Posted by: milos_rs
02-08-2024, 08:01 PM
Forum: Phishing / Scam / Spam kampanje
- No Replies

sa reddita, navodno javljaju se prodavcima preko vibera i pokušavaju ovako da kupe, tražeći da se na lažnoj stranici pošte unesu podaci kartice, prilično standardan phishing samo što je trenutno baš aktivna kampanja, video sam i drugde da se žale.

   

   

   

   

   

   

Ne uspevam da uđem na sajt ni sa desktopa ni sa mobilnog, samo redirektuje na posta.rs, verovatno gase link kad se ne koristi, tj. istekne "tracking broj"

Code:
posta-rs.eorder23425.com has address 172.67.196.134 posta-rs.eorder23425.com has address 104.21.21.58 Domain Name: eorder23425.com Registry Domain ID: 2835543194_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.godaddy.com Registrar URL: https://www.godaddy.com Updated Date: 2023-12-06T05:23:23Z Creation Date: 2023-12-06T05:23:23Z



Posted by: 1van
02-08-2024, 01:10 PM
Forum: Vesti, zanimljivosti i razno
- No Replies

Quote:This report calculates a repairability score for the most popular cell phone and laptop brands, and grades which manufacturers are designing devices to last and which are “Failing the Fix.”

Report: https://cdn.arstechnica.net/wp-content/u...ng-Fix.pdf



Posted by: Aleksandar.Ristić
02-08-2024, 11:55 AM
Forum: Vesti, zanimljivosti i razno
- Replies (5)

PoC||GTFO 0x22 je izašao: https://www.alchemistowl.org/pocorgtfo/ (mirror: https://pocorgtfo.hacke.rs/)

Quote:PoC||GTFO 0x22, February 2024, Through desert & wilderness, Laphroaig reaches great heights from the deepest of depths.

Sadržaj: https://twitter.com/travisgoodspeed/stat...8340277707



Posted by: maxxa
02-08-2024, 12:37 AM
Forum: Phishing / Scam / Spam kampanje
- Replies (1)

Neko na šaljiv način žicka soma dindži sa lažnog IG profila Cece R @cecaraznatoviicofficial

   


Izvor: https://twitter.com/HeyoAleks/status/175...9364194462



Posted by: VincaSec
02-07-2024, 09:47 PM
Forum: OSINT
- No Replies

Quote:A stealer log is a collection of data assembled from a victim’s device.  These logs are generated by malicious software on the target device (typically running a Windows OS).  Once the victim is infected, the malware then proceeds to gather personal and sensitive data to exfiltrate this back to a server being controlled by the threat actor.

There are multiple varieties of stealer logs.  We observe the most common to be Racoon, Redline, Titan, and Vidar, but many others can and do exist.  While many strains of virus have been developed and utilised, their overall function remains consistent and the data they collect is similar across all variants.  We discuss a typical log below:
https://sosintel.co.uk/stealer-logs-what...d-to-know/

   
Fig. 1. – An example file tree of a typical stealer log

Quote:Naming conventions for individual logs vary from stealer to stealer, but this can include such details as victim country, victim hardware id (HWID), and the date and time of capture.

HWIDs are unique and are used as a security measure by Microsoft when Windows is activated.  They are generated when an OS is first installed.  Date and time details can be used to verify the veracity of the data.

├─ Autofills/

│  ├─ Google_[Chrome]_Default.txt

│  ├─ Google_[Chrome]_Profile1.txt

│  ├─ Microsoft_[Edge]_Default.txt

We input a lot of data into web browsers.  To make this process easier, most now facilitate the auto-filling of data, saving the user considerable time.  This data is stored within the browser for quick and easy recall when required.  Stealer logs will routinely target this data, which can include:

Names and DOBs
Addresses
Contact details (email addresses, telephone numbers etc)
Partial credit card details
Access to this data poses a significant risk.  Threat actors can and will use this gathered information to develop a profile of the victim, making it easier for them to launch successful, socially-engineered attacks.

├─ Cookies/

│  ├─ Google_[Chrome]_Default Extension.txt

│  ├─ Google_[Chrome]_Default Network.txt

│  ├─ Google_[Chrome]_Profile 1 Network.txt

│  ├─ Microsoft_[Edge]_Default Network.txt

│  ├─ Microsoft_[Edge]_Profile 1 Network.txt

│  ├─ Opera Software_Unknown Network.txt

Web browsers will also store temporary files or cookies.  These will contain details about credentialed sessions on the browser, but not password information.  The risk caused by the exposure of this data is that it allows a threat actor to replicate account access, potentially bypassing login details to access more sensitive information.

├─ CreditCards/

│  ├─ Microsoft_[Edge]_Default.txt

Web browsers may also save financial information, for ease of access when making online purchases.  Some stealer malware variants will seek to extract this information.  In this example, unredacted credit card details were saved in the Edge web browser, and extracted in full by the malware.

├─ FileGrabber/

│  ├─ Users/

│  │  ├─ Pauli/

│  │  │  ├─ Desktop/

│  │  │  │  ├─ passwords.txt

Some stealer malware variants possess the ability to extract a victim’s files.  Typically, they will focus on file locations which are common across different devices and likely to hold valuable information, such as Desktop or Documents.  The example above shows the victim had a text file saved on their Desktop, containing their usernames and passwords for various sites.

├─ DomainDetects.txt

This file is generated by the malware.  It reads the extracted information and highlights the most common domains seen in the data.  Threat actors use this analysis to identify logs of interest, i.e. those that are accessing websites and services that are of value or can be exploited further.

