Dark Web analiza eps.rs
#8
Drugari iz https://sosintel.co.uk/ su nam poslali još podataka:

Quote:1mln_URL48.txt:http://sapsolman1.eps.local/:vladanj:[PASSWORD_REDACTED]
sunurl-PRIVATE-22.10-2-.txt:http://imenik.eps.local/||
sunurl-PRIVATE-22.10-2-.txt:http://proxy1.eps.local/|predrag.tosic|[PASSWORD_REDACTED]
sunurl-PRIVATE-22.10-2-.txt:http://proxy3.eps.local/|eps\predrag.tosic|[PASSWORD_REDACTED]
sunurl-PRIVATE-22.10-2-.txt:http://proxy1.eps.local/|eps\predrag.tosic|[PASSWORD_REDACTED]
sunurl-PRIVATE-22.10-7-.txt:g212:1129:https://ise21.eps.local/

Daljim istraživanjem možemo da vidimo da su to:

[email protected]
[email protected]

I da, imamo i nove interne domene:

Quote:imenik.eps.local
proxy1.eps.local
proxy3.eps.local

eps-grupa.eps.local
jana2-p.eps.rs
mdm-ggm-p.eps.local
mdm-t.eps.local
piseps-p.eps.local

Da sumiramo sada imamo sa tri različita izvora detalje (slike ekrana mejl inboksa zaposlenih i detekcije honeypot-ova, saznanja o internim EPS domenima iz Stealer logova i Password dampova) o kompromitaciji EPS-a.
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply


Messages In This Thread
Dark Web analiza eps.rs - by VincaSec - 12-06-2023, 05:54 PM
RE: Dark Web analiza eps.rs - by 1van - 12-07-2023, 07:36 AM
RE: Dark Web analiza eps.rs - by 1van - 12-07-2023, 07:39 AM
RE: Dark Web analiza eps.rs - by 1van - 12-07-2023, 07:48 AM
RE: Dark Web analiza eps.rs - by 1van - 12-13-2023, 08:37 AM
RE: Dark Web analiza eps.rs - by 1van - 12-15-2023, 08:25 AM
RE: Dark Web analiza eps.rs - by 1van - 12-18-2023, 01:23 PM
RE: Dark Web analiza eps.rs - by 1van - 12-19-2023, 09:37 AM
RE: Dark Web analiza eps.rs - by VincaSec - 01-05-2024, 09:31 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)