
t3ft3lb
@t3ft3lb
Followers
2K
Following
68
Media
74
Statuses
127
Threat researcher, Malware analyst All tweets represent my personal opinion
Joined March 2013
I'm very glad to present my first huge report about #SideWinder #APT written in solo. I hope that this research will bring order to the attribution.
Group-IB Threat Intelligence team uncovered a previously undocumented spear #phishing campaign carried out by #APT #SideWinder between June and November 2021:. @t3ft3lb
0
8
23
APT #CloudAtlas FUD #PowerShower. AdobeMon.ps1. powershell -w 01 -Exec Bypass -enc [base64_payload]. URL: hxxps://gimnazija[.]org/dmvc.html/bopyrus40
1
1
7
Related:.Susp #APT #SharpPanda.878-CV-DU.docx.Template URL: hxxp://38.54.31[.]43/WindowsTime/Fishing.png
0
4
7
Susp #APT #SharpPanda.out.png (#RoyalRoad RTF). WSWtmf.a (5t Downloader).6dfba2e6ae44c0efc5835e0c5838c5ea.C2: hxxp://38.54.31[.]43/WindowsTime/update.php?Data=<encrypted_data>.Task: WindowsUpdateTaskMachine - rundll32.exe %TEMP%\WSWtmf.a StartW. @nao_sec
3
17
44
#APT #CloudAtlas attacks #Belarus.Инженерная записка.doc.URLs:.hxxps://triger-working[.]com/en/about-us/unshelling.hxxps://triger-working[.]com/unshelling/c0.hxxps://web-telegrama[.]org/podcast/accademia-solferino/backtracker
2
6
21
Susp pro-Ukrainian #APT #StickyWerewolf now attacks #Poland. Wezwanie_swiadka.pdf.exe.d7ff05311350b4990ccd642a44679d1d. MicroWord.exe.542678c60cf6de9e6ca876e102b233e6. hxxps://share-files[.]pl/Wezwanie_swiadka.pdf. #Darktrack #RAT C2: 46.246.97[.]61:7412.Mutex: E4B6tMOXArC4kQ36
0
9
27
#APT #Donot.Fax Copy.xls.Downloader IxVr.exe.fdc74c66146828985c3f2cc8ef80c0f5.hxxps://records.mindef[.]live/bjhruhukuru/rkuahruhueike.hxxps://records.mindef[.]live/oiporoioqk/lporurkiqjffqe.User-Agent: FireFox 17.13. @DmitriyMelikov
0
8
25
Susp #APT #CloudAtlas.7bdb049cb0cc3623e4fa1d8e2574f1ce.1Table Template URL: hxxps://network-list[.]com?wkbi.html_handfeed
0
3
20
RT @AzakaSekai_: #VirusTotal just got back to us confirming that #Retrohunt quota is now counted on a per rule basis instead of per job WIT….
0
6
0
#phishing.Be careful when buying theater/exhibition tickets. hxxps://culture-afisha[.]com/1.php.hxxps://culture-afisha[.]com/booking/card.php?id=<id>.hxxps://culture-afisha[.]com/booking/new_wait.php?id=<id>. @Namecheap
1
2
5
#APT #CloudAtlas РЕЗЮМЕ_e48ef291-9b7a-49af-8f12-708d09d9f0a3.1.doc (old sample).1Table Template URL: hxxps://supportpanel.agent-group[.]org/certificates/kainite
1
4
23