t3ft3lb Profile Banner
t3ft3lb Profile
t3ft3lb

@t3ft3lb

Followers
2K
Following
68
Media
74
Statuses
127

Threat researcher, Malware analyst All tweets represent my personal opinion

Joined March 2013
Don't wanna be here? Send us removal request.
@t3ft3lb
t3ft3lb
3 years
I'm very glad to present my first huge report about #SideWinder #APT written in solo. I hope that this research will bring order to the attribution.
@GroupIB_TI
Group-IB Threat Intelligence
3 years
Group-IB Threat Intelligence team uncovered a previously undocumented spear #phishing campaign carried out by #APT #SideWinder between June and November 2021:. @t3ft3lb
Tweet media one
0
8
23
@t3ft3lb
t3ft3lb
2 months
APT #CloudAtlas FUD #PowerShower. AdobeMon.ps1. powershell -w 01 -Exec Bypass -enc [base64_payload]. URL: hxxps://gimnazija[.]org/dmvc.html/bopyrus40
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
1
7
@t3ft3lb
t3ft3lb
1 year
Related:.Susp #APT #SharpPanda.878-CV-DU.docx.Template URL: hxxp://38.54.31[.]43/WindowsTime/Fishing.png
Tweet media one
Tweet media two
0
4
7
@t3ft3lb
t3ft3lb
1 year
Susp #APT #SharpPanda.out.png (#RoyalRoad RTF). WSWtmf.a (5t Downloader).6dfba2e6ae44c0efc5835e0c5838c5ea.C2: hxxp://38.54.31[.]43/WindowsTime/update.php?Data=<encrypted_data>.Task: WindowsUpdateTaskMachine - rundll32.exe %TEMP%\WSWtmf.a StartW. @nao_sec
Tweet media one
Tweet media two
3
17
44
@t3ft3lb
t3ft3lb
1 year
#APT #CloudAtlas attacks #Belarus.Инженерная записка.doc.URLs:.hxxps://triger-working[.]com/en/about-us/unshelling.hxxps://triger-working[.]com/unshelling/c0.hxxps://web-telegrama[.]org/podcast/accademia-solferino/backtracker
Tweet media one
Tweet media two
Tweet media three
Tweet media four
2
6
21
@t3ft3lb
t3ft3lb
2 years
Susp pro-Ukrainian #APT #StickyWerewolf now attacks #Poland. Wezwanie_swiadka.pdf.exe.d7ff05311350b4990ccd642a44679d1d. MicroWord.exe.542678c60cf6de9e6ca876e102b233e6. hxxps://share-files[.]pl/Wezwanie_swiadka.pdf. #Darktrack #RAT C2: 46.246.97[.]61:7412.Mutex: E4B6tMOXArC4kQ36
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
9
27
@t3ft3lb
t3ft3lb
2 years
RT @nao_sec: Long time no see! #FirePeony (aka #SharpPanda) #RoyalRoad RTF -> 5.t Downloader.
Tweet media one
Tweet media two
0
9
0
@t3ft3lb
t3ft3lb
2 years
#APT #Donot.Fax Copy 20 Dec 23.xls (no decoy, macros).Downloader nikes.exe.hxxps://life.natureplants[.]online/bvgdtye/yuetyt2tw4.hxxps://life.natureplants[.]online/gfvgdteo/loqtyntc2.User-Agent: "Microcrop org"
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
5
21
@t3ft3lb
t3ft3lb
2 years
RT @cyb3rops: Introducing YARA-Forge ⚡️.- Streamlined Public YARA Rule Collection. Excited to share my latest project with the community ju….
0
254
0
@t3ft3lb
t3ft3lb
2 years
RT @rivitna2: #DecoyDog #CLEFIA.Here are my Python scripts for DecoyDog :-).
0
1
0
@t3ft3lb
t3ft3lb
2 years
#APT #Donot.Application to Consulate General.doc.URL: hxxp://speedrugg[.]info/ZKlVWfynYHjd1nm7/aXFwQpdVsYmKbkoWi9y9ZBzIkFE6GHxv0ePSSilV3Ai6F2Ir.(ico|png|mp3|mp4). Jaca sample (PE32+).C2: trigershop[.]info
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
1
13
@t3ft3lb
t3ft3lb
2 years
RT @rivitna2: #Mallox #Mallab #Ransomware #Decryptor.ah6GlfAw$cV7LUHurrQq.
0
7
0
@t3ft3lb
t3ft3lb
2 years
#APT #Donot.Program on Cyber Security Studies (PCSS-25-1).doc.URL: hxxp://harddive[.]info/hM2acgcg15KzzO9d/yErKU1yd97xzKdqmojnG9fMtjhAnu9dBrvXvBJJwbGqvxnxV.(ico|png|mp3|mp4). Jaca sample C2: bulkquantity[.]info
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
8
24
@t3ft3lb
t3ft3lb
2 years
#APT #Donot.Fax Copy.xls.Downloader IxVr.exe.fdc74c66146828985c3f2cc8ef80c0f5.hxxps://records.mindef[.]live/bjhruhukuru/rkuahruhueike.hxxps://records.mindef[.]live/oiporoioqk/lporurkiqjffqe.User-Agent: FireFox 17.13. @DmitriyMelikov
Tweet media one
Tweet media two
Tweet media three
0
8
25
@t3ft3lb
t3ft3lb
2 years
Susp #APT #CloudAtlas.7bdb049cb0cc3623e4fa1d8e2574f1ce.1Table Template URL: hxxps://network-list[.]com?wkbi.html_handfeed
Tweet media one
Tweet media two
Tweet media three
0
3
20
@t3ft3lb
t3ft3lb
2 years
RT @rivitna2: #TgRAT 3.0.078125 (Linux version) dropper.
0
5
0
@t3ft3lb
t3ft3lb
2 years
RT @AzakaSekai_: #VirusTotal just got back to us confirming that #Retrohunt quota is now counted on a per rule basis instead of per job WIT….
0
6
0
@t3ft3lb
t3ft3lb
2 years
#APT #Donot.XLS:..URL: hxxp://thanrole[.]buzz/Ur7AdyiXFB1VNNl8/rHhiHSQwiAkySF9iqJEoCk7SOHz8DHf8zosMprQQOEERSk10.(ico|png|mp3|mp4). Jaca sample:.C2: adjusteble[.]info
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
14
44
@t3ft3lb
t3ft3lb
2 years
#phishing.Be careful when buying theater/exhibition tickets. hxxps://culture-afisha[.]com/1.php.hxxps://culture-afisha[.]com/booking/card.php?id=<id>.hxxps://culture-afisha[.]com/booking/new_wait.php?id=<id>. @Namecheap
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
2
5
@t3ft3lb
t3ft3lb
2 years
#APT #CloudAtlas РЕЗЮМЕ_e48ef291-9b7a-49af-8f12-708d09d9f0a3.1.doc (old sample).1Table Template URL: hxxps://supportpanel.agent-group[.]org/certificates/kainite
Tweet media one
Tweet media two
Tweet media three
1
4
23
@t3ft3lb
t3ft3lb
2 years
#APT #Donot.e.doc.URL: hxxp://mentsele[.]info/XA3JOnMP01TenAuE/442WpoKwPlGlPBMPFMI1q5TzgOKfNQXZhkIKRv9rfAgEQfC6.(ico|png|mp3|mp4). Jaca variant.DLL: mvcfinder32.dll.Export: blstingFindUpl, blstingFindUplP1.C2: gizgashineson[.]buzz (encoded: leasly[.]buzz)
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
6
14