James_inthe_box
2025-05-01

Hear me out..."vibe admining":

"This directory kinda has a lot of files...let's delete some"
"That account feels like too much access...let's remove some..."
"This server seems unhappy...let's reboot it"

2025-05-01

A csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfill addresses:

gist.github.com/silence-is-bes

#retrohunt

2025-04-30

@cR0w @mttaggart @wdormann Betting this means brand new client machines....ergo nothing is tied to the client (cert, etc...).

2025-04-30

@da_667 Never forget:
wired.com/story/the-full-story

It's why I stopped taking .*RSA.* seriously after that.

2025-04-23

@da_667 Also, @jane_0sint has this as #strrat

2025-04-23

@SwiftOnSecurity This is what I use...good on the phone as well in an always open tab...one less app on the device is a good thing.

2025-04-23

@da_667 C2 "header" of the first 5 bites is the same though...so that's something.

2025-04-23

@Ichinin Haha...ouch ;)

2025-04-23

cc @da_667 on traffic

2025-04-22
2025-04-21

@GossiTheDog Wonder what the price will be...

2025-04-21

@GossiTheDog Pretty excited for this...but not excited enough to:

1. Pre-order
2. Buy on release day
3. Buy full price

2025-04-21

@mttaggart I feel like I was ahead of the curve by just closing that browser tab and not opening it again a couple months ago. Bluesky was just not impressive.

2025-04-21
2025-04-21

#malware #opendir ultimately #venomrat + #hvnc:

https://carltonsfile\.com/mor1/ -> https://paste\.ee/d/c7nSA2yM/0

c2: 109.248.144.175:4449

4541fd01a19f1e484f24eff86f42ac36ea9b30686fd405ca0a50f3e517657a61

2025-04-20

@r3dbU7z Good find.

2025-04-18

@jgreig Good.

2025-04-17

@wdormann Spellcheck/formcheck/AI check?

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst