaps from 2023 based on timestamps and lack of c2 responsiveness .-> modspaceinterior[.]com/wp-content/upgrade/01/.
#SideCopy. JS Army (Strat) .zip.87c0e81c2f0495b2174fdc8a12d9be3d. Army_Strat .lnk --> desktop-ey8nc5b.7460b5ba1628e9be5afe773a247ecb61. 01048 .hta --> inniaromas[.]com.c07f421d3a3ba5e78f55c234ccaaa908. Same C2, decoy, FetaRAT and ActionRAT
0
3
8
People laugh about attribution some times, but in the careers of people in labs here, exactly zero times has this tool ever been used by anyone who wasnt connected to CN sponsored espionage (including moonlighting), with a rare exception of a joker on VT. zero crimeware uses.
0
2
11
#dailyphish #crimeware .5b964166035f3a8509b8e78c49a9c53dadbd788624899dfa9b7709c198f88852 -> fixecondfirbook[.]info
1
2
2
It's kind of strange how long theyve been able to use this api.camera-drive[.]org for hosting these mac and windows payloads --- going on a month+ but at a very high volume for a targeted attacker. @namecheap able to take camera-drive[.]org down?.
2
1
7
found first:
#APT. f4c4f68f8b27279b00b718b02392d5dfe1766c342a189a51e0e2a6f6412e1ce0. 74.50.94[.]175:9992.74.50.94[.]175:7032.hxxps://www.dropbox[.]com/scl/fi/lpgj7eek9jczsx2ey83tk/zzG[.]zip
0
2
3
Back from vacation it appears; campaigns starting back up after a brief respite.2f8e8b2783c8c47da0f265199671f3cae4e31b2a03999fff12aa3090c74c7a51. linkcuts[.]com/5xu034g2 -> doads[.]org -> mocky -> .jkbfgkjdffghh.linkpc[.]net
"info.pdf" #russia #apt #phishing 53142380d75e3f54490f2896b58f308e6b91bec841d09b4e88985cb5b7812031.-> linkcuts[.]com/gumcrr51 -> doads[.]org/gumcrr51 -> run.mocky[.]io/v3/22a2a2d8-84b9-4619-b8ba-359beb386cf9 -> jkbfgkjdffghh.linkpc[.]net
0
2
8
same filename today (오류발견 수정신고 제출 요청 안내(국세징수법 시행규칙).hwp.lnk) but different payload --- and only 1MB this time.a1b67cfb080f4d1e4cbb0019a30259cb291f56c0ada02e2ca1028f675b187727.raleighice[.]com/wp-includes/js/inc/get.php.
LNK inflation is even higher than real inflation!.오류발견 수정신고 제출 요청 안내(국세징수법 시행규칙).hwp.lnk.355MB! .(Guide to requesting submission of error discovery correction report (National Tax Collection Act Enforcement Regulations).hwp.lnk).
0
1
4