
Sourajeet Majumder
@soursecc
Followers
492
Following
315
Media
79
Statuses
256
21, Security Researcher @cloudsek, All views personal
out of sight
Joined September 2020
Fresh ClickFix IoC : . /clasoftmedia[.]ci./retcap[.]eu./rafelink[.]life./akwatic-hotel[.]ci./bleulab[.]ci./gomezmontero[.]eu./gtl[.]ci./javiergomezmontero[.]eu./ardiellifornasa[.]ge. #IoC #ClickFix | #ThreatHunting #Validin . cc : @500mk500 @MichalKoczwara @skocherhan @1ZRR4H
4
4
27
RT @500mk500: @soursecc @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H On dropthefile[.]xyz from screenshot --> BODY_SHA1-HOST=8c51d0….
0
2
0
ClickFix IoC : . generali-fx[.]com.generali-fx[.]com/cloudfare. #IoCs #ClickFix | #Censys #ThreatHunting . cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H
3
1
10
ClickFix IoC : . hrdepartments[.]org. #IoCs #ClickFix | #Censys #ThreatHunting. cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H
1
11
62
Fresh similar ones :. /meet.google.webconnect58[.]com/ktb-gkc-xha./meet.google.web-connect[.]us./meet.google.webconnect49[.]com/krk-rvc-xwh/./www.meet.google.webconnect88[.]com./meet.google.webconnect11[.]com. #IoCs | #ThreatHunting #Censys. cc : @500mk500 @moonlock_lab
@txhaflaire @SANSInstitute @BleepinComputer Thanks for sharing! Looks like this domain plays a key role in this campaign too: .meet[.]google[.]webconnect49[.]com.We will be taking a closer look as well 👀.
1
0
4
Fresh IoCs for #ClickFix impersonating @bookingcom . - 77.105.164[.]95/s/59ed1342-898f-4455-a521-dc4b737b6aea.- booking.extranethelpid612[.]com.- admin.extra-book3[.]com. #IoCs | #Censys #ThreatHunting . cc : @500mk500 @malwrhunterteam @MichalKoczwara @skocherhan @1ZRR4H
2
12
42
++ ./ns1.www-mlcrosoft[.]com ./ns2.www-mlcrosoft[.]com ./gui.www-mlcrosoft[.]com ./log.www-mlcrosoft[.]com ./csp.www-mlcrosoft[.]com ./login.www-mlcrosoft[.]com ./office.www-mlcrosoft[.]com . cc : @msftsecresponse @msftsecurity @MsftSecIntel.
2
2
6
More of these #ScatteredSpider 🕷️. /146.70.87[.]184./www-mlcrosoft[.]com./account.www-mlcrosoft[.]com./sso.www-mlcrosoft[.]com./ssoo.www-mlcrosoft[.]com. #IoCs | #ThreatHunting #Censys. cc : @500mk500 @malwrhunterteam @MichalKoczwara @skocherhan @1ZRR4H
Possible Scattered Spider Evilginx 🕷️🪝. /23[.]227.202.254./mlcrosofft[.]com./ads[.]mlcrosofft[.]com./sso[.]mlcrosofft[.]com./ssoo[.]mlcrosofft[.]com. Authentication systems impersonated 🥷
2
28
90
Possible Scattered Spider Infra Targeting @iconectiv🕷️ . /18.219.115[.]252 . #IoCs #ScatteredSpider | #ThreatHunting #Censys . cc : @500mk500 @MichalKoczwara @skocherhan @volrant136 @malwrhunterteam
0
0
7
Possible Scattered Spider Infra Targeting @KennedyWilson 🕷️. /18.117.173[.]7./kennedywilsoninc[.]com. #IoCs #ScatteredSpider | #ThreatHunting #Censys. @500mk500 @MichalKoczwara @malwrhunterteam @skocherhan @1ZRR4H
1
7
42
Possible Scattered Spider Infra For @mangopay 🕷️. /188.166.149[.]50./synlace[.]ai./mangopay-okta[.]com./mangopay-atlassian[.]net./alm[.]gg. #ThreatHunting #FOFA | #IoCs #APT . @malwrhunterteam @MichalKoczwara @500mk500 @skocherhan
1
3
9
RT @prajwaldza: Data breach: BWSSB's claims don’t match independent findings. @DeccanHerald @TechCrucio. Read more at: .
0
1
0
RT @prajwaldza: #IMPACT | A day after I exclusively reported the data breach in the BWSSB's application portal for water connection exposin….
0
3
0
RT @prajwaldza: #EXCLUSIVE | A major data breach in the Bangalore Water Supply and Sewerage Board's (BWSSB) application portal for water co….
0
2
0
RT @News9Tweets: Signed up for water, lost your privacy? #Aadhaar, PAN & more of 2.9L #BWSSB users leaked on the dark web. @SudhaSadhanand….
0
1
0
RT @rohanpaul_ai: Exciting yet alarming findings from this bold new Paper. "Jailbreaking Large Language Models with Symbolic Mathematics"….
0
27
0
RT @AlexRobey23: Chatbots like ChatGPT can be jailbroken to output harmful text. But what about robots? Can AI-controlled robots be jailbro….
0
144
0