Source Byte
Открыть в Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Больше8 146
Подписчики
+2124 часа
+707 дней
+31530 день
Архив постов
8 151
According to Israeli sources (who obtained a copy of the AFTA report on the recent Sepah Bank attack by Indra):
[00] The attacker gained access through an old Windows Server 2003 machine used for email services. This server was running MDaemon.
Note: The source stated that the specific mail server was server[.]ictops[.]ir, but we found no public records of this domain. It is likely a local/internal domain used by the bank, which reduces the likelihood that this server was the initial entry point in this attack.
[01] The attacker moved Lateral to other servers (no evidence on how this was done).
[02] They reached the targeted server and deployed their C2 (NjRat) via a PowerShell script.
Note : The C2 server was hosted in Canada.
that's all we know :(
i created a chart for better understanding
wish it helps
PDF version :
8 151
Untill now We shared :
[ 00 ] Attack Against Iran’s State Broadcaster (done by Ghyam Sarnegouni TA )
[ 01 ] Indra (گنجشگ درنده) samples related to attacks on Iran Railway Company & some Companies on syria ( related to I.R.G.C )
find them on Samples Topic on Group
Plz share us your IoCs related to current attacks against Iran it will help everyone prepping for Threat Actors as currently we don't have any global CTI
8 151
1FuckiRGCTerroristsNoBiTEXXXaAovLX
DFuckiRGCTerrroristsNoBiTEXXXWLW65t
TKFuckiRGCTerroristsNoBiTEXy2r7mNX
8 151
Repost from Nobitex | نوبیتکس
اطلاعیه در خصوص حادثه امنیتی
صبح امروز ۲۸ خرداد، تیم فنی ما نشانههایی از دسترسی غیرمجاز به بخشی از زیرساختهای اطلاعرسانی و کیف پول گرم را شناسایی کرده است. بلافاصله پس از تشخیص، تمام دسترسیها متوقف شد و تیمهای امنیتی داخلی ما در حال بررسی دقیق ابعاد این حادثه هستند.
یادآور میشویم دارایی کاربران مطابق استانداردهای ذخیره سرد در امنیت کامل است و حادثه فوق فقط بخشی از دارایی کیفپولهای گرم را تحت تاثیر قرار داده است.
نوبیتکس مسئولیت کامل این حادثه را پذیرفته و به کاربران اطمینان میدهیم که تمام خسارات احتمالی از طریق صندوق بیمه و منابع نوبیتکس جبران خواهد شد.
تا زمان بررسی کامل، به طور موقت، دسترسی وبسایت و اپلیکیشن وجود ندارد.
همچنین جزئیات بیشتر ، پس از تکمیل بررسیها، منتشر خواهد شد.
از اعتماد و صبوری شما سپاسگزاریم.
8 151
+1
LOL , IDF says we targeted two F-14
I just check google earth location and find out these were decoys , they have been there since 2022
😂😂
Location :
35.69468, 51.33251
8 151
Signature Kid is a header only tool that steals a signature from a file and copy it to whathever file you want.
Beyond Stealing, Signature Kid goes a step further by Windows Internal to trick the system to treat the copied signature as valid.
https://github.com/dslee2022/SignatureKid
