Gi7w0rm(@Gi7w0rm) 's Twitter Profileg
Gi7w0rm

@Gi7w0rm

Threat Intelligence and #URINT Analyst |
See my Linktree for other socials |
In case I post false intel, contact me!
Support me: https://t.co/5WgDqr0K8p

ID:1058319953739333632

linkhttps://linktr.ee/gi7w0rm calendar_today02-11-2018 11:28:34

7,3K Tweets

14,5K Followers

685 Following

Gi7w0rm(@Gi7w0rm) 's Twitter Profile Photo

107 reports sent for critical vulnerabilities since last month.
65 fixed.
Sent several reports aside that are not registered by the platform.
Want to know how many I heard back from ?
3 in total.

Ungrateful work 😮‍💨
cc: LeakIX

107 reports sent for critical vulnerabilities since last month. 65 fixed. Sent several reports aside that are not registered by the platform. Want to know how many I heard back from ? 3 in total. Ungrateful work 😮‍💨 cc: @leak_ix
account_circle
Joseph Cox(@josephfcox) 's Twitter Profile Photo

News: I have quit VICE. Me and a small group of Motherboard writers have launched our own company: 404media.co. We'll continue impactful journalism.

If you've ever wanted to support my work, this is the time. Please subscribe monthly/yearly nytimes.com/2023/08/22/bus…

account_circle
Bryce(@bryceabdo) 's Twitter Profile Photo

🔊 access to aka Lizar/Icebot alone is not enough to attribute to the cluster we call .

this capability has been for 💰 for a while & is no longer considered exclusive to core at this pt.

and, the same goes for the loader - fun!

🧊🤖

account_circle
Germán Fernández(@1ZRR4H) 's Twitter Profile Photo

More .MSI files with 0 detections
C2: 107.181.161.200:9999

'Wrapped using MSI Wrapper from www[.]exemsi[.]com'

Sample: bazaar.abuse.ch/sample/eb7ef73…
Related: twitter.com/Gi7w0rm/status…

More #DarkGate .MSI files with 0 detections C2: 107.181.161.200:9999 'Wrapped using MSI Wrapper from www[.]exemsi[.]com' Sample: bazaar.abuse.ch/sample/eb7ef73… Related: twitter.com/Gi7w0rm/status…
account_circle
Gi7w0rm(@Gi7w0rm) 's Twitter Profile Photo

Still up as of today:




tons of loaders.
I do believe this could be a leaking own tools ?
There is at least one PayPal scam script in here as well refering to 777sup .org

tria.ge/230822-3m8ylah…

cc:
NanoBaiter
John Hammond

Still up as of today: #OrcusRAT #XWorm #UltraVNC #AnyDesk tons of loaders. I do believe this could be a #scambaiter leaking own tools ? There is at least one PayPal scam script in here as well refering to 777sup .org tria.ge/230822-3m8ylah… cc: @NanoBaiter @_JohnHammond
account_circle
LeakIX(@leak_ix) 's Twitter Profile Photo

🚨CVE-2023-34124 ( and friends ) - New plugin released for finding vulnerable GMS instances.

Found ~100 vulnerable public instances.

Hosting providers and national CERTs have been notified.

Sources: Rapid7 - attackerkb.com/topics/Vof5fWs…
Thanks: Gi7w0rm

🚨CVE-2023-34124 ( and friends ) - New plugin released for finding vulnerable #SonicWall GMS instances. Found ~100 vulnerable public instances. Hosting providers and national CERTs have been notified. Sources: @rapid7 - attackerkb.com/topics/Vof5fWs… Thanks: @Gi7w0rm
account_circle
Gi7w0rm(@Gi7w0rm) 's Twitter Profile Photo

Burning a :
139.99.32[.]95:8000
with different samples looking like a test environment.

At least 1 time :
tria.ge/230821-prkjxac…

Software used to host this WebDav is likely:
github.com/mar10/wsgidav/

Have fun :)

Burning a #WebDav #TA: 139.99.32[.]95:8000 #opendir with different samples looking like a test environment. At least 1 time #QuasarRAT : tria.ge/230821-prkjxac… Software used to host this WebDav is likely: github.com/mar10/wsgidav/ Have fun :) #infosec
account_circle