Kompromitovani računari zaposlenih u NIS -u
#1
   
   
Code:
0:{13 items
"date_uploaded":"2024-01-06T13:30:32.335Z"
"stealer_family":"Lumma"
"computer_name":"Korisnik"
"operating_system":"Windows 10 (10.0.19045)"
"antiviruses":[]0 items
"employee_session_cookies":212 items
[100 items
0:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-03-27T14:51:32.000Z"
}
1:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"ACCOUNT_CHOOSER"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:24.000Z"
}
2:{5 items
"url":"chrome.google.com"
"domain":"google.com"
"name":"__utma"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-01-12T00:40:55.000Z"
}
3:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSIDTS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-28T19:59:01.000Z"
}
4:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-16T16:55:39.000Z"
}
5:{5 items
"url":"google.com"
"domain":"google.com"
"name":"NID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-25T19:17:59.000Z"
}
6:{5 items
"url":"google.com"
"domain":"google.com"
"name":"NID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-27T18:34:45.000Z"
}
7:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"sess-at-main"
"value":"••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-21T15:28:31.000Z"
}
8:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"session-token"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2036-01-01T08:00:00.000Z"
}
9:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-20T12:05:35.000Z"
}
10:{5 items
"url":"www.amazon.com"
"domain":"amazon.com"
"name":"csm-hit"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-06T15:28:16.000Z"
}
11:{5 items
"url":"support.google.com"
"domain":"google.com"
"name":"_ga"
"value":"•••••••••••••••••••••••••••"
"expiry":"2025-12-23T20:38:53.000Z"
}
12:{5 items
"url":"www.linkedin.com"
"domain":"linkedin.com"
"name":"bscookie"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-23T13:25:08.000Z"
}
13:{5 items
"url":"chrome.google.com"
"domain":"google.com"
"name":"__utma"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-12-22T18:32:28.000Z"
}
14:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"LSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-11-21T15:38:31.000Z"
}
15:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T07:58:30.000Z"
}
16:{5 items
"url":"auth0.openai.com"
"domain":"openai.com"
"name":"did_compat"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-08T22:06:49.000Z"
}
17:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-12-17T16:45:43.000Z"
}
18:{5 items
"url":"play.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-03-13T14:28:31.000Z"
}
19:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SNID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-28T10:14:04.000Z"
}
20:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-12-01T13:56:01.000Z"
}
21:{5 items
"url":"google.com"
"domain":"google.com"
"name":"1P_JAR"
"value":"•••••••••••••"
"expiry":"2024-01-24T19:18:01.000Z"
}
22:{5 items
"url":"google.com"
"domain":"google.com"
"name":"HSID"
"value":"•••••••••••••••••"
"expiry":"2024-10-23T05:59:53.000Z"
}
23:{5 items
"url":"google.com"
"domain":"google.com"
"name":"NID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-25T09:43:54.000Z"
}
24:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"session-id-time"
"value":"•••••••••••"
"expiry":"2024-03-21T15:28:31.000Z"
}
25:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSIDCC"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-16T16:55:39.000Z"
}
26:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-12-03T16:17:49.000Z"
}
27:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga_3WTQFP9ECQ"
"value":"•••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T05:59:39.000Z"
}
28:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"UserMatchHistory"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-18T11:59:50.000Z"
}
29:{5 items
"url":"auth0.openai.com"
"domain":"openai.com"
"name":"did"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-08T22:06:49.000Z"
}
30:{5 items
"url":"openai.com"
"domain":"openai.com"
"name":"cf_clearance"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-27T14:46:39.000Z"
}
31:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"session-id-time"
"value":"•••••••••••"
"expiry":"2036-01-01T08:00:00.000Z"
}
32:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"AnalyticsSyncHistory"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-18T11:59:50.000Z"
}
33:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T06:00:49.000Z"
}
34:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"session-id"
"value":"•••••••••••••••••••"
"expiry":"2036-01-01T08:00:00.000Z"
}
35:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-20T12:05:34.000Z"
}
36:{5 items
"url":"chat.openai.com"
"domain":"openai.com"
"name":"cf_clearance"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-18T19:03:13.000Z"
}
37:{5 items
"url":"meet.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T06:01:58.000Z"
}
38:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"bcookie"
"value":"••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-12-03T16:53:17.000Z"
}
39:{5 items
"url":"myaccount.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-10-14T12:20:29.000Z"
}
40:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:23.000Z"
}
41:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SNID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-16T17:31:25.000Z"
}
42:{5 items
"url":"drive.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T07:13:44.000Z"
}
43:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-3PLSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:24.000Z"
}
44:{5 items
"url":"google.com"
"domain":"google.com"
"name":"AEC"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-24T17:56:03.000Z"
}
45:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-09-04T20:43:44.000Z"
}
46:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-08T17:04:13.000Z"
}
47:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T05:59:53.000Z"
}
48:{5 items
"url":"gaming.amazon.com"
"domain":"amazon.com"
"name":"twitch-prime-language"
"value":"•••••"
"expiry":"2024-03-21T15:26:08.000Z"
}
49:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"sp-cdn"
"value":"•••••••••"
"expiry":"2024-03-21T15:28:29.000Z"
}
50:{5 items
"url":"google.com"
"domain":"google.com"
"name":"APISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-08T17:04:13.000Z"
}
51:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2025-12-17T16:45:43.000Z"
}
52:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-05T19:03:24.000Z"
}
53:{5 items
"url":"myaccount.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-03-09T17:10:38.000Z"
}
54:{5 items
"url":"github.com"
"domain":"github.com"
"name":"logged_in"
"value":"••"
"expiry":"2024-01-17T23:37:00.000Z"
}
55:{5 items
"url":"google.com"
"domain":"google.com"
"name":"AEC"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-13T10:27:19.000Z"
}
56:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-12-01T13:56:21.000Z"
}
57:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-12-17T16:45:43.000Z"
}
58:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SSID"
"value":"•••••••••••••••••"
"expiry":"2024-11-20T16:55:23.000Z"
}
59:{5 items
"url":"myaccount.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:25.000Z"
}
60:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"lc-main"
"value":"•••••"
"expiry":"2036-01-01T08:00:00.000Z"
}
61:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-20T12:05:34.000Z"
}
62:{5 items
"url":"drive.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T07:13:44.000Z"
}
63:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga_3WTQFP9ECQ"
"value":"•••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-10-27T10:14:18.000Z"
}
64:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"x-main"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-21T15:28:31.000Z"
}
65:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SEARCH_SAMESITE"
"value":"••••••••"
"expiry":"2024-05-29T18:40:54.000Z"
}
66:{5 items
"url":"chrome.google.com"
"domain":"google.com"
"name":"_ga_Q3KJSFNQDY"
"value":"•••••••••••••••••••••••••••••••••••••"
"expiry":"2025-05-16T16:56:11.000Z"
}
67:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-3PLSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T07:13:44.000Z"
}
68:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga"
"value":"•••••••••••••••••••••••••••••"
"expiry":"2025-10-27T10:14:18.000Z"
}
69:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-23T05:59:53.000Z"
}
70:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:23.000Z"
}
71:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"at-main"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-21T15:28:31.000Z"
}
72:{5 items
"url":"google.com"
"domain":"google.com"
"name":"HSID"
"value":"•••••••••••••••••"
"expiry":"2024-06-20T12:05:34.000Z"
}
73:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"SMSV"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2032-12-05T17:04:13.000Z"
}
74:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"li_sugr"
"value":"••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-18T12:00:13.000Z"
}
75:{5 items
"url":"myaccount.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-03-09T17:10:38.000Z"
}
76:{5 items
"url":"google.com"
"domain":"google.com"
"name":"NID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-16T11:49:16.000Z"
}
77:{5 items
"url":"policies.google.com"
"domain":"google.com"
"name":"_ga"
"value":"•••••••••••••••••••••••••••"
"expiry":"2025-01-28T01:31:55.000Z"
}
78:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-03-27T14:51:32.000Z"
}
79:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:23.000Z"
}
80:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga_3WTQFP9ECQ"
"value":"•••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-20T19:38:28.000Z"
}
81:{5 items
"url":"amazon.com"
"domain":"amazon.com"
"name":"session-id"
"value":"•••••••••••••••••••"
"expiry":"2024-03-21T15:28:31.000Z"
}
82:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-12-03T16:17:49.000Z"
}
83:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SSID"
"value":"•••••••••••••••••"
"expiry":"2025-12-17T16:45:43.000Z"
}
84:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SNID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-25T17:58:09.000Z"
