@JAMESWT_MHT Profile picture

JAMESWT

@JAMESWT_MHT

#Independent #Malware #Hunter #CyberSecurity #InfoSec https://t.co/KCFBJcHHcW

Similar User
MalwareHunterTeam photo

@malwrhunterteam

James photo

@James_inthe_box

ExecuteMalware photo

@executemalware

Karsten Hahn photo

@struppigel

Arkbird photo

@Arkbird_SOLG

proxylife photo

@pr0xylife

abuse.ch photo

@abuse_ch

Cryptolaemus photo

@Cryptolaemus1

blackorbird photo

@blackorbird

Dee photo

@ViriBack

reecDeep photo

@reecdeep

Shadow Chaser Group photo

@ShadowChasing1

hasherezade photo

@hasherezade

ANY.RUN photo

@anyrun_app

Myrtus photo

@Myrtus0x0

Pinned

Inaugurato un nuovo TAG "SPAM-ITA" in @abuse_ch per tracciare i samples con target Italiano ricevuti tramite Emails Malevole di Spam 💯bazaar.abuse.ch/browse/tag/Spa…💯 Ultimi 2 mesi, i samples più vecchi rimangono con i tags specifici tipo bazaar.abuse.ch/browse/tag/age… ecc

Tweet Image 1

The ScreenConnect installer it gave: 4db7803a3142fb22ba63631612943f91459eceb4e1ded7b88808f9cec74f87b0

Tweet Image 1


ZIP>SVG>URL>ZIP>PW LOP852>#AsyncRat ⛔️C2 powerupsnew.]dynuddns].com Drop ⛔️https://i0004.clarodrive.]com/s/siEsdDALjZ665wE/ Samples ❇️bazaar.abuse.ch/browse/tag/pow… AnyRun 🔱app.any.run/tasks/77b108db…

Tweet Image 1
Tweet Image 2
Tweet Image 3

"DEMANDA NOTIFICACION FRAUDE FISCAL\.zip": 3ad130b7dfd420c304d97e267e1b9bce6ace72edb9cb1749700902b885817c88 -> "DEMANDA NOTIFICACION FRAUDE FISCAL.svg": 01ad5238f803563f1635fdadfef47f97c0c2c8e0c90111b625a248d44f9017f9 @1ZRR4H

Tweet Image 1


JAMESWT Reposted

Via, @ransomfeednews 🆕 #Everest: 121° attacco #Ransomware del 2024 (2° nel mese di Novembre) ad un target 🇮🇹 Bio-Clima Service S.R.L. | bioclimaservice.it Italy (Bernareggio - Monza Brianza) 🔗 ransomfeed.it/index.php?page… #Ransomfeed è anche su #Telegram: 🔗…

Tweet Image 1

JAMESWT Reposted

🚨 #AGCOM vuole fermare lo #spoofing: proposta una misura per bloccare le chiamate internazionali che si spacciano per numeri italiani. 🔒 Un passo concreto per proteggere i cittadini dalle frodi, a differenza del costoso (e inefficace) #PiracyShield 🏴‍☠️ dday.it/redazione/5111…


JAMESWT Reposted

🔴#Phishing @Agenzia_Entrate Rimborso fiscale - IT1X112024609163652609163652 📧🎯🇮🇹 💶1073,88 € 🔗https: //auth-serveronline-serv1.de/7aIT03j82stf28&sp_aqd=d2lkZ2V0TmFtjhghjHGyuUygHjuyTtyYtFGbXJhaQ&th=2/ #ASN @CloudflareHelp

Tweet Image 1
Tweet Image 2

"Invio Ordine Fornitore Nr. 2024.1797" spam email spread #SnakeKeylogger Samples bazaar.abuse.ch/browse/tag/Spa… AnyRun app.any.run/tasks/102c286f… Drop https://filetransfer[.io/data-package/7pdXjNKP/download

Tweet Image 1
Tweet Image 2

JAMESWT Reposted

2024-11-14 (Thursday): #RaspberryRobin infection chain uses WebDAV share, today at 2z[.]si@ssl\u\. Victim downloads a zip archive, then extracts and double-clicks an HTA file, which loads and runs a Raspberry Robin DLL from the WebDAV share. Details at bit.ly/3O9XMwA

Tweet Image 1
Tweet Image 2
Tweet Image 3
Tweet Image 4

JAMESWT Reposted

Pivoting on this information, I generated a #RaspberryRobin infection using the #WebDAV server. I posted a #pcap with some fresh malware samples at malware-traffic-analysis.net/2024/11/14/ind…

Tweet Image 1
Tweet Image 2
Tweet Image 3
Tweet Image 4

JAMESWT Reposted
Tweet Image 1

#phishing 🇮🇹 register full identify theft: 1⃣ user:pass 2⃣ cc 3⃣ id documents (!) abusing @Shufti_Pro IoC: 16f9032b.claritascosmeticos,com,br[/xhr,/collecte,/pg1].php->shufti id @illegalFawn @JAMESWT_MHT @phishunt_io @PhishKitTracker @ActorExpose

Tweet Image 1
Tweet Image 2
Tweet Image 3


JAMESWT Reposted

#RaaS #ransomware 🫢🤦‍♂️ Install in your @kalilinux and... "Ransomware Flexibility" ~ Current Directory Encryption ~ Entire User Files Encryption ~ Persistent Infection With Annoying PopUp Banner ~ Persistent Hidden Ransomware (Continuos Encryption). github.com/M4xSec/curse2d…


JAMESWT Reposted

#phishing 🇮🇹 register full identify theft: 1⃣ user:pass 2⃣ cc 3⃣ id documents (!) abusing @Shufti_Pro IoC: 16f9032b.claritascosmeticos,com,br[/xhr,/collecte,/pg1].php->shufti id @illegalFawn @JAMESWT_MHT @phishunt_io @PhishKitTracker @ActorExpose

Tweet Image 1
Tweet Image 2
Tweet Image 3

JAMESWT Reposted

Ha! Elon is already abusing its government position. You need Twitter Premium to send a CV for DOGE. Nice.

Tweet Image 1
Tweet Image 2

JAMESWT Reposted

Upcoming new feature for the teletoken.info advanced_info page:

Tweet Image 1
Tweet Image 2

JAMESWT Reposted

distro https://azuredcloud.]world/ https://memorun.]life/medk.php c2's - BRC4 https://burjog.]com:9043/matrix.php https://samomol.]com:9043/pankihoy.php Latro: https://rolefenik.]com https://ergiholim.]com https://bestmarsgood.]com https://cerwintifed.]com (2/3) 👇


Loading...

Something went wrong.


Something went wrong.