02/28

Rogue RDP – Revisiting Initial Access Methods - Black Hills Information Security

https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
Rogue RDP – Revisiting Initial Access Methods - Black Hills Information Security

Daxin: Stealthy Backdoor Designed for Attacks Against Hardened Networks | Broadcom Software Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/daxin-backdoor-espionage
Daxin: Stealthy Backdoor Designed for Attacks Against Hardened Networks | Broadcom Software Blogs

vx-underground - Directory

https://share.vx-underground.org/Conti/
vx-underground - Directory

disBalancer crowdsourcing cyber warfare (loic hive mind) - The Cyber Shafarat - Treadstone 71

https://cybershafarat.com/2022/02/27/disbalancer-crowdsourcing-cyber-warfare-loic-hive-mind/
disBalancer crowdsourcing cyber warfare (loic hive mind) - The Cyber Shafarat - Treadstone 71

Tweet / Twitter

https://twitter.com/JoshuaPotash/status/1498332884121399307
Tweet / Twitter

Conti ransomware gang chats leaked by pro-Ukraine member - The Record by Recorded Future

https://therecord.media/conti-ransomware-gang-chats-leaked-by-pro-ukraine-member/
Conti ransomware gang chats leaked by pro-Ukraine member - The Record by Recorded Future

404 - Not Found! - AnonFiles

https://anonfiles.com/VeP6K6K5xc/1_tgz
404 - Not Found! - AnonFiles

Russian Electric Vehicle Chargers Hacked, Tell Users ‘PUTIN IS A DICKHEAD’

https://www.vice.com/en/article/akvya5/russian-electric-vehicle-chargers-hacked-tell-users-putin-is-a-dickhead
Russian Electric Vehicle Chargers Hacked, Tell Users ‘PUTIN IS A DICKHEAD’

Conti ransomware's internal chats leaked after siding with Russia

https://www.bleepingcomputer.com/news/security/conti-ransomwares-internal-chats-leaked-after-siding-with-russia/
Conti ransomware's internal chats leaked after siding with Russia

Experts Create Apple AirTag Clone That Can Bypass Anti-Tracking Measures

https://thehackernews.com/2022/02/experts-create-apple-airtag-clone-that.html
Experts Create Apple AirTag Clone That Can Bypass Anti-Tracking Measures

Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits – Sophos News

https://news.sophos.com/en-us/2022/02/28/conti-and-karma-actors-attack-healthcare-provider-at-same-time-through-proxyshell-exploits/
Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits – Sophos News

Screenshot from 2021-12-15 21-26-28.png - AnonFiles

https://anonfiles.com/f1VfcbLdxe/Screenshot_from_2021-12-15_21-26-28_png
Screenshot from 2021-12-15 21-26-28.png - AnonFiles

BrokenPrint: A Netgear stack overflow – NCC Group Research

https://research.nccgroup.com/2022/02/28/brokenprint-a-netgear-stack-overflow/
BrokenPrint: A Netgear stack overflow – NCC Group Research

Orion/RAN_ALPHV_Feb_2022_1.yara at main · StrangerealIntel/Orion · GitHub

https://github.com/StrangerealIntel/Orion/blob/main/Ransomware/RAN_ALPHV_Feb_2022_1.yara
Orion/RAN_ALPHV_Feb_2022_1.yara at main · StrangerealIntel/Orion · GitHub

conti leaks on Twitter: "conti jabber leaks https://t.co/0FzXiXhI2d" / Twitter

https://twitter.com/ContiLeaks/status/1498030708736073734
conti leaks on Twitter: "conti jabber leaks https://t.co/0FzXiXhI2d" / Twitter

storage-master-3607d1f6a72e28efe84b55e8a660ff97db0e79a2.zip - AnonFiles

https://anonfiles.com/ndh8deL5xd/storage-master-3607d1f6a72e28efe84b55e8a660ff97db0e79a2_zip
storage-master-3607d1f6a72e28efe84b55e8a660ff97db0e79a2.zip - AnonFiles

185.25.51.173-20220228.json - AnonFiles

https://anonfiles.com/X0vcd8L7x8/185.25.51.173-20220228_json
185.25.51.173-20220228.json - AnonFiles

Ransomwhere

http://ransomwhe.re
Ransomwhere

‘Exploiting Cadavers ’and ‘Faked IEDs’: Experts Debunk Staged Pre-War ‘Provocation’ in the Donbas - bellingcat

https://www.bellingcat.com/news/2022/02/28/exploiting-cadavers-and-faked-ieds-experts-debunk-staged-pre-war-provocation-in-the-donbas/
‘Exploiting Cadavers ’and ‘Faked IEDs’: Experts Debunk Staged Pre-War ‘Provocation’ in the Donbas - bellingcat

Toyota suspends domestic factory operations after suspected cyber attack | Reuters

https://www.reuters.com/business/autos-transportation/toyota-suspends-all-domestic-factory-operations-after-suspected-cyber-attack-2022-02-28/
Toyota suspends domestic factory operations after suspected cyber attack | Reuters

spoked-master-cf530950c30b81188d40c56b9a66e7d3bb21710c.zip - AnonFiles

https://anonfiles.com/dch1dfL6x4/spoked-master-cf530950c30b81188d40c56b9a66e7d3bb21710c_zip
spoked-master-cf530950c30b81188d40c56b9a66e7d3bb21710c.zip - AnonFiles

Insurance giant AON hit by a cyberattack over the weekend

https://www.bleepingcomputer.com/news/security/insurance-giant-aon-hit-by-a-cyberattack-over-the-weekend/
Insurance giant AON hit by a cyberattack over the weekend

| Job Preference

http://www.jobpreference.com
| Job Preference

Toyota halts production after reported cyberattack on supplier

https://www.bleepingcomputer.com/news/security/toyota-halts-production-after-reported-cyberattack-on-supplier/
Toyota halts production after reported cyberattack on supplier

Sources: Belarus to join Russia’s war on Ukraine within hours

https://kyivindependent.com/national/sources-belarus-to-join-russias-war-on-ukraine-within-hours/
Sources: Belarus to join Russia’s war on Ukraine within hours

Joe's Transition - Cobalt Strike Research and Development

https://www.cobaltstrike.com/blog/joes-transition/
Joe's Transition - Cobalt Strike Research and Development

Humble Book Bundle: The Joy of Coding by No Starch Press

https://www.humblebundle.com/books/joy-coding-no-starch-press-books
Humble Book Bundle: The Joy of Coding by No Starch Press

YaraDBG v0.0.2

http://yaradbg.dev
YaraDBG v0.0.2

Ready, Set, Go — Golang Internals and Symbol Recovery | Mandiant

https://www.mandiant.com/resources/golang-internals-symbol-recovery
Ready, Set, Go — Golang Internals and Symbol Recovery | Mandiant

Intelligence X

https://intelx.io/?did=64ea2187-8ae9-4053-ba46-06413b809713
Intelligence X

2.tgz - AnonFiles

https://anonfiles.com/H8B7b1L4x6/2_tgz
2.tgz - AnonFiles

AsyncRAT/AsyncRAT_28.02.2022.txt at main · pr0xylife/AsyncRAT · GitHub

https://github.com/pr0xylife/AsyncRAT/blob/main/AsyncRAT_28.02.2022.txt
AsyncRAT/AsyncRAT_28.02.2022.txt at main · pr0xylife/AsyncRAT · GitHub