cyberundergroundfeed
@cyberfeeddigest
I deliver daily #DarkWeb ,#DeepWeb and #CTI feeds,and a bit of geopolitical clashes #Darkweb #Deepweb #Ransomware #Malware #Databreach #CTI #ThreatIntel
๐งญ #Opendir Find: 99 Sysinternals EXEs on Exposed IP โ 163[.]172[.]38[.]6 ๐ Public directory hosting 99 .EXE files from !sysinternals: hxxp://163[.]172[.]38[.]6/tools/!sysinternals/ โ ๏ธ Likely useful for red teams, malware devs, or analysts โ handle with caution. #Malwareโฆ
![cyberfeeddigest's tweet image. ๐งญ #Opendir Find: 99 Sysinternals EXEs on Exposed IP โ 163[.]172[.]38[.]6
๐ Public directory hosting 99 .EXE files from !sysinternals:
hxxp://163[.]172[.]38[.]6/tools/!sysinternals/
โ ๏ธ Likely useful for red teams, malware devs, or analysts โ handle with caution.
#Malwareโฆ](https://pbs.twimg.com/media/GwzYsu4XkAAsyRm.jpg)
๐ #Turkish Educational Website #Defaced by #LegionLeakers Hacker EbRaHiM-VaKeR ๐น๐ท An educational site from #Turkey was allegedly #Hacked by Notifier: EbRaHiM-VaKeR of the LegionLeakers team. ๐ฏ Target: ๐ hxxps://decem[.]deu[.]edu[.]tr/ ๐ The defacement showcases continuedโฆ
![cyberfeeddigest's tweet image. ๐ #Turkish Educational Website #Defaced by #LegionLeakers Hacker EbRaHiM-VaKeR ๐น๐ท
An educational site from #Turkey was allegedly #Hacked by Notifier: EbRaHiM-VaKeR of the LegionLeakers team.
๐ฏ Target:
๐ hxxps://decem[.]deu[.]edu[.]tr/
๐ The defacement showcases continuedโฆ](https://pbs.twimg.com/media/Gw7QjBEWkAAEahB.jpg)
๐ง๐ช #NoName057 Launches #DDOS Barrage on #Belgium Gov & Public Services ๐ฅ The pro-Russian group #NoName057 has allegedly targeted major #Belgian infrastructure with coordinated DDoS attacks: โ National Social Security Office ๐โฆ

๐ #Thai Gov Website #Defaced by ./KeyzNet ๐น๐ญ A governmental site in #Thailand was allegedly #Hacked by defacer ./KeyzNet. ๐ Target: huaihosp[.]go[.]th/nero.html ๐ป DEFANG your clicks โ mirror of the defacement is still live. ๐ #CyberSecurity #Thailand #Defacement #KeyzNetโฆ
![cyberfeeddigest's tweet image. ๐ #Thai Gov Website #Defaced by ./KeyzNet ๐น๐ญ
A governmental site in #Thailand was allegedly #Hacked by defacer ./KeyzNet.
๐ Target: huaihosp[.]go[.]th/nero.html
๐ป DEFANG your clicks โ mirror of the defacement is still live.
๐ #CyberSecurity #Thailand #Defacement #KeyzNetโฆ](https://pbs.twimg.com/media/Gw44XqlXwAAgRg4.jpg)
๐จ #ARES Group Allegedly #Breached Former Police Base in Sochi ๐ท๐บ โ 47M+ Detailed Personal Records A massive and previously unpublished #DataLeak from a former police database used by specialized services in #Sochi, #Russia ๐ท๐บ is allegedly up for sale on a #Darkweb forum. ๐ฆโฆ

๐จ #ARES Group Leaks Massive ๐ท๐บ #Russia E-Commerce Data | 62M+ Records from 119 Stores A member of a #Darkweb forum allegedly #Breached 62,143,571 records from Russian logistics company Sberlogistics (source: hxxps://sberlogistics[.]ru) โ tied to 119 major online stores,โฆ
![cyberfeeddigest's tweet image. ๐จ #ARES Group Leaks Massive ๐ท๐บ #Russia E-Commerce Data | 62M+ Records from 119 Stores
A member of a #Darkweb forum allegedly #Breached 62,143,571 records from Russian logistics company Sberlogistics (source: hxxps://sberlogistics[.]ru) โ tied to 119 major online stores,โฆ](https://pbs.twimg.com/media/Gw3Yk5jWUAEluYi.jpg)
๐จ #NoName057 Strikes Again: Wave of #DDOS Attacks on #Germany Transport & Tax Infrastructure The pro-Russian group #NoName057 has allegedly launched coordinated DDoS attacks targeting key ๐ฉ๐ช #German transport & financial systems: โ WestfalenBahn GmbH ๐โฆ

๐ต๏ธโโ๏ธ 1M+ Users Exposed in Alleged #Breach of #Russian Legal Consultation Platform A member of a #Darkweb forum claims to have leaked a database of 1 million+ users from a ๐ท๐บ Russian online legal consultation service. ๐ Allegedly exposed fields include: Full Name, Birthday,โฆ

๐ฅ #DDOS Campaign Hits Major Institutions in #Azerbaijan โ Banks & Airport Disrupted A wave of denial-of-service attacks has reportedly targeted key Azerbaijani entities: ๐ซ International Bank of Azerbaijan (IBA) ๐ hxxps://check-host[.]net/check-report/2a79e0f2k199 ๐โฆ
![cyberfeeddigest's tweet image. ๐ฅ #DDOS Campaign Hits Major Institutions in #Azerbaijan โ Banks & Airport Disrupted
A wave of denial-of-service attacks has reportedly targeted key Azerbaijani entities:
๐ซ International Bank of Azerbaijan (IBA)
๐ hxxps://check-host[.]net/check-report/2a79e0f2k199
๐โฆ](https://pbs.twimg.com/media/Gw3QO80WcAAnQAK.jpg)
๐งฐ #Sysinternals PsTools Suite #Opendir Discovered on Czech Domain โ Packed with EXEs A directory hosted on ๐จ๐ฟ 29980xg[.]257[.]cz exposes the full PsTools v1.60 suite: ๐ hxxp://29980xg[.]257[.]cz/dl/programy/!Sysinternals/PsTools160/ ๐ฆ Notable .EXE files: psexec.exe,โฆ
![cyberfeeddigest's tweet image. ๐งฐ #Sysinternals PsTools Suite #Opendir Discovered on Czech Domain โ Packed with EXEs
A directory hosted on ๐จ๐ฟ 29980xg[.]257[.]cz exposes the full PsTools v1.60 suite:
๐ hxxp://29980xg[.]257[.]cz/dl/programy/!Sysinternals/PsTools160/
๐ฆ Notable .EXE files:
psexec.exe,โฆ](https://pbs.twimg.com/media/Gw2cEybWUAA5xlO.jpg)
๐งฐ Live Sysinternals #Opendir Exposed on #Switzerland Domain โ 75 .EXE Files for Analysis A directory hosted on ๐จ๐ญ riskmitigation[.]ch appears to mirror live.sysinternals.com: ๐ hxxps://riskmitigation[.]ch/live.sysinternals.com/ ๐ Contains: 75 .EXE files ๐ Valuable forโฆ
![cyberfeeddigest's tweet image. ๐งฐ Live Sysinternals #Opendir Exposed on #Switzerland Domain โ 75 .EXE Files for Analysis
A directory hosted on ๐จ๐ญ riskmitigation[.]ch appears to mirror live.sysinternals.com:
๐ hxxps://riskmitigation[.]ch/live.sysinternals.com/
๐ Contains: 75 .EXE files
๐ Valuable forโฆ](https://pbs.twimg.com/media/Gw2bB0qWkAAf1tu.jpg)
๐ฅ #NoName057 Launches #DDOS Wave on #Italy โ Gov & Military Sites Hit The pro-Russian group #NoName057 allegedly targeted several key ๐ฎ๐น Italian portals with #DDOS attacks: โ Municipality of Emaville โ Projects of Milan Municipality โ City of Catania โ Italian Air Forceโฆ