}
85:{5 items
"url":"myaccount.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:25.000Z"
}
86:{5 items
"url":"drive.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-10-14T12:20:29.000Z"
}
87:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-3PLSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-20T12:05:35.000Z"
}
88:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SSID"
"value":"•••••••••••••••••"
"expiry":"2024-06-20T12:05:34.000Z"
}
89:{5 items
"url":"paypal.com"
"domain":"paypal.com"
"name":"ts"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-10-23T07:05:55.000Z"
}
90:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-08T17:04:13.000Z"
}
91:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2025-12-17T16:45:43.000Z"
}
92:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"LSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-20T12:05:35.000Z"
}
93:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-12-01T13:56:01.000Z"
}
94:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:23.000Z"
}
95:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga_3WTQFP9ECQ"
"value":"•••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-09-04T20:42:10.000Z"
}
96:{5 items
"url":"google.com"
"domain":"google.com"
"name":"AEC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-13T11:49:16.000Z"
}
97:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"LSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-10-08T17:04:13.000Z"
}
98:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-06-20T12:05:34.000Z"
}
99:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-11-20T16:55:39.000Z"
}
]
[100 - 200]
[200 - 212]
"date_compromised":"2023-12-25T19:34:08.000Z"
"credentials":[6 items
0:{5 items
"type":"employee"
"url":"••••••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••••••••••"
"password":"••••••••"
}
1:{5 items
"type":"employee"
"url":"••••••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••••••••••"
"password":"••••••••"
}
2:{5 items
"type":"employee"
"url":"••••••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••••••••••"
"password":"••••••••"
}
3:{5 items
"type":"employee"
"url":"••••••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••••••••••"
"password":"••••••••"
}
4:{5 items
"type":"employee"
"url":"••••••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••••••••••"
"password":"••••••••"
}
5:{5 items
"type":"employee"
"url":"••••••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••••••••••"
"password":"••••••••"
}
]
Code:
"date_uploaded":"2023-03-16T05:19:25.546Z"
"stealer_family":"RedLine"
"computer_name":"vrlek"
"operating_system":"Windows 10 Enterprise x64"
"antiviruses":[3 items
0:"Windows Defender"
1:"Avast Antivirus"
2:"IObit Malware Fighter"
]
"employee_session_cookies":[40 items
0:{5 items
"url":"login.live.com"
"domain":"live.com"
"name":"uaid"
"value":"••••••••••••••••••••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
1:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
2:{5 items
"url":"google.com"
"domain":"google.com"
"name":"AID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-01T07:59:58.000Z"
}
3:{5 items
"url":"support.google.com"
"domain":"google.com"
"name":"_ga"
"value":"••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:59:38.000Z"
}
4:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
5:{5 items
"url":"login.live.com"
"domain":"live.com"
"name":"MSPRequ"
"value":"•••••••••••••••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
6:{5 items
"url":"www.linkedin.com"
"domain":"linkedin.com"
"name":"bscookie"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-07T12:39:55.000Z"
}
7:{5 items
"url":"support.google.com"
"domain":"google.com"
"name":"_ga_H30R9PNQFN"
"value":"•••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:59:40.000Z"
}
8:{5 items
"url":"login.live.com"
"domain":"live.com"
"name":"MSCC"
"value":"••••••••••••••••"
"expiry":"2024-02-01T12:45:00.000Z"
}
9:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"lang"
"value":"••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
10:{5 items
"url":"google.com"
"domain":"google.com"
"name":"APISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
11:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:58:43.000Z"
}
12:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SIDCC"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-07T13:00:46.000Z"
}
13:{5 items
"url":"google.com"
"domain":"google.com"
"name":"HSID"
"value":"•••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
14:{5 items
"url":"myactivity.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:26:37.000Z"
}
15:{5 items
"url":"login.live.com"
"domain":"live.com"
"name":"MSPOK"
"value":"••••••••••••••••••••••••••••••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
16:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-1PLSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:43:18.000Z"
}
17:{5 items
"url":"login.live.com"
"domain":"live.com"
"name":"OParams"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
18:{5 items
"url":"live.com"
"domain":"live.com"
"name":"mkt"
"value":"••••••••••"
"expiry":"2024-01-06T23:59:58.000Z"
}
19:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
20:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
21:{5 items
"url":"myactivity.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:26:37.000Z"
}
22:{5 items
"url":"live.com"
"domain":"live.com"
"name":"mkt1"
"value":"••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
23:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"LSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:43:18.000Z"
}
24:{5 items
"url":"live.com"
"domain":"live.com"
"name":"amsc"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
25:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
26:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-07T13:15:20.000Z"
}
27:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
28:{5 items
"url":"ads.linkedin.com"
"domain":"linkedin.com"
"name":"lang"
"value":"••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
29:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-07T13:00:46.000Z"
}
30:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"bcookie"
"value":"••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-07T12:39:55.000Z"
}
31:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Host-GMAIL_SCH"
"value":"•••"
"expiry":"9999-12-31T23:59:59.999Z"
}
32:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"GMAIL_AT"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
33:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:58:43.000Z"
}
34:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:58:43.000Z"
}
35:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-3PLSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T12:43:18.000Z"
}
36:{5 items
"url":"mega.nz"
"domain":"mega.nz"
"name":"geoip"
"value":"••"
"expiry":"9999-12-31T23:59:59.999Z"
}
37:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"ACCOUNT_CHOOSER"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
38:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SSID"
"value":"•••••••••••••••••"
"expiry":"2024-02-11T11:02:44.000Z"
}
39:{5 items
"url":"chrome.google.com"
"domain":"google.com"
"name":"__utma"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-11T11:50:50.000Z"
}
]
"date_compromised":"2023-01-07T00:00:00.000Z"
"credentials":[9 items
0:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••••••••••••••"
"password":"•••••••••"
}
1:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••••••••••••••"
"password":"•••••••••"
}
2:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••••"
"password":"••••••••"
}
3:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••"
"password":"••••••••"
}
4:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••••••••"
"password":"••••••••"
}
5:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••"
"password":"•••••••••••"
}
6:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••"
"password":"•••••••••••"
}
7:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••"
"password":"••••••••••"
}
8:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••••••••••"
"password":"•••••••••••••"
}
]

There is no patch for stupidity - Kevin Mitnick
Reply
#2
Code:
"date_uploaded":"2023-04-04T09:19:02.794Z"
"stealer_family":"RedLine"
"computer_name":"goran"
"operating_system":"Windows 10 Enterprise x64"
"antiviruses":[1 item
0:"Windows Defender"
]
"employee_session_cookies":[23 items
0:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"LSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T17:00:27.000Z"
}
1:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
2:{5 items
"url":"acrobat.adobe.com"
"domain":"adobe.com"
"name":"uvts"
"value":"••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-26T11:06:59.000Z"
}
3:{5 items
"url":"facebook.com"
"domain":"facebook.com"
"name":"datr"
"value":"••••••••••••••••••••••••"
"expiry":"2024-04-20T13:25:04.000Z"
}
4:{5 items
"url":"google.com"
"domain":"google.com"
"name":"HSID"
"value":"•••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
5:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
6:{5 items
"url":"adobe.com"
"domain":"adobe.com"
"name":"AMCV_9E1005A551ED61CA0A490D45%40AdobeOrg"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-29T10:08:02.000Z"
}
7:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-11T21:19:11.000Z"
}
8:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-02T19:13:38.000Z"
}
9:{5 items
"url":"google.com"
"domain":"google.com"
"name":"APISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
10:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-11T21:19:11.000Z"
}
11:{5 items
"url":"adobe.com"
"domain":"adobe.com"
"name":"kndctr_9E1005A551ED61CA0A490D45_AdobeOrg_identity"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-02T12:26:13.000Z"
}
12:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
13:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSIDCC"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-02T19:13:38.000Z"
}
14:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-11T21:19:11.000Z"
}
15:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-02T19:13:38.000Z"
}
16:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
17:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-1PLSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T17:00:27.000Z"