├─ ImportantAutofills.txt

This file is generated from parsed data from stored auto-fills.  It seeks to extract data deemed most valuable to a threat actor, which can include sensitive Personally Identifiable Information (PII) and financial data.

├─ InstalledBrowsers.txt

Details all installed browsers, including version information.  Identifying an old browser version could provide a threat actor opportunity to launch attacks using known exploits.

├─ InstalledSoftware.txt

Details all applications installed on a victim device, including version information.  This too has value to a threat actor to identify potential vectors for exploitation.

├─ Passwords.txt

The holy grail for stealer malware.  Passwords are extracted from web browsers and stored in this file, including the site name, username and cleartext password.

This file has the potential to be the most destructive for a victim and highlights the inherent risks in using native browser password storage, rather than more secure and reputable password managers.

├─ ProcessList.txt

This file contains an extract of the running processes at the time of infection.  When used in combination with other gathered data, it can provide a threat actor with the opportunity to attack the device further, by utilising suitable exploits identified through this data.

├─ Screenshot.jpg

Not every stealer malware will do this, but some will take a screenshot of the victims’ screen at the point of infection.  This provides some additional information regarding the victim and their habits and activities.  This would have the potential to capture sensitive information if the victim is within a corporate network, or provide a threat actor with additional material for making blackmail or ransom threats.
├─ UserInformation.txt

The last file will generate details regarding the victim’s device, including IPs, hardware, location, and date

   
Example: screenshot



Posted by: 1van
02-07-2024, 06:58 PM
Forum: Vesti, zanimljivosti i razno
- No Replies

Quote:Pokušaji prevare građana SMS porukama koje navodno šalje JP „Pošta Srbije“ naglo su se povećali pred novogodišnje praznike. U decembru 2023. godine, broj pokušaja obmane praktično se upetostručio – sa prosečnih stotinak do 160 mesečno zabeleženih tokom prethodnih godina na oko 500, kažu u „Pošti Srbije“.

Podaci MUP-a poslati Novoj ekonomiji pokazuju da je tokom 2023. godine ukupno primljeno 2.023 zahteva za prikupljanje potrebnih obaveštenja Posebnog tužilaštva za za visokotehnološki kriminal. Tokom 2020. godine bilo ih je znatno manje, ukupno 1.203, a godinu pre toga još za 50 odsto manje.

Izvor: https://novaekonomija.rs/vesti-iz-zemlje...u-decembru



Posted by: 1van
02-07-2024, 06:46 PM
Forum: Vesti, zanimljivosti i razno
- No Replies

Quote:InformNapalm volunteer intelligence community has a new CYBINT investigation based on data from the correspondence between Russian politicians and their assistants, exposing sensitive facts about international economic relations between Russia and Serbia, as well as other aspects of international politics, corruption and energy (in)security. The materials were obtained by InformNapalm from the Ukrainian hacktivists of the Cyber Resistance group, the findings were verified and supplemented with video evidence presented in this publication.

Details: https://informnapalm.org/en/hacking-assi...tate-duma/

   



Posted by: 1van
02-07-2024, 06:36 PM
Forum: Vesti, zanimljivosti i razno
- No Replies

Quote:Some 1,300 suspicious IP addresses or URLs have been identified as part of a global INTERPOL operation targeting phishing, malware and ransomware attacks.

Operation Synergia, which ran from September to November 2023, was launched in response to the clear growth, escalation and professionalisation of transnational cybercrime and the need for coordinated action against new cyber threats.

The operation involved 60 law enforcement agencies from more than 50 INTERPOL member countries, with officers conducting house searches and seizing servers as well as electronic devices. To date, 70% of the command-and-control (C2) servers identified have been taken down, with the remainder currently under investigation.

Quote:
  • Most of the C2 servers taken down were in Europe, where 26 people were arrested.
  • Hong Kong and Singapore Police took down 153 and 86 servers, respectively.
  • South Sudan and Zimbabwe reported the most takedowns on the African continent, arresting four suspects.
  • Bolivia mobilized a range of public authorities to identify malware and resulting vulnerabilities.
  • Kuwait’s worked closely with Internet Service Providers to identify victims, conduct field investigations and offer technical guidance to mitigate impacts.

Quote:Participating countries:

Albania, Algeria, Australia , Bangladesh, Belarus, Belgium, Benin, Bolivia, Bosnia and Herzegovina, Brazil, Cameroon, Canada, China, Cyprus, Czech Republic, Dominican Republic, Ecuador, Estonia, Eswatini, France, Georgia, Greece, Guyana, India, Ireland, Israel, Kuwait, Latvia, Lebanon, Lichtenstein, Maldives, Mauritius, Moldova, Nepal, Nicaragua, Nigeria, Palestine, Poland, Qatar, Russia, San Marino, Singapore, South Korea, South Sudan, Spain, Sri Lanka, Switzerland, Tanzania, Thailand, Tonga, Tunisia, Türkiye, Uganda, United Arab Emirates, Uruguay, Zimbabwe.

Nema Srbije...

Izvor: https://www.interpol.int/en/News-and-Eve...er-threats

   



Posted by: 1van
02-07-2024, 04:26 PM
Forum: Neadekvatno zaštićeni resursi
- No Replies

Izvor: https://twitter.com/nebjak/status/1754805185283539069

Greška "User data (ban_id, ben_id, msisdn) are missing", ukazuje da je izgleda prošao login, ali ga nema u "poslovnoj" aplikaciji (ban_id = Billing Account Number).

   



Posted by: VincaSec
02-07-2024, 03:43 PM
Forum: Kompromitovani resursi
- Replies (4)