๐จ #Indonesia Maritime Comms Provider "Amalgam Indocorpora" Allegedly #Breached โ 6.4M Records Leaked A member of a #Darkweb forum claims to have leaked a 2GB MariaDB SQL dump from ๐ฎ๐ฉ Amalgam Indocorpora ๐ hxxp://www[.]amalgam[.]co[.]id/ ๐๏ธ Leak Date: June 26, 2023 ๐ฆ Data:โฆ
![cyberfeeddigest's tweet image. ๐จ #Indonesia Maritime Comms Provider "Amalgam Indocorpora" Allegedly #Breached โ 6.4M Records Leaked
A member of a #Darkweb forum claims to have leaked a 2GB MariaDB SQL dump from ๐ฎ๐ฉ Amalgam Indocorpora
๐ hxxp://www[.]amalgam[.]co[.]id/
๐๏ธ Leak Date: June 26, 2023
๐ฆ Data:โฆ](https://pbs.twimg.com/media/Gw2VWYrXMAACriW.jpg)
๐ต #TeaForWomen App Breach โ 59.3GB User Database Allegedly #Leaked A member of a #Darkweb forum claims to have #breached the database of TeaForWomen[.]com, a women's social networking & dating platform. ๐งฉ Data Size: 59.3GB ๐ฑ Platform: Tea App / TeaForWomen[.]com ๐ Allegedlyโฆ
![cyberfeeddigest's tweet image. ๐ต #TeaForWomen App Breach โ 59.3GB User Database Allegedly #Leaked
A member of a #Darkweb forum claims to have #breached the database of TeaForWomen[.]com, a women's social networking & dating platform.
๐งฉ Data Size: 59.3GB
๐ฑ Platform: Tea App / TeaForWomen[.]com
๐ Allegedlyโฆ](https://pbs.twimg.com/media/Gw2UgN1WUAA_MJd.jpg)
๐ฐ #Malaysia Gov Archive Website #Hacked by "Black Rabbit" Defacer ๐จ Government domain targeted: hxxps://mygwa[.]arkib[.]gov[.]my/snoopdog.php โ๏ธ Defaced by: Black Rabbit ๐ฏ Affiliation: black rabbit team #CyberAttack #Defacement #Hacktivism #Malaysia #Infosec
![cyberfeeddigest's tweet image. ๐ฐ #Malaysia Gov Archive Website #Hacked by "Black Rabbit" Defacer
๐จ Government domain targeted:
hxxps://mygwa[.]arkib[.]gov[.]my/snoopdog.php
โ๏ธ Defaced by: Black Rabbit
๐ฏ Affiliation: black rabbit team
#CyberAttack #Defacement #Hacktivism #Malaysia #Infosec](https://pbs.twimg.com/media/Gw2IzbvXUAAusmJ.jpg)
๐ฐ #Indonesia Gov Mail Portal Hacked by "Black Rabbit" #Defacer The site: hxxps://mailprov[.]acehprov[.]go[.]id/slick.php was allegedly defaced by hacker Black Rabbit of team black rabbit. ๐ Target: Government domain ๐ Country: #Indonesia #CyberAttack #Defacement #Hacktivismโฆ
![cyberfeeddigest's tweet image. ๐ฐ #Indonesia Gov Mail Portal Hacked by "Black Rabbit" #Defacer
The site:
hxxps://mailprov[.]acehprov[.]go[.]id/slick.php
was allegedly defaced by hacker Black Rabbit of team black rabbit.
๐ Target: Government domain
๐ Country: #Indonesia
#CyberAttack #Defacement #Hacktivismโฆ](https://pbs.twimg.com/media/Gw2IXQ_X0AA1OVC.jpg)
๐ฅ #Pakistani Educational Site #Hacked by #Iranian Group "MrVGunz [!]" The website of HF College of Nursing โ hxxps://hfcon[.]edu[.]pk/ โ was allegedly #defaced by Iranian hackers. ๐ ๏ธ Defacement message signed by MrVGunz [!] ๐ Target: #Pakistan education sector #CyberAttackโฆ
![cyberfeeddigest's tweet image. ๐ฅ #Pakistani Educational Site #Hacked by #Iranian Group "MrVGunz [!]"
The website of HF College of Nursing โ
hxxps://hfcon[.]edu[.]pk/ โ was allegedly #defaced by Iranian hackers.
๐ ๏ธ Defacement message signed by MrVGunz [!]
๐ Target: #Pakistan education sector
#CyberAttackโฆ](https://pbs.twimg.com/media/Gw2HtHfWAAAN3Fs.jpg)
๐ข TVU #DataLeak: ~100K Student Records from #Iran University #Breached A #Darkweb forum member allegedly #breached ๐ฎ๐ท Iranโs Technical & Vocational University (TVU) โ leaking a 24.8MB CSV/TXT export with ~100,000 student records. ๐ฏ Target: bustan[.]nus[.]ac[.]ir (Studentโฆ
![cyberfeeddigest's tweet image. ๐ข TVU #DataLeak: ~100K Student Records from #Iran University #Breached
A #Darkweb forum member allegedly #breached ๐ฎ๐ท Iranโs Technical & Vocational University (TVU) โ leaking a 24.8MB CSV/TXT export with ~100,000 student records.
๐ฏ Target: bustan[.]nus[.]ac[.]ir (Studentโฆ](https://pbs.twimg.com/media/Gwz98Y4WcAIvlEj.jpg)