Sourajeet 🔍
@soursecc
Security Researcher @cloudsek, All views personal
🧵#AePS (Aadhaar Enabled Payment System) based frauds & Leakage of #Biometrics from State Government site #Aadhaar #privacy #security #hacking

Fresh ClickFix IoC : /clasoftmedia[.]ci /retcap[.]eu /rafelink[.]life /akwatic-hotel[.]ci /bleulab[.]ci /gomezmontero[.]eu /gtl[.]ci /javiergomezmontero[.]eu /ardiellifornasa[.]ge #IoC #ClickFix | #ThreatHunting #Validin cc : @500mk500 @MichalKoczwara @skocherhan @1ZRR4H
![soursecc's tweet image. Fresh ClickFix IoC :
/clasoftmedia[.]ci
/retcap[.]eu
/rafelink[.]life
/akwatic-hotel[.]ci
/bleulab[.]ci
/gomezmontero[.]eu
/gtl[.]ci
/javiergomezmontero[.]eu
/ardiellifornasa[.]ge
#IoC #ClickFix | #ThreatHunting #Validin
cc : @500mk500 @MichalKoczwara @skocherhan @1ZRR4H](https://pbs.twimg.com/media/GwK97qqXsAAiaiY.jpg)
![soursecc's tweet image. Fresh ClickFix IoC :
/clasoftmedia[.]ci
/retcap[.]eu
/rafelink[.]life
/akwatic-hotel[.]ci
/bleulab[.]ci
/gomezmontero[.]eu
/gtl[.]ci
/javiergomezmontero[.]eu
/ardiellifornasa[.]