
Matthew
@embee_research
Followers
14K
Following
3K
Media
496
Statuses
1K
Security Researcher, Creating and Sharing Educational Content.
Australia
Joined July 2022
A Beginners Guide to Tracking Malware Infrastructure . New post with 11 Examples (Including Cobalt Strike and Qakbot) that you can use to query and track C2’s, Open Directories and More🔥. (Special thanks to @censysio 🥳). #threatintel #malware.
10
292
809
RT @cyb3rops: I’ve noticed that some people misread my posts about AI. So let me try to be as clear and sober as possible:.I’m not saying t….
0
49
0
RT @felixm_pw: With some guidance from @DebugPrivilege I've found a way to easily dump clear text implants even while they sleep. Bad day f….
0
102
0
RT @thezedwards: Our team at Silent Push has been hard at work on the largest report we’ve ever made public – and along with Reuters – toda….
0
42
0
RT @silentpush: Did you know that registration emails can be used to hunt for #malware infra?. If an actor uses a unique email when registe….
0
16
0
RT @silentpush: We're seeing lots of similar #phishing domains to those reported by @_JohnHammond 🚨. The actors are using consistent naming….
0
6
0
RT @silentpush: Quick Tip for Hunting #LegionLoader Domains With #WHOIS Records🏹. LegionLoader actors have recently been creating #C2 domai….
0
14
0
RT @silentpush: Hunting Tip - Tracking #ValleyRAT Delivery Domains via ICP License Codes🔥. ValleyRAT has recently been reported using fake….
0
10
0
RT @silentpush: Quick Tip for Hunting #Lumma Domains By Checking WHOIS Records 🏹 . Lumma actors often create #C2 domains in (likely automat….
0
27
0
RT @vxunderground: Hi, I've seen a lot of noobies lately discussing their productivity. They're comparing their work ethic or research skil….
0
39
0
Nice and Simple Scattered Spider Pivots - Thanks to Initial Intel and previous posts from @TLP_R3D . 1⃣ Regex Pattern And Server Header .2⃣ Regex, Server Header and ASN .3⃣ Regex, Dates, ASN and Name Server . Utilising Domain Search and Web Scanner from @silentpush
🔥After a Long Break - New #ScatteredSpider . Domain: revolut-okta[.]com.IP Address: 80.78.27.6.AS Owner: ABSTRACT, FI
0
24
109