}
18:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
19:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"ACCOUNT_CHOOSER"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T06:59:44.000Z"
}
20:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SSID"
"value":"•••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
21:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-3PLSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T17:00:27.000Z"
}
22:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
]
"date_compromised":"2023-04-03T21:33:09.000Z"
"credentials":[1 item
0:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••••••"
"password":"•••••••••"
}
]
Code:
"date_uploaded":"2023-01-24T14:00:41.927Z"
"stealer_family":"RedLine"
"computer_name":"ProServis"
"operating_system":"Windows 10 Enterprise x64"
"antiviruses":[1 item
0:"Windows Defender"
]
"employee_session_cookies":[57 items
0:{5 items
"url":"amazon.co.uk"
"domain":"amazon.co.uk"
"name":"session-id"
"value":"•••••••••••••••••••"
"expiry":"2036-01-01T08:00:01.000Z"
}
1:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-20T13:14:13.000Z"
}
2:{5 items
"url":"chrome.google.com"
"domain":"google.com"
"name":"__utma"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2023-10-27T22:30:06.000Z"
}
3:{5 items
"url":"google.com"
"domain":"google.com"
"name":"HSID"
"value":"•••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
4:{5 items
"url":"facebook.com"
"domain":"facebook.com"
"name":"datr"
"value":"••••••••••••••••••••••••"
"expiry":"2024-03-13T19:57:44.000Z"
}
5:{5 items
"url":"amazon.co.uk"
"domain":"amazon.co.uk"
"name":"session-id-time"
"value":"•••••••••••"
"expiry":"2036-01-01T08:00:01.000Z"
}
6:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"ACCOUNT_CHOOSER"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-03T14:48:16.000Z"
}
7:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-09T15:49:34.000Z"
}
8:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"bcookie"
"value":"••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-25T19:18:00.000Z"
}
9:{5 items
"url":"myaccount.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-22T09:57:39.000Z"
}
10:{5 items
"url":"hp.com"
"domain":"hp.com"
"name":"_ga"
"value":"••••••••••••••••••••••••••"
"expiry":"2024-01-26T20:43:03.000Z"
}
11:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"LSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-09T22:47:29.000Z"
}
12:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"bcookie"
"value":"••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-19T14:12:46.000Z"
}
13:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-20T13:21:04.000Z"
}
14:{5 items
"url":"facebook.com"
"domain":"facebook.com"
"name":"_js_datr"
"value":"••••••••••••••••••••••••"
"expiry":"2024-02-20T14:20:28.000Z"
}
15:{5 items
"url":"h30434.www3.hp.com"
"domain":"hp.com"
"name":"VISITOR_BEACON"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2032-01-24T20:42:51.000Z"
}
16:{5 items
"url":"linkedin.com"
"domain":"linkedin.com"
"name":"lang"
"value":"••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
17:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga_3WTQFP9ECQ"
"value":"•••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-03T14:47:52.000Z"
}
18:{5 items
"url":"drive.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-09T22:47:29.000Z"
}
19:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-09T22:47:29.000Z"
}
20:{5 items
"url":"cloud.google.com"
"domain":"google.com"
"name":"_ga_devsite"
"value":"•••••••••••••••••••••••••••"
"expiry":"2024-04-28T11:54:36.000Z"
}
21:{5 items
"url":"drive.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-09T22:47:29.000Z"
}
22:{5 items
"url":"hp.com"
"domain":"hp.com"
"name":"AMCV_5E34123F5245B2CD0A490D45%40AdobeOrg"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-26T20:43:05.000Z"
}
23:{5 items
"url":"amazon.co.uk"
"domain":"amazon.co.uk"
"name":"lc-acbuk"
"value":"•••••"
"expiry":"2036-01-01T08:00:01.000Z"
}
24:{5 items
"url":"developers.google.com"
"domain":"google.com"
"name":"_ga_devsite"
"value":"•••••••••••••••••••••••••••"
"expiry":"2024-04-28T11:54:34.000Z"
}
25:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-1PLSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-09T22:47:29.000Z"
}
26:{5 items
"url":"support.google.com"
"domain":"google.com"
"name":"_ga"
"value":"•••••••••••••••••••••••••••"
"expiry":"2024-04-10T19:45:36.000Z"
}
27:{5 items
"url":"www.linkedin.com"
"domain":"linkedin.com"
"name":"bscookie"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-19T14:12:45.000Z"
}
28:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
29:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
30:{5 items
"url":"google.com"
"domain":"google.com"
"name":"APISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
31:{5 items
"url":"hp.com"
"domain":"hp.com"
"name":"s_fid"
"value":"•••••••••••••••••••••••••••••••••"
"expiry":"2027-01-26T20:43:02.000Z"
}
32:{5 items
"url":"h30434.www3.hp.com"
"domain":"hp.com"
"name":"LithiumCookiesAccepted"
"value":"•"
"expiry":"2032-01-24T20:42:50.000Z"
}
33:{5 items
"url":"hp.com"
"domain":"hp.com"
"name":"s_vi"
"value":"••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-26T22:00:09.000Z"
}
34:{5 items
"url":"partnerdash.google.com"
"domain":"google.com"
"name":"_ga"
"value":"••••••••••••••••••••••••••"
"expiry":"2024-04-10T19:45:15.000Z"
}
35:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-3PLSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-09T22:47:29.000Z"
}
36:{5 items
"url":"chat.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-09T15:47:54.000Z"
}
37:{5 items
"url":"amazon.co.uk"
"domain":"amazon.co.uk"
"name":"session-token"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2036-01-01T08:00:01.000Z"
}
38:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
39:{5 items
"url":"sites.google.com"
"domain":"google.com"
"name":"__utma"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-10T19:44:46.000Z"
}
40:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga"
"value":"•••••••••••••••••••••••••••••"
"expiry":"2024-01-25T08:07:39.000Z"
}
41:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__utma"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T17:02:08.000Z"
}
42:{5 items
"url":"cloud.google.com"
"domain":"google.com"
"name":"_ga"
"value":"•••••••••••••••••••••••••••"
"expiry":"2024-04-28T11:54:35.000Z"
}
43:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-09T15:49:34.000Z"
}
44:{5 items
"url":"facebook.com"
"domain":"facebook.com"
"name":"oo"
"value":"••"
"expiry":"2027-03-20T20:30:06.000Z"
}
45:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SSID"
"value":"•••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
46:{5 items
"url":"ads.linkedin.com"
"domain":"linkedin.com"
"name":"lang"
"value":"••••••••••••••"
"expiry":"9999-12-31T23:59:59.999Z"
}
47:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
48:{5 items
"url":"chat.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-09T15:47:54.000Z"
}
49:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
50:{5 items
"url":"facebook.com"
"domain":"facebook.com"
"name":"sb"
"value":"••••••••••••••••••••••••"
"expiry":"2024-02-20T14:20:15.000Z"
}
51:{5 items
"url":"cloud.google.com"
"domain":"google.com"
"name":"__utma"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-28T11:54:33.000Z"
}
52:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-02-19T16:24:15.000Z"
}
53:{5 items
"url":"myaccount.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-22T09:57:39.000Z"
}
54:{5 items
"url":"h30434.www3.hp.com"
"domain":"hp.com"
"name":"LithiumVisitor"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2032-01-24T20:42:52.000Z"
}
55:{5 items
"url":"google.com"
"domain":"google.com"
"name":"_ga"
"value":"•••••••••••••••••••••••••••••"
"expiry":"2024-05-03T14:47:52.000Z"
}
56:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSIDCC"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-01-20T13:14:13.000Z"
}
]
"date_compromised":"2023-01-20T05:23:43.000Z"
"credentials":[1 item
0:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"••••••••••••••••"
"password":"•••••••••"
}
]
Code:
"date_uploaded":"2023-04-04T09:19:02.794Z"
"stealer_family":"RedLine"
"computer_name":"goran"
"operating_system":"Windows 10 Enterprise x64"
"antiviruses":[1 item
0:"Windows Defender"
]
"employee_session_cookies":[23 items
0:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"LSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T17:00:27.000Z"
}
1:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
2:{5 items
"url":"acrobat.adobe.com"
"domain":"adobe.com"
"name":"uvts"
"value":"••••••••••••••••••••••••••••••••••••"
"expiry":"2024-03-26T11:06:59.000Z"
}
3:{5 items
"url":"facebook.com"
"domain":"facebook.com"
"name":"datr"
"value":"••••••••••••••••••••••••"
"expiry":"2024-04-20T13:25:04.000Z"
}
4:{5 items
"url":"google.com"
"domain":"google.com"
"name":"HSID"
"value":"•••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
5:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
6:{5 items
"url":"adobe.com"
"domain":"adobe.com"
"name":"AMCV_9E1005A551ED61CA0A490D45%40AdobeOrg"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-29T10:08:02.000Z"
}
7:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-11T21:19:11.000Z"
}
8:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PSIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-02T19:13:38.000Z"
}
9:{5 items
"url":"google.com"
"domain":"google.com"
"name":"APISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
10:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-GAPS"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-11T21:19:11.000Z"
}
11:{5 items
"url":"adobe.com"
"domain":"adobe.com"
"name":"kndctr_9E1005A551ED61CA0A490D45_AdobeOrg_identity"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-02T12:26:13.000Z"
}
12:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
13:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-1PSIDCC"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-02T19:13:38.000Z"
}
14:{5 items
"url":"mail.google.com"
"domain":"google.com"
"name":"__Secure-OSID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-11T21:19:11.000Z"
}
15:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SIDCC"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-02T19:13:38.000Z"
