Euler Neto Profile
Euler Neto

@netonightmare

Followers
211
Following
1K
Media
56
Statuses
524

Just one propagandist of time; DFIR/Malware/OSINT, Death Metal, Beer, Horror Movies, Sports, Retro-gaming; My opinions, my own.

Aracaju, Brasil
Joined July 2009
Don't wanna be here? Send us removal request.
@netonightmare
Euler Neto
4 months
The US isolation is including stopping sharing cyber #threatintel.
0
0
1
@netonightmare
Euler Neto
4 months
RT @g0ttfrid: [ CajuSec2025 ]. Ingressos: CFP: CFS: DM
Tweet media one
0
3
0
@netonightmare
Euler Neto
4 months
RT @ACEResponder: How Stuxnet worked. #ThreatHunting #DFIR
0
101
0
@netonightmare
Euler Neto
5 months
RT @leanpub: Accelerated Linux Disassembly, Reconstruction and Reversing, Second Edition by Dmitry Vostokov is on sale on Leanpub! Its sugg….
0
2
0
@netonightmare
Euler Neto
6 months
RT @VideoGameHstry: DOOM is now playable in a PDF file
0
540
0
@netonightmare
Euler Neto
6 months
RT @g0ttfrid: CFP aberto pro CajuSEC 2025.
0
2
0
@netonightmare
Euler Neto
6 months
The first versions of Coyote #malware use a combination of Base64 and AES encryption, now, the new versions are using Base64 encoded twice.
Tweet media one
0
0
1
@netonightmare
Euler Neto
6 months
Some #Phishing websites try to steal your credentials with fake login pages which show the logo of the domain passed in the parameter. One example is hxxps://secure[.]adnxs[.]com/clktrb?id=<id_number>&redir=hxxps://kmgsuwasewa[.]lk/khfe/jbfv?.email=<user>@<domain>
Tweet media one
0
0
1
@netonightmare
Euler Neto
6 months
RT @OSINTDojo: Shout out to @netonightmare for earning their new #OSINT Shogun badge! First one awarded in the new year. 🎉.
0
1
0
@netonightmare
Euler Neto
6 months
RT @patrickwardle: Interested in all the new macOS malware of 2024!? 🍎🐛. I've started my annual "The Mac Malware of <Insert Year>" report.….
0
95
0
@netonightmare
Euler Neto
7 months
I wrote a blog post about the basics of ROP chain. #ReverseEngineering #ExploitDevelopment #ROPChain.
0
0
0
@netonightmare
Euler Neto
7 months
Google promoting fake Correios websites in Gmail. #GoogleAds #Phishing
Tweet media one
Tweet media two
Tweet media three
0
0
2
@netonightmare
Euler Neto
7 months
Couldn't get a photo with focus with the moment that the pacemaker was controlled remotely.
Tweet media one
0
0
0
@netonightmare
Euler Neto
7 months
I've been analyzing the code of the pacemaker hacked in the Homeland series but, so far, didn't find any information if it's a valid code.
Tweet media one
1
0
1
@netonightmare
Euler Neto
9 months
e-notas[.]com/dsdrk/inspecionando[.]php.e-notas[.]com/zizaobrita/inspecionando[.]php.ebaoffice[.]com[.]br/cito/inspecionando[.]php.ebaoffice[.]com[.]br/imagens/bo/inspecionando[.]php.rodovalhoadvogados[.]com[.]br/657890/inspecionando[.]php.
0
0
1
@netonightmare
Euler Neto
9 months
109[.]110[.]184[.]252/ar/inspecionando[.]php.109[.]110[.]184[.]31/exercito/inspecionando[.]php.142[.]171[.]135[.]63/matrix/7/inspecionando[.]php.142[.]171[.]227[.]163/matrix/inspecionando[.]php.164[.]92[.]92[.]132/dan/inspecionando[.]php.35[.]172[.]214[.]51/inspecionando[.]php.
1
0
1
@netonightmare
Euler Neto
9 months
Newly observed URLs associated to CHAVECLOAK 🇧🇷.This brazilian banking trojan uses DLL-Side loading and communicates with URLs ending in inspecionando[.]php.#Malware #Trojan #C2. URLs below in the comments. 👇.
1
1
12
@netonightmare
Euler Neto
9 months
It downloads a LNK file with the description "This shortcut is part of a controlled security simulation conducted by the Red Team.". Same file seen here: @malwrhunterteam @1ZRR4H
Tweet media one
@malwrhunterteam
MalwareHunterTeam
10 months
@1ZRR4H "This shortcut is part of a controlled security simulation conducted by the Red Team. It is designed to test detection and response capabilities of our Blue Team defenses.".Real or actors playing?.🤔
Tweet media one
0
0
2
@netonightmare
Euler Neto
9 months
E-mail addresses in the format <name>.<surname>@[a-z0-9]{5}.domain.URLs in the format hxxps://<IP>.host.secureserver.net/[a-z0-9]{10}/[a-z0-9]{7}_<email>/curriculo_OUTUBRO_2024_[a-z0-9]{15}_curriculo_<day>10(_<num>){0,1}.
0
0
0
@netonightmare
Euler Neto
9 months
#Phishing October campaign related to a fake CV, targeting brazilian users. 🇧🇷.E-mail addresses and URL formats in the comment below.
Tweet media one
2
0
2