8
57
10
7
20
21
7
42
15
14
11
7
[-] kid@sh.itjust.works 3 points 1 week ago

By the messages that they are sending to customers, looks like is related to recent updates to the services, but nothing clear.

[-] kid@sh.itjust.works 2 points 1 month ago

Of course, in the end it is just conflict, and when it spills over into the real world then you have a war. But this is not always the case We have already had disruption in power grids, nuclear plants, hospitals, public offices, critical infrastructure of financial markets (some of them with impact in real lives) without retaliation in the physical world.

Cyberwar, in my perspective, have some nuances. For instance, in a physical conflict, a hostile nation's invasion of my property immediately becomes a state issue. However, this isn't always the case in a cyberwar if a hostile state invades my organization (It's hard to immediately distinguish whether the actor is a nation state, a financially motivated group, hacktivists, or just a guy who eats pizza in his mom's basement). Most of the time, organizations are on their own.

In a cyberwar, espionage is also far more acceptable. This is something the NSA (and FSB/SVR) has been doing for years (against private entities and states). In a way, I understand that it is something similar to what the cold war was (is), but with no boots on the ground.

[-] kid@sh.itjust.works 2 points 1 month ago

I'd better say that states have been doing this.

[-] kid@sh.itjust.works 1 points 1 month ago

Maybe cyber resilience? Quick identify, respond and recover from an incident.

[-] kid@sh.itjust.works 1 points 2 months ago

IoCs from original research:

Hashes

267071df79927abd1e57f57106924dd8a68e1c4ed74e7b69403cdcdf6e6a453b 54/70

d6ac21a409f35a80ba9ccfe58ae1ae32883e44ecc724e4ae8289e7465ab2cf40 54/71

ad4d196b3d85d982343f32d52bffc6ebfeec7bf30553fa441fd7c3ae495075fc

13c017cb706ef869c061078048e550dba1613c0f2e8f2e409d97a1c0d9949346

b376a3a6bae73840e70b2fa3df99d881def9250b42b6b8b0458d0445ddfbc044

Domains

hanagram[.]jpthefinetreats[.]com

caduff-sa[.]chjeepcarlease[.]com

buy-new-car[.]com

carleasingguru[.]com

IP Addresses

91[.]193[.]18[.]120

[-] kid@sh.itjust.works 2 points 2 months ago* (last edited 2 months ago)

IoCs:

IOCs Hashes (SHA-256) Email – 16e6dfd67d5049ffedb8c55bee6ad80fc0283757bc60d4f12c56675b1da5bf61

Docx – 1abf56bc5fbf84805ed0fbf28e7f986c7bb2833972793252f3e358b13b638bb1

Injected ZIP – 95898c9abce738ca53e44290f4d4aa4e8486398de3163e3482f510633d50ee6c

LNK file – d07323226c7be1a38ffd8716bc7d77bdb226b81fd6ccd493c55b2711014c0188

Final ZIP – 94499196a62341b4f1cd10f3e1ba6003d0c4db66c1eb0d1b7e66b7eb4f2b67b6 26/64

Client32.exe – 89f0c8f170fe9ea28b1056517160e92e2d7d4e8aa81f4ed696932230413a6ce1 26/73

URLs and Hostnames yourownmart[.]com/solar[.]txt

firstieragency[.]com/depbrndksokkkdkxoqnazneifidmyyjdpji[.]txt

yourownmart[.]com

firstieragency[.]com

parabmasale[.]com

tapouttv28[.]com

IP Addresses 192[.]236[.]192[.]48

173[.]252[.]167[.]50

199[.]188[.]205[.]15

46[.]105[.]141[.]54

Others Message ID contains: “sendinblue[.]com”

Return Path contains: “sender-sib[.]com”

Source

[-] kid@sh.itjust.works 2 points 2 months ago

For the IoCs, check the original research.

[-] kid@sh.itjust.works 1 points 2 months ago

Unfortunately, this is the really not only for Meta, but most of social platforms, gaming, e-commerce, not to mention gambling.

[-] kid@sh.itjust.works 2 points 2 months ago

Maybe they are using this as propaganda to get resources from west.

[-] kid@sh.itjust.works 2 points 3 months ago

I would like to moderate this community. I believe that cybersec community deserves a place in the fediverse and since this is the largest cybersec comm, it would be a good idea to keep it alive.

view more: ‹ prev next ›

kid

joined 3 months ago
MODERATOR OF