}
16:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SID"
"value":"•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
17:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-1PLSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T17:00:27.000Z"
}
18:{5 items
"url":"google.com"
"domain":"google.com"
"name":"__Secure-3PAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
19:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"ACCOUNT_CHOOSER"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T06:59:44.000Z"
}
20:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SSID"
"value":"•••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
21:{5 items
"url":"accounts.google.com"
"domain":"google.com"
"name":"__Host-3PLSID"
"value":"••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••"
"expiry":"2024-04-01T17:00:27.000Z"
}
22:{5 items
"url":"google.com"
"domain":"google.com"
"name":"SAPISID"
"value":"••••••••••••••••••••••••••••••••••"
"expiry":"2024-05-07T17:46:47.000Z"
}
]
"date_compromised":"2023-04-03T21:33:09.000Z"
"credentials":[1 item
0:{5 items
"type":"employee"
"url":"•••••••••••••••••••••••••••••••••••••"
"domain":"nis.rs"
"username":"•••••••••••"
"password":"•••••••••"
}
]
There is no patch for stupidity - Kevin Mitnick
Reply
#3
   
   
There is no patch for stupidity - Kevin Mitnick
Reply
#4
Infected Device - Accounts for "nis.rs" were observed for sale on the Russian Market, On Feb 12, 2024
Code:
{
    "country": "RS",
    "date": "2024.02.12",
    "files": "archive.zip",
    "id": "15256344",
    "isp": "TELEKOM SRBIJA a.d.",
    "links": [
        "freepik.com",
        "login.aliexpress.com",
        "lams.metropolitan.ac.rs",
        "isum.metropolitan.ac.rs",
        "mail.metropolitan.ac.rs",
        "kupujemprodajem.com",
        "mail.metropolitan.ac.rs",
        "netflix.com",
        "laptopplaza.rs",
        "aliexpress.com",
        "eon.tv",
        "istockphoto.com",
        "vega.mysafeservers.com",
        "warranty.makita.eu",
        "accounts.google.com",
        "pkspartner.rs",
        "app.pkspartner.rs",
        "companywall.rs",
        "prijava.eid.gov.rs",
        "jnportal.ujn.gov.rs",
        "prijava.eid.gov.rs",
        "racun.jkponnis.rs.212-200-255-36.oblaci.rs",
        "companywall.rs",
        "frigomec.com",
        "status-frigo.com",
        "sr-rs.facebook.com",
        "srm.nis.rs",
        "b2bpartnerportal.com",
        "app.pkspartner.rs",
        "tenderilive.com",
        "accounts.hrlab.rs",
        "vega.mysafeservers.com",
        "app.pkspartner.rs",
        "kemoimpex.com",
        "registracijas.eid.gov.rs",
        "pkspartner.rs",
        "vega.mysafeservers.com",
        "accounts.google.com",
        "84.54.179.178",
        "crf.trezor.gov.rs",
        "accounts.hrlab.rs",
        "en.islcollective.com",
        "castolin.com",
        "vega.mysafeservers.com",
        "prijava.eid.gov.rs",
        "jugoistok.com",
        "poslovi.infostud.com",
        "status-frigo.com",
        "usluge.pks.rs",
        "helpdesk.pksca.rs",
        "telenor.rs",
        "live.grantovi.com",
        "vega.mysafeservers.com",
        "aplikacije.pks.rs",
        "prijave.ras.gov.rs",
        "status-frigo.com",
        "yettel.rs",
        "cloud.enka.com",
        "egps.enka.com",
        "blablacar.rs",
        "scoring.rs",
        "yettel.rs",
        "coursera.org",
        "lams.metropolitan.ac.rs",
        "accounts.google.com"
    ],
    "outlook": "-",
    "price": "10.00",
    "province": "Sumadija",
    "size": "0.47Mb",
    "stealer": "stealc ",
    "vendor": "Mo####yf [Diamond]"
}

Code:
{
    "country": "RS",
    "date": "2023.12.12",
    "files": "archive.zip",
    "id": "13742506",
    "isp": "SAT-TRAKT Telecommunications",
    "links": [
        "forum.miniclubserbia.rs",
        "kufirc.com",
        "prijava.eid.gov.rs",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "login.gaijin.net",
        "moto-berza.com",
        "signin.rockstargames.com",
        "hu-hu.facebook.com",
        "epicgames.com",
        "rtlmost.hu",
        "kupujemprodajem.com",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "deezer.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "katana.facebook.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "connect.ubisoft.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "deezer.com",
        "sr-rs.facebook.com",
        "signin.ea.com",
        "gateway.hbogo.eu",
        "help.steampowered.com",
        "forum.bjbikers.com",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "pinterest.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.live.com",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "epicgames.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "facebook.com",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "facebook.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "login.yahoo.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "novi.kupujemprodajem.com",
        "auth0.openai.com",
        "account.proton.me",
        "zoovilleforum.net",
        "discord.com",
        "id.logi.com",
        "app.roll20.net",
        "gamers-outlet.net",
        "profile.callofduty.com",
        "banggood.com",
        "client.banggood.com",
        "192.168.0.1",
        "uk.banggood.com",
        "sculpfun.com",
        "hasznaltauto.hu",
        "fleet.omv.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "hu.banggood.com",
        "sso.willhaben.at",
        "account.protonvpn.com",
        "account.battle.net",
        "amateri.com",
        "player.tunein",
        "myauktion.com",
        "sso.willhaben.at",
        "myauktion.com",
        "willhaben.at",
        "amazon.com",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "netflix.com",
        "steamcommunity.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "login.live.com",
        "crt.omv.com",
        "fleet.omv.com",
        "fleet.omv.com",
        "accounts.saloodo.com",
        "cards.nis.rs",
        "my.timocom.com",
        "ciha-hotspot.stcable.rs",
        "rtlmost.hu",
        "poughkeepsie-hotspot.stcable.rs",
        "bazen-hotspot.stcable.rs",
        "sr-rs.facebook.com",
        "moj.esdnevnik.rs",
        "accounts.google.com",
        "comet.fss.rs",
        "lennonbt-hotspot.stcable.rs",
        "coca-cola.rs",
        "sorozatbarat.club",
        "shtreber.com",
        "baron-hotspot.stcable.rs",
        "accounts.google.com",
        "hotspot.stcable.rs",
        "prezi.com",
        "pinterest.com",
        "termalnar-hotspot.stcable.rs",
        "mediaclient.netflix.com",
        "zlatna.grana.hotspot.stcable.rs",
        "izlogideja-hotspot.stcable.rs",
        "coca-cola.rs",
        "aternos.org",
        "accounts.lidl.com",
        "m.kupujemprodajem.com",
        "kupujemprodajem.com",
        "servisi.euprava.gov.rs",
        "steamcommunity.com",
        "servisi.euprava.gov.rs",
        "kufirc.com",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "moto-berza.com",
        "hu-hu.facebook.com",
        "rtlmost.hu",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "deezer.com",
        "sr-rs.facebook.com",
        "gateway.hbogo.eu",
        "help.steampowered.com",
        "forum.bjbikers.com",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "auth0.openai.com",
        "account.proton.me",
        "zoovilleforum.net",
        "discord.com",
        "id.logi.com",
        "app.roll20.net",
        "gamers-outlet.net",
        "profile.callofduty.com",
        "client.banggood.com",
        "192.168.0.1",
        "uk.banggood.com",
        "sculpfun.com",
        "hasznaltauto.hu",
        "fleet.omv.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "hu.banggood.com",
        "account.protonvpn.com",
        "account.battle.net",
        "amateri.com",
        "player.tunein",
        "myauktion.com",
        "sso.willhaben.at",
        "myauktion.com",
        "willhaben.at",
        "amazon.com",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "novi.kupujemprodajem.com",
        "pinterest.com",
        "banggood.com",
        "facebook.com",
        "facebook.com",
        "kupujemprodajem.com",
        "katana.facebook.com",
        "signin.ea.com",
        "prijava.eid.gov.rs",
        "signin.rockstargames.com",
        "epicgames.com",
        "connect.ubisoft.com",
        "login.live.com",
        "login.yahoo.com",
        "steamcommunity.com",
        "sso.willhaben.at",
        "netflix.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "auth0.openai.com",
        "zoovilleforum.net",
        "account.proton.me",
        "accounts.google.com",
        "registracija.eid.gov.rs",
        "registracija.eid.gov.rs",
        "prijava.eid.gov.rs",
        "sso.willhaben.at",
        "signin.rockstargames.com",
        "forum.miniclubserbia.rs",
        "kufirc.com",
        "prijava.eid.gov.rs",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "login.gaijin.net",
        "moto-berza.com",
        "signin.rockstargames.com",
        "hu-hu.facebook.com",
        "epicgames.com",
        "rtlmost.hu",
        "kupujemprodajem.com",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "deezer.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "katana.facebook.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "connect.ubisoft.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "deezer.com",
        "sr-rs.facebook.com",
        "signin.ea.com",
        "gateway.hbogo.eu",
        "help.steampowered.com",
        "forum.bjbikers.com",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "pinterest.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.live.com",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "epicgames.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "facebook.com",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "facebook.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "login.yahoo.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "novi.kupujemprodajem.com",
        "auth0.openai.com",
        "account.proton.me",
        "zoovilleforum.net",
        "discord.com",
        "id.logi.com",
        "app.roll20.net",
        "gamers-outlet.net",
        "profile.callofduty.com",
        "banggood.com",
        "client.banggood.com",
        "192.168.0.1",
        "uk.banggood.com",
        "sculpfun.com",
        "hasznaltauto.hu",
        "fleet.omv.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "hu.banggood.com",
        "sso.willhaben.at",
        "account.protonvpn.com",
        "account.battle.net",
        "amateri.com",
        "player.tunein",
        "myauktion.com",
        "sso.willhaben.at",
        "myauktion.com",
        "willhaben.at",
        "amazon.com",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "netflix.com",
        "steamcommunity.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "login.live.com",
        "crt.omv.com",
        "fleet.omv.com",
        "fleet.omv.com",
        "accounts.saloodo.com",
        "cards.nis.rs",
        "my.timocom.com",
        "ciha-hotspot.stcable.rs",
        "rtlmost.hu",
        "poughkeepsie-hotspot.stcable.rs",
        "bazen-hotspot.stcable.rs",
        "sr-rs.facebook.com",
        "moj.esdnevnik.rs",
        "accounts.google.com",
        "comet.fss.rs",
        "lennonbt-hotspot.stcable.rs",
        "coca-cola.rs",
        "sorozatbarat.club",
        "shtreber.com",
        "baron-hotspot.stcable.rs",
        "accounts.google.com",
        "hotspot.stcable.rs",
        "prezi.com",
        "pinterest.com",
        "termalnar-hotspot.stcable.rs",
        "mediaclient.netflix.com",
        "zlatna.grana.hotspot.stcable.rs",
        "izlogideja-hotspot.stcable.rs",
        "coca-cola.rs",
        "aternos.org",
        "accounts.lidl.com",
        "m.kupujemprodajem.com",
        "kupujemprodajem.com",
        "servisi.euprava.gov.rs",
        "steamcommunity.com",
        "servisi.euprava.gov.rs",
        "kufirc.com",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "moto-berza.com",
        "hu-hu.facebook.com",
        "rtlmost.hu",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "deezer.com",
        "sr-rs.facebook.com",
        "gateway.hbogo.eu",
        "help.steampowered.com",
        "forum.bjbikers.com",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "auth0.openai.com",
        "account.proton.me",
        "zoovilleforum.net",
        "discord.com",
        "id.logi.com",
        "app.roll20.net",
        "gamers-outlet.net",
        "profile.callofduty.com",
        "client.banggood.com",
        "192.168.0.1",
        "uk.banggood.com",
        "sculpfun.com",
        "hasznaltauto.hu",
        "fleet.omv.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "hu.banggood.com",
        "account.protonvpn.com",
        "account.battle.net",
        "amateri.com",
        "player.tunein",
        "myauktion.com",
        "sso.willhaben.at",
        "myauktion.com",
        "willhaben.at",
        "amazon.com",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "novi.kupujemprodajem.com",
        "pinterest.com",
        "banggood.com",
        "facebook.com",
        "facebook.com",
        "kupujemprodajem.com",
        "katana.facebook.com",
        "signin.ea.com",
        "prijava.eid.gov.rs",
        "signin.rockstargames.com",
        "epicgames.com",
        "connect.ubisoft.com",
        "login.live.com",
        "login.yahoo.com",
        "steamcommunity.com",
        "sso.willhaben.at",
        "netflix.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "auth0.openai.com",
        "zoovilleforum.net",
        "account.proton.me",
        "accounts.google.com",
        "registracija.eid.gov.rs",
        "registracija.eid.gov.rs",
        "prijava.eid.gov.rs",
        "sso.willhaben.at",
        "signin.rockstargames.com",
        "forum.miniclubserbia.rs",
        "kufirc.com",
        "prijava.eid.gov.rs",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "login.gaijin.net",
        "moto-berza.com",
        "signin.rockstargames.com",
        "hu-hu.facebook.com",
        "epicgames.com",
        "rtlmost.hu",
        "kupujemprodajem.com",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "deezer.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "katana.facebook.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "connect.ubisoft.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "deezer.com",
        "sr-rs.facebook.com",
        "signin.ea.com",
        "gateway.hbogo.eu",
        "help.steampowered.com",
        "forum.bjbikers.com",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "pinterest.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.live.com",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "epicgames.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "facebook.com",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "facebook.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "login.yahoo.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "novi.kupujemprodajem.com",
        "auth0.openai.com",
        "account.proton.me",
        "zoovilleforum.net",
        "discord.com",
        "id.logi.com",
        "app.roll20.net",
        "gamers-outlet.net",
        "profile.callofduty.com",
        "banggood.com",
        "client.banggood.com",
        "192.168.0.1",
        "uk.banggood.com",
        "sculpfun.com",
        "hasznaltauto.hu",
        "fleet.omv.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "hu.banggood.com",
        "sso.willhaben.at",
        "account.protonvpn.com",
        "account.battle.net",
        "amateri.com",
        "player.tunein",
        "myauktion.com",
        "sso.willhaben.at",
        "myauktion.com",
        "willhaben.at",
        "amazon.com",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "netflix.com",
        "steamcommunity.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "login.live.com",
        "crt.omv.com",
        "fleet.omv.com",
        "fleet.omv.com",
        "accounts.saloodo.com",
        "cards.nis.rs",
        "my.timocom.com",
        "ciha-hotspot.stcable.rs",
        "rtlmost.hu",
        "poughkeepsie-hotspot.stcable.rs",
        "bazen-hotspot.stcable.rs",
        "sr-rs.facebook.com",
        "moj.esdnevnik.rs",
        "accounts.google.com",
        "comet.fss.rs",
        "lennonbt-hotspot.stcable.rs",
        "coca-cola.rs",
        "sorozatbarat.club",
        "shtreber.com",
        "baron-hotspot.stcable.rs",
        "accounts.google.com",
        "hotspot.stcable.rs",
        "prezi.com",
        "pinterest.com",
        "termalnar-hotspot.stcable.rs",
        "mediaclient.netflix.com",
        "zlatna.grana.hotspot.stcable.rs",
        "izlogideja-hotspot.stcable.rs",
        "coca-cola.rs",
        "aternos.org",
        "accounts.lidl.com",
        "m.kupujemprodajem.com",
        "kupujemprodajem.com",
        "servisi.euprava.gov.rs",
        "steamcommunity.com",
        "servisi.euprava.gov.rs",
        "kufirc.com",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "moto-berza.com",
        "hu-hu.facebook.com",
        "rtlmost.hu",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "deezer.com",
        "sr-rs.facebook.com",
        "gateway.hbogo.eu",
        "help.steampowered.com",
        "forum.bjbikers.com",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "auth0.openai.com",
        "account.proton.me",
        "zoovilleforum.net",
        "discord.com",
        "id.logi.com",
        "app.roll20.net",
        "gamers-outlet.net",
        "profile.callofduty.com",
        "client.banggood.com",
        "192.168.0.1",
        "uk.banggood.com",
        "sculpfun.com",
        "hasznaltauto.hu",
        "fleet.omv.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "hu.banggood.com",
        "account.protonvpn.com",
        "account.battle.net",
        "amateri.com",
        "player.tunein",
        "myauktion.com",
        "sso.willhaben.at",
        "myauktion.com",
        "willhaben.at",
        "amazon.com",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "novi.kupujemprodajem.com",
        "pinterest.com",
        "banggood.com",
        "facebook.com",
        "facebook.com",
        "kupujemprodajem.com",
        "katana.facebook.com",
        "signin.ea.com",
        "prijava.eid.gov.rs",
        "signin.rockstargames.com",
        "epicgames.com",
        "connect.ubisoft.com",
        "login.live.com",
        "login.yahoo.com",
        "steamcommunity.com",
        "sso.willhaben.at",
        "netflix.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "auth0.openai.com",
        "zoovilleforum.net",
        "account.proton.me",
        "accounts.google.com",
        "registracija.eid.gov.rs",
        "registracija.eid.gov.rs",
        "prijava.eid.gov.rs",
        "sso.willhaben.at",
        "signin.rockstargames.com",
        "forum.miniclubserbia.rs",
        "kufirc.com",
        "prijava.eid.gov.rs",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "login.gaijin.net",
        "moto-berza.com",
        "signin.rockstargames.com",
        "hu-hu.facebook.com",
        "epicgames.com",
        "rtlmost.hu",
        "kupujemprodajem.com",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "deezer.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "katana.facebook.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "connect.ubisoft.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "deezer.com",
        "sr-rs.facebook.com",
        "signin.ea.com",
        "gateway.hbogo.eu",
        "help.steampowered.com",
        "forum.bjbikers.com",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "pinterest.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.live.com",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "epicgames.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "facebook.com",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "facebook.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "login.yahoo.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "novi.kupujemprodajem.com",
        "auth0.openai.com",
        "account.proton.me",
        "zoovilleforum.net",
        "discord.com",
        "id.logi.com",
        "app.roll20.net",
        "gamers-outlet.net",
        "profile.callofduty.com",
        "banggood.com",
        "client.banggood.com",
        "192.168.0.1",
        "uk.banggood.com",
        "sculpfun.com",
        "hasznaltauto.hu",
        "fleet.omv.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "hu.banggood.com",
        "sso.willhaben.at",
        "account.protonvpn.com",
        "account.battle.net",
        "amateri.com",
        "player.tunein",
        "myauktion.com",
        "sso.willhaben.at",
        "myauktion.com",
        "willhaben.at",
        "amazon.com",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "netflix.com",
        "steamcommunity.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "login.live.com",
        "crt.omv.com",
        "fleet.omv.com",
        "fleet.omv.com",
        "accounts.saloodo.com",
        "cards.nis.rs",
        "my.timocom.com",
        "ciha-hotspot.stcable.rs",
        "rtlmost.hu",
        "poughkeepsie-hotspot.stcable.rs",
        "bazen-hotspot.stcable.rs",
        "sr-rs.facebook.com",
        "moj.esdnevnik.rs",
        "accounts.google.com",
        "comet.fss.rs",
        "lennonbt-hotspot.stcable.rs",
        "coca-cola.rs",
        "sorozatbarat.club",
        "shtreber.com",
        "baron-hotspot.stcable.rs",
        "accounts.google.com",
        "hotspot.stcable.rs",
        "prezi.com",
        "pinterest.com",
        "termalnar-hotspot.stcable.rs",
        "mediaclient.netflix.com",
        "zlatna.grana.hotspot.stcable.rs",
        "izlogideja-hotspot.stcable.rs",
        "coca-cola.rs",
        "aternos.org",
        "accounts.lidl.com",
        "m.kupujemprodajem.com",
        "kupujemprodajem.com",
        "servisi.euprava.gov.rs",
        "steamcommunity.com",
        "servisi.euprava.gov.rs",
        "kufirc.com",
        "edukacije.acas.rs",
        "wish.contextlogic.com",
        "signin.ea.com",
        "eduka.rs",
        "moto-berza.com",
        "hu-hu.facebook.com",
        "rtlmost.hu",
        "ucloudcam.com",
        "mediaclient.netflix.com",
        "forum.xboxrepublika.com",
        "v3.camscanner.com",
        "crf.trezor.gov.rs",
        "bludnice.com",
        "flortvagytobb.com",
        "aliexpresshd.alibaba.com",
        "smushgame.com",
        "login.gog.com",
        "spotify.com",
        "kufirc.com",
        "telenor.rs",
        "bs-ba.facebook.com",
        "polovniautomobili.com",
        "accounts.pubg.com",
        "instructables.com",
        "forum.miniclubserbia.rs",
        "moj.stcable.net",
        "geniustrainer.net",
        "euauth.hik-connect.com",
        "ncore.cc",
        "account.ubisoft.com",
        "xhamster.com",
        "xboxrepublika.com",
        "pexels.com",
        "polovniautomobili.com",
        "grammarly.com",
        "maticneevidencije.rs",
        "rtl.hu",
        "accounts.autodesk.com",
        "accounts.google.com",
        "new.edmodo.com",
        "accounts.google.com",
        "192.168.0.1",
        "android.degoo.com",
        "torrentmasters.net",
        "login.skype.com",
        "registracija.eid.gov.rs",
        "account.dyn.com",
        "ztracker.org",
        "szexichat.com",
        "pinterest.com",
        "kufirc.com",
        "community.ultimaker.com",
        "wetransfer.com",
        "192.168.0.140",
        "login.teamviewer.com",
        "app.pracenje.eu",
        "inventables.com",
        "arenabg.com",
        "mediaclient.netflix.com",
        "login.gog.com",
        "kufirc.com",
        "accounts.spotify.com",
        "login.yahoo.com",
        "orca.facebook.com",
        "camscanner.com",
        "torrentmasters.eu",
        "192.168.0.1",
        "android.coub.com",
        "bithorlo.info",
        "store.steampowered.com",
        "torrentmasters.eu",
        "lennonbt-hotspot.stcable.rs",
        "app.pracenje.eu",
        "minitorque.com",
        "pinterest.com",
        "crf.trezor.gov.rs",
        "192.168.0.68",
        "kepesmotor.hu",
        "new.edmodo.com",
        "ztracker.cc",
        "sr.eon.tv",
        "arenabg.ch",
        "netflix.com",
        "torrentmasters.net",
        "gateway.hbogo.rs",
        "torrentmasters.info",
        "estone.cc",
        "na.wargaming.net",
        "eveonline.com",
        "autoprofessionals.org",
        "macor.ath.cx",
        "poughkeepsie.hotspot.rs",
        "bludnice.com",
        "kufirc.com",
        "samsung.android.degoo.com",
        "account.dji.com",
        "account.protonvpn.com",
        "cryptsy.com",
        "192.168.1.1",
        "m.kupujemprodajem.com",
        "iforgot.apple.com",
        "torrentmasters.info",
        "moj.esdnevnik.rs",
        "coub.com",
        "xboxrepublika.com",
        "coub.com",
        "torrentmasters.net",
        "mini2.com",
        "eu.wargaming.net",
        "humblebundle.com",
        "192.168.0.107",
        "192.168.3.10",
        "192.168.0.68",
        "idmsa.apple.com",
        "roblox.com",
        "kufirc.com",
        "instagram.com",
        "m.facebook.com",
        "free-stl.ru",
        "login.yahoo.com",
        "us.battle.net",
        "rtlmost.hu",
        "rtl.hu",
        "accounts.thingiverse.com",
        "login.gaijin.net",
        "accounts.google.com",
        "yubraca.net",
        "torrentmasters.net",
        "pilot.dji",
        "signup.eune.leagueoflegends.com",
        "accounts.spotify.com",
        "torrentmasters.eu",
        "csapl.pcpf.panasonic.com",
        "titkosflort.com",
        "netflix.com",
        "en.industryarena.com",
        "easel.inventables.com",
        "arenabg.com",
        "forum.burek.com",
        "amazon.de",
        "hik-connect.com",
        "ucp.nordforapps.com",
        "komitenti.lion-group.rs",
        "baron-hotspot.stcable.rs",
        "hik-connect.com",
        "izlogideja-hotspot.stcable.rs",
        "torrentmasters.eu",
        "tiktok.com",
        "elitewarez.biz",
        "auth0.openai.com",
        "techlandgg.com",
        "admin.hasznaltauto.hu",
        "account.samsung.com",
        "videa.hu",
        "torrentmasters.org",
        "novi.kupujemprodajem.com",
        "pinterest.com",
        "banggood.com",
        "facebook.com",
        "facebook.com",
        "kupujemprodajem.com",
        "katana.facebook.com",
        "signin.ea.com",
        "prijava.eid.gov.rs",
        "signin.rockstargames.com",
        "epicgames.com",
        "connect.ubisoft.com",
        "login.live.com",
        "login.yahoo.com",
        "steamcommunity.com",
        "sso.willhaben.at",
        "netflix.com",
        "polovniautomobili.com",
        "mojsbb.rs",
        "app.pracenje.eu",
        "app.pracenje.eu",
        "kupujemprodajem.com",
        "polovniautomobili.com",
        "192.168.0.140",
        "app.pracenje.eu",
        "auth.platform.trans.eu",
        "accounts.autodesk.com",
        "hu-go.hu",
        "facebook.com",
        "novi.kupujemprodajem.com",
        "app.pracenje.eu",
        "192.168.0.1",
        "netflix.com",
        "auth0.openai.com",
        "zoovilleforum.net",
        "account.proton.me",
        "accounts.google.com",
        "registracija.eid.gov.rs",
        "registracija.eid.gov.rs",
        "prijava.eid.gov.rs",
        "sso.willhaben.at",
        "signin.rockstargames.com"
    ],
    "outlook": "-",
    "price": "10.00",
    "province": "Vojvodina",
    "size": "0.78Mb",
    "stealer": "lumma ",
    "vendor": "Mo####yf [Diamond]"
}
There is no patch for stupidity - Kevin Mitnick
Reply
#5
"webmail.nis.rs" has been detected in the Github Gist

Code:
{"level":"debug","ts":1696233545.839838,"logger":"events","msg":"event","name":"tls_get_certificate","id":"7ad4cf4e-57d4-4a53-90f2-163322bf8a08","origin":"tls","data":{"client_hello":{"CipherSuites":[2570,4865,4866,4867,49195,49199,49196,49200,52393,52392,49171,49172,156,157,47,53],"ServerName":"sns01mb01-sfhub.nis.local","SupportedCurves":[10794,29,23,24],"SupportedPoints":"AA==","SignatureSchemes":[1027,2052,1025,1283,2053,1281,2054,1537],"SupportedProtos":["http/1.1"],"SupportedVersions":[27242,772,771],"Conn":{}}}}
{"level":"debug","ts":1696233545.8399208,"logger":"tls.handshake","msg":"choosing certificate","identifier":"sns01mb01-sfhub.nis.local","num_choices":1}
{"level":"debug","ts":1696233545.83994,"logger":"tls.handshake","msg":"custom certificate selection results","identifier":"sns01mb01-sfhub.nis.local","subjects":["reverseproxyint","sns01sp-rp","sns01sp-rp.asutp.local","sns01enmpro","sns01enmpro.nis.local","sns01usoi4-app.nis.local","sns01usoi4-app","sns01mb01-sfhub","sns01mb01-sfhub.nis.local","materijalnibilans","materijalnibilans.nis.local","mb.nis.rs","powerbi.nis.rs","int","int.nis.local","webmail.nis.rs","webmail","mechfond","mechfond.nis.local","maxups","maxups.nis.eu","mobop","mobop.nis.local","gps.nis.rs","gps-test.nis.rs","sns01gis02","sns01gis02.nis.local","10.99.62.20"],"managed":false,"issuer_key":"","hash":"971b2f8d96b435f700d0f3fd1bde7cd74f228c5ec7cff29893b8e384d7f8e9f4"}
{"level":"debug","ts":1696233545.839948,"logger":"tls.handshake","msg":"matched certificate in cache","remote_ip":"10.100.103.21","remote_port":"59084","subjects":["reverseproxyint","sns01sp-rp","sns01sp-rp.asutp.local","sns01enmpro","sns01enmpro.nis.local","sns01usoi4-app.nis.local","sns01usoi4-app","sns01mb01-sfhub","sns01mb01-sfhub.nis.local","materijalnibilans","materijalnibilans.nis.local","mb.nis.rs","powerbi.nis.rs","int","int.nis.local","webmail.nis.rs","webmail","mechfond","mechfond.nis.local","maxups","maxups.nis.eu","mobop","mobop.nis.local","gps.nis.rs","gps-test.nis.rs","sns01gis02","sns01gis02.nis.local","10.99.62.20"],"managed":false,"expiration":1758880031,"hash":"971b2f8d96b435f700d0f3fd1bde7cd74f228c5ec7cff29893b8e384d7f8e9f4"}
{"level":"debug","ts":1696233545.842473,"logger":"http.handlers.reverse_proxy","msg":"selected upstream","dial":"sns01mb01-sfhub.nis.local:18666","total_upstreams":1}
{"level":"debug","ts":1696233545.878019,"logger":"http.handlers.reverse_proxy","msg":"upstream roundtrip","upstream":"sns01mb01-sfhub.nis.local:18666","duration":0.035475695,"request":{"remote_ip":"10.100.103.21","remote_port":"59084","client_ip":"10.100.103.21","proto":"HTTP/1.1","method":"GET","host":"sns01mb01-sfhub.nis.local:18666","uri":"/service/fdmaic4e8abpxzoe","headers":{"Pragma":["no-cache"],"X-Forwarded-Host":["sns01mb01-sfhub.nis.local:18666"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39"],"Accept-Encoding":["gzip, deflate, br"],"Upgrade":["websocket"],"Connection":["Upgrade"],"Sec-Websocket-Extensions":["permessage-deflate; client_max_window_bits"],"Accept-Language":["en-US,en;q=0.9"],"X-Forwarded-Proto":["https"],"Origin":["https://sns01mb01-sfhub.nis.local"],"Cache-Control":["no-cache"],"X-Forwarded-For":["10.100.103.21"],"Sec-Websocket-Version":["13"],"Sec-Websocket-Key":["mfX1HkHAzuRKunh/MflsJw=="]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"sns01mb01-sfhub.nis.local"}},"headers":{"Sec-Websocket-Version":["13"]},"status":426}
{"level":"error","ts":1696233545.8786438,"logger":"http.handlers.reverse_proxy","msg":"aborting with incomplete response","upstream":"sns01mb01-sfhub.nis.local:18666","duration":0.035475695,"request":{"remote_ip":"10.100.103.21","remote_port":"59084","client_ip":"10.100.103.21","proto":"HTTP/1.1","method":"GET","host":"sns01mb01-sfhub.nis.local:18666","uri":"/service/fdmaic4e8abpxzoe","headers":{"Pragma":["no-cache"],"X-Forwarded-Host":["sns01mb01-sfhub.nis.local:18666"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39"],"Accept-Encoding":["gzip, deflate, br"],"Upgrade":["websocket"],"Connection":["Upgrade"],"Sec-Websocket-Extensions":["permessage-deflate; client_max_window_bits"],"Accept-Language":["en-US,en;q=0.9"],"X-Forwarded-Proto":["https"],"Origin":["https://sns01mb01-sfhub.nis.local"],"Cache-Control":["no-cache"],"X-Forwarded-For":["10.100.103.21"],"Sec-Websocket-Version":["13"],"Sec-Websocket-Key":["mfX1HkHAzuRKunh/MflsJw=="]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"sns01mb01-sfhub.nis.local"}},"error":"reading: context canceled"}
{"level":"debug","ts":1696233545.8824418,"logger":"http.handlers.reverse_proxy","msg":"selected upstream","dial":"sns01mb01-sfhub.nis.local:443","total_upstreams":1}
{"level":"debug","ts":1696233545.884747,"logger":"http.handlers.reverse_proxy","msg":"selected upstream","dial":"sns01mb01-sfhub.nis.local:443","total_upstreams":1}
{"level":"debug","ts":1696233545.8861496,"logger":"http.handlers.reverse_proxy","msg":"selected upstream","dial":"sns01mb01-sfhub.nis.local:443","total_upstreams":1}
{"level":"debug","ts":1696233545.8867483,"logger":"http.handlers.reverse_proxy","msg":"upstream roundtrip","upstream":"sns01mb01-sfhub.nis.local:443","duration":0.001922187,"request":{"remote_ip":"10.100.103.21","remote_port":"59023","client_ip":"10.100.103.21","proto":"HTTP/2.0","method":"GET","host":"sns01mb01-sfhub.nis.local:443","uri":"/sfhub/Assets/SigmafineHub-Visualizer-registered.png","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39"],"X-Forwarded-For":["10.100.103.21"],"Sec-Fetch-Mode":["no-cors"],"Accept-Language":["en-US,en;q=0.9"],"X-Forwarded-Host":["sns01mb01-sfhub.nis.local"],"Sec-Ch-Ua":["\" Not A;Brand\";v=\"99\", \"Chromium\";v=\"101\", \"Microsoft Edge\";v=\"101\""],"Accept":["image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Accept-Encoding":["gzip, deflate, br"],"Sec-Fetch-Site":["same-origin"],"Sec-Fetch-Dest":["image"],"Referer":["https://sns01mb01-sfhub.nis.local/sfhub/login/sign_in/signin"],"Sec-Ch-Ua-Mobile":["?0"],"If-None-Match":["\"0ce9b61fbd8d61:0\""],"X-Forwarded-Proto":["https"],"If-Modified-Since":["Wed, 23 Dec 2020 07:15:24 GMT"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"sns01mb01-sfhub.nis.local"}},"headers":{"Etag":["\"0ce9b61fbd8d61:0\""],"Server":["Microsoft-IIS/10.0"],"X-Powered-By":["ASP.NET"],"Date":["Mon, 02 Oct 2023 07:59:05 GMT"],"Cache-Control":["no-cache"],"Accept-Ranges":["bytes"]},"status":304}
{"level":"debug","ts":1696233545.8873892,"logger":"http.handlers.reverse_proxy","msg":"upstream roundtrip","upstream":"sns01mb01-sfhub.nis.local:443","duration":0.001201797,"request":{"remote_ip":"10.100.103.21","remote_port":"59023","client_ip":"10.100.103.21","proto":"HTTP/2.0","method":"GET","host":"sns01mb01-sfhub.nis.local:443","uri":"/sfhub/Assets/SigmafineHub-Admin-registered.png","headers":{"Sec-Fetch-Site":["same-origin"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-Dest":["image"],"Accept-Language":["en-US,en;q=0.9"],"X-Forwarded-Host":["sns01mb01-sfhub.nis.local"],"Referer":["https://sns01mb01-sfhub.nis.local/sfhub/login/sign_in/signin"],"X-Forwarded-For":["10.100.103.21"],"Accept-Encoding":["gzip, deflate, br"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Ch-Ua":["\" Not A;Brand\";v=\"99\", \"Chromium\";v=\"101\", \"Microsoft Edge\";v=\"101\""],"If-None-Match":["\"0ce9b61fbd8d61:0\""],"X-Forwarded-Proto":["https"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39"],"Sec-Fetch-Mode":["no-cors"],"Accept":["image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8"],"If-Modified-Since":["Wed, 23 Dec 2020 07:15:24 GMT"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"sns01mb01-sfhub.nis.local"}},"headers":{"X-Powered-By":["ASP.NET"],"Date":["Mon, 02 Oct 2023 07:59:05 GMT"],"Cache-Control":["no-cache"],"Accept-Ranges":["bytes"],"Etag":["\"0ce9b61fbd8d61:0\""],"Server":["Microsoft-IIS/10.0"]},"status":304}
{"level":"debug","ts":1696233545.8994024,"logger":"http.handlers.reverse_proxy","msg":"upstream roundtrip","upstream":"sns01mb01-sfhub.nis.local:443","duration":0.016885835,"request":{"remote_ip":"10.100.103.21","remote_port":"59023","client_ip":"10.100.103.21","proto":"HTTP/2.0","method":"POST","host":"sns01mb01-sfhub.nis.local:443","uri":"/SFWebApi/SigmafineServices.SVC/sfAdmin/connect","headers":{"Content-Type":["text/plain"],"X-Forwarded-Proto":["https"],"Accept":["application/json, text/plain, */*"],"Accept-Encoding":["gzip, deflate, br"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39"],"Sec-Fetch-Site":["same-origin"],"X-Forwarded-Host":["sns01mb01-sfhub.nis.local"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Authorization":[],"Accept-Language":["en-US,en;q=0.9"],"Content-Length":["88"],"Sec-Ch-Ua":["\" Not A;Brand\";v=\"99\", \"Chromium\";v=\"101\", \"Microsoft Edge\";v=\"101\""],"X-Forwarded-For":["10.100.103.21"],"Sec-Fetch-Mode":["cors"],"Sec-Ch-Ua-Mobile":["?0"],"Origin":["https://sns01mb01-sfhub.nis.local"],"Referer":["https://sns01mb01-sfhub.nis.local/sfhub/login/sign_in/signin"],"Sec-Fetch-Dest":["empty"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"sns01mb01-sfhub.nis.local"}},"headers":{"Access-Control-Allow-Credentials":["false"],"Date":["Mon, 02 Oct 2023 07:59:05 GMT"],"Cache-Control":["private"],"Server":["Microsoft-IIS/10.0"],"Access-Control-Allow-Methods":["GET, HEAD, POST, PUT, DELETE, CONNECT, OPTIONS, TRACE, PATCH"],"Access-Control-Allow-Headers":["X-Content-Type-Options,X-Requested-With,Content-Type,X-Custom-Header,Authorization,Server,Access-Control-Allow-Origin,Access-Control-Request-Method,Access-Control-Allow-Headers,Access-Control-Allow-Credentials,X-Powered-By,Date,Content-Length"],"X-Aspnet-Version":["4.0.30319"],"X-Powered-By":["ASP.NET"],"Content-Type":["application/json; charset=utf-8"],"Access-Control-Allow-Origin":["*"],"Access-Control-Request-Method":["POST,GET,PUT,PATCH,DELETE,OPTIONS"]},"status":200}
There is no patch for stupidity - Kevin Mitnick
Reply
#6
Infected Device - Accounts for "webmail.nis.rs" were observed for sale on the Russian Market, On Aug 27, 2023
Code:
{
    "country": "RS",
    "date": "2023.08.27",
    "files": "archive.zip",
    "id": "11983603",
    "isp": "Telekom Srbija Internet Backbone Network",
    "links": [
        "auth.services.adobe.com",
        "android.instagram.com",
        "megasrbija.com",
        "my.jdownloader.org",
        "yts.ag",
        "vdocuments.mx",
        "prijevodi-online.org",
        "openlibrary.org",
        "uploaded.net",
        "scribd.com",
        "svetbiljaka.com",
        "serbianforum.org",
        "opensubtitles.org",
        "croportal.net",
        "login.yahoo.com",
        "acdid.acdsee.com",
        "stripotekaforum.com",
        "moj.mts.rs",
        "svetbiljaka.com",
        "serbianforum.org",
        "serbianforum.org",
        "adobeid.services.adobe.com",
        "kupdf.net",
        "balkandownload.org",
        "4shared.com",
        "instagram.com",
        "yts.am",
        "crowarez.org",
        "mediafire.com",
        "forum.krstarica.com",
        "galaksija.info",
        "account.live.com",
        "search.4shared.com",
        "serbianforum.org",
        "vojvodinanet.com",
        "uptobox.com",
        "warez-serbia.com",
        "twitter.com",
        "login.yahoo.com",
        "uploaded.net",
        "penzijskifond.rs",
        "drustvenamreza.com",
        "ashampoo.com",
        "serbianforum.org",
        "knjigoteka.org",
        "auth.opera.com",
        "pinterest.com",
        "uploaded.net",
        "support.uptobox.com",
        "megasrbija.com",
        "mojtotaltv.tv",
        "docsity.com",
        "gomlab.com",
        "login.live.com",
        "balkandownload.org",
        "balkandownload.org",
        "serbianforum.org",
        "sr.wikibooks.org",
        "yettel.rs",
        "login.live.com",
        "vk.com",
        "edoc.site",
        "megasrbija.com",
        "svetbiljaka.com",
        "balkandownload.org",
        "en.idcgames.com",
        "nitroflare.com",
        "serbianforum.org",
        "mojzrenjanin.com",
        "svetbiljaka.com",
        "pdfdrive.com",
        "scribd.com",
        "linkedin.com",
        "penzijskifond.rs",
        "instagram.com",
        "help.steampowered.com",
        "srpskaforum.com",
        "watchsomuch.tv",
        "serbianforum.org",
        "warezhr.org",
        "serbianforum.org",
        "knjige.club",
        "academia.edu",
        "connect.ubisoft.com",
        "archive.org",
        "4shared.com",
        "accounts.firefox.com",
        "prijevodi-online.org",
        "watchsomuch.to",
        "nitroflare.com",
        "knjigoteka.org",
        "accounts.google.com",
        "api.twitter.com",
        "signup.live.com",
        "steamcommunity.com",
        "accounts.google.com",
        "balkandownload.org",
        "serbianforum.org",
        "4shared.com",
        "megasrbija.com",
        "serbianforum.org",
        "uploaded.net",
        "knjige.club",
        "forum.titlovi.com",
        "yts.lt",
        "ulozto.net",
        "github.com",
        "facebook.com",
        "sr-rs.facebook.com",
        "accountscenter.facebook.com",
        "facebook.com",
        "kreativnost.4umer.com",
        "croportal.net",
        "maska.forumsr.com",
        "filesflash.com",
        "topalovic.rs",
        "facebook.com",
        "radiosumadinac.org",
        "edoc.site",
        "sr.wikibooks.org",
        "knjige.club",
        "svetbiljaka.com",
        "pdfdrive.com",
        "drugari.info",
        "filmskimaraton.com",
        "4shared.com",
        "accounts.google.com",
        "kupujemprodajem.com",
        "signup.live.com",
        "dlscrib.com",
        "megasrbija.com",
        "archive.org",
        "login.live.com",
        "facebook.com",
        "megagames.com",
        "signin.rockstargames.com",
        "drustvenamreza.com",
        "prijevodi-online.org",
        "maska.justgoo.com",
        "linkedin.com",
        "flix123.com",
        "bosnaunited.net",
        "acdid.acdsee.com",
        "login.live.com",
        "vojvodinanet.com",
        "filmovi.infopult.net",
        "rs.singlelogin.me",
        "eucionica.rs",
        "filmovizija.com",
        "vdocuments.mx",
        "serbianforum.org",
        "rasadnikeden.rs",
        "4dportal.com",
        "bosanskaraja.com",
        "my.screenname.aol.com",
        "arenaelite.net",
        "noviteti.net",
        "sr-rs.facebook.com",
        "pdfcoffee.com",
        "downturk.net",
        "tapatalk.com",
        "odigledolokomotive.rs",
        "vk.com",
        "forum.burek.com",
        "auth.opera.com",
        "4shared.com",
        "4dportal.com",
        "penzijskifond.rs",
        "balkandownload.org",
        "yts.lt",
        "drugari.org",
        "account.live.com",
        "kino.rs",
        "m2.facebook.com",
        "aladin.info",
        "megasrbija.com",
        "forum.titlovi.com",
        "fastserbia.com",
        "dfiles.eu",
        "mywot.com",
        "knjigoteka.org",
        "help.steampowered.com",
        "stripotekaforum.com",
        "adobeid.services.adobe.com",
        "crowarez.org",
        "smokismokic.com",
        "megasrbija.com",
        "sfi1.biz",
        "rtsplaneta.rs",
        "singlelogin.org",
        "yubraca.net",
        "account.playzula.com",
        "pinterest.com",
        "piksla.com",
        "dfiles.eu",
        "accounts.google.com",
        "rapidserbia4ever.com",
        "icerbox.com",
        "scribd.com",
        "crnaberza.com",
        "pizdarijewap.com",
        "ana.rs",
        "rapid-serbia.com",
        "topalovic.rs",
        "sandbox.game",
        "rapidserbia4ever.com",
        "aternos.org",
        "accounts.google.com",
        "king.com",
        "academia.edu",
        "fastserbia.com",
        "royalgames.com",
        "karike.com",
        "slideshare.net",
        "steamcommunity.com",
        "leo.rs",
        "bastovanstvo.rs",
        "misterije.com",
        "m.facebook.com",
        "malipirat.com",
        "uptobox.com",
        "penzijskifond.rs",
        "mojtotaltv.tv",
        "king.com",
        "vojvodinanet.com",
        "yubraca.net",
        "aladin.info",
        "yts.ag",
        "netflix.com",
        "login.vitalsource.com",
        "forum.krstarica.com",
        "sr.wikibooks.org",
        "balkandownload.org",
        "connect.ubisoft.com",
        "facebook.com",
        "napravisam.rs",
        "user.bitski.com",
        "gorenje.rs",
        "relax-forum.com",
        "id.lyoness.com",
        "misterije.com",
        "rapidserbia.com",
        "login.live.com",
        "yettel.rs",
        "authorize.kobo.com",
        "bosnaunited.net",
        "doisrpska.nub.rs",
        "relax-forum.com",
        "webmail.nis.rs",
        "login.live.com",
        "windscribe.com",
        "rapidgator.net",
        "android.degoo.com",
        "membership.square-enix.com",
        "movies-shows.com",
        "leptiricabioskop.com",
        "nitroflare.com",
        "mega.nz",
        "accounts.firefox.com",
        "haoss.org",
        "poreklo.rs",
        "rapidbelgrade.com",
        "rapidserbia4ever.com",
        "api.twitter.com",
        "warezhr.org",
        "serbianforum.org",
        "search.4shared.com",
        "support.uptobox.com",
        "singlelogin.me",
        "majevica.forumakers.com",
        "signup.live.com",
        "mogawifi.net",
        "filesflash.com",
        "odigledolokomotive.rs",
        "login.yahoo.com",
        "haoss.org",
        "adobeid-na1.services.adobe.com",
        "mycity-military.com",
        "arenaelite.net",
        "serbianforum.org",
        "balkandownload.org",
        "marketkonekt.com",
        "srpskaforum.com",
        "forum.krstarica.com",
        "topalovic.rs",
        "pvpro.com",
        "srpskaforum.com",
        "accounts.google.com",
        "warez-serbia.com",
        "kupdf.net",
        "wattpad.com",
        "accounts.google.com",
        "banjalukaforum.com",
        "twitter.com",
        "poreklo.rs",
        "napravisam.rs",
        "knjige.club",
        "twitter.com",
        "yugo.forum.st",
        "yts.am",
        "rapidserbia.forumsr.com",
        "crobytes.org",
        "accounts.google.com",
        "fax.pdf24.org",
        "instructables.com",
        "balkanelite.org",
        "ilovepdf.com",
        "kreativnost.4umer.com",
        "membership.square-enix.com",
        "galaksija.info",
        "kupujemprodajem.com",
        "nitroflare.net",
        "instructables.com",
        "en.idcgames.com",
        "nitroflare.com",
        "sfi1.biz",
        "svetbiljaka.com",
        "lost-serbia.forumotion.com",
        "forum.arheo-amateri.rs",
        "bosnaunited.net",
        "serbianforum.org",
        "exyushare.net",
        "instagram.com",
        "remixvockanje.rs",
        "webmail.nis.rs",
        "bosnaonline.org",
        "docsity.com",
        "facebook.com",
        "scribd.com",
        "facebook.com",
        "signup.live.com",
        "mojzrenjanin.com",
        "accounts.google.com",
        "sr-rs.facebook.com",
        "my.jdownloader.org",
        "uploaded.net",
        "serbianforum.org",
        "webmail.nis.rs",
        "webmail.nis.rs",
        "citehr.com",
        "login.yahoo.com",
        "my.jdownloader.org",
        "malioglasi.co.rs",
        "login.live.com",
        "accounts.google.com",
        "facebook.com",
        "malioglasi.co.rs",
        "serbianforum.org",
        "zvezdan.serbianforum.info",
        "topalovic.rs",
        "opensubtitles.org",
        "warez-bb.org",
        "webmail.nis.rs",
        "openlibrary.org",
        "uploaded.net",
        "webmail.nis.rs",
        "connect.collectorz.com",
        "android.instagram.com",
        "uploaded.net",
        "mogawifi.net",
        "webmail.nis.rs",
        "katana.facebook.com",
        "account.live.com",
        "knjigoteka.org",
        "connect.telenordigital.com",
        "socidoc.com",
        "my.jdownloader.org",
        "milversite.net",
        "topalovic.rs",
        "encian.hr",
        "webmail.nis.rs",
        "sr-rs.facebook.com",
        "prodaja.zelena-apoteka.com",
        "facebook.com",
        "kupujemprodajem.com",
        "lutrija.rs",
        "192.168.0.1",
        "topalovic.rs",
        "istoricari.com",
        "topalovic.rs",
        "katana.facebook.com",
        "facebook.com",
        "accounts.google.com",
        "signup.euw.leagueoflegends.com",
        "topalovic.rs",
        "instagram.com",
        "192.168.0.1",
        "moj.mts.rs"
    ],
    "outlook": "-",
    "price": "10.00",
    "province": "Vojvodina",
    "size": "0.50Mb",
    "stealer": "lumma ",
    "vendor": "Mo####yf [Diamond]"
}
Infected Device - Accounts for "webmail.nis.rs" were observed for sale on the Russian Market, On Aug 14, 2023
Code:
{
    "country": "RS",
    "date": "2023.08.11",
    "files": "archive.zip",
    "id": "11821824",
    "isp": "CETIN Ltd. Belgrade",
    "links": [
        "balkandownload.org",
        "mega.nz",
        "facebook.com",
        "accounts.google.com",
        "cad-hr.net",
        "eenmarket.group",
        "crf.trezor.gov.rs",
        "facebook.com",
        "exchange.ecd.rs",
        "exchange.ecd.rs",
        "webtrader.eenmarketgroup.cc",
        "webtrader.gmar.cc",
        "kapitalrs.com",
        "auth.wetransfer.com",
        "accounts.google.com",
        "sns01ise02.nis.rs",
        "192.168.1.1",
        "accounts.google.com",
        "ingkomora.rs",
        "forum.benchmark.rs",
        "balkandownload.org",
        "yettel.rs",
        "forum.benchmark.rs",
        "m.facebook.com",
        "forum.benchmark.rs",
        "forum.benchmark.rs",
        "accounts.google.com",
        "m.facebook.com",
        "accounts.firefox.com",
        "dms-gt.srbijagas.com",
        "facebook.com",
        "skyscrapercity.com",
        "balkandownload.org",
        "emmi.rs",
        "winwin.rs",
        "rtsplaneta.rs",
        "router.asus.com",
        "edcentar.com",
        "jugoistok.rs",
        "accounts.firefox.com.cn",
        "yout.com",
        "telenor.rs",
        "kupujemprodajem.com",
        "seljacionline-forum.com",
        "radiosumadinac.org",
        "netfilm.tv",
        "megasrbija.com",
        "mega.nz",
        "id.cashbackworld.com",
        "kapitalrs.com",
        "internations.org",
        "ingkomora.org.rs",
        "ingkomora.rs",
        "ingkomora.rs",
        "forum.krstarica.com",
        "fastserbia.com",
        "prijava.eid.gov.rs",
        "domaci.de",
        "cad-hr.net",
        "malioglasi.co.rs",
        "online.mobibanka.rs",
        "wetransfer.com",
        "account.live.com",
        "login.live.com",
        "login.live.com",
        "accounts.google.com",
        "id7.cloud.huawei.com",
        "jugoistok.rs",
        "cad-hr.net",
        "reid.apr.gov.rs",
        "reid.apr.gov.rs",
        "manualslib.com",
        "sportske.net",
        "edcentar.rs",
        "mi-srbija.rs",
        "mi-srbija.rs",
        "edcentar.rs",
        "accounts.google.com",
        "grider.rgz.gov.rs",
        "m.facebook.com",
        "ingkomora.rs",
        "webmail.nis.rs",
        "facebook.com",
        "webtrader.eenmarketgroup.cc",
        "webtrader.gmar.cc",
        "ekapija.com",
        "192.168.1.1",
        "192.168.1.1",
        "yettel.rs",
        "yettel.rs",
        "forum.benchmark.rs",
        "212.62.32.199",
        "modulus.rs",
        "ossp.katastar.gov.mk",
        "sr.wikipedia.org",
        "sr.wikipedia.org",
        "rs.jooble.org",
        "servisi.pio.rs",
        "servisi.pio.rs",
        "cadtutor.net",
        "damaswiki.net",
        "yettel.rs",
        "ingkomora.org.rs",
        "ingkomora.org.rs",
        "ingkomora.rs",
        "linkedin.com"
    ],
    "outlook": "-",
    "price": "10.00",
    "province": "Belgrade",
    "size": "0.72Mb",
    "stealer": "lumma ",
    "vendor": "Mo####yf [Diamond]"
}
There is no patch for stupidity - Kevin Mitnick
Reply
#7
   
   
   
   
   
There is no patch for stupidity - Kevin Mitnick
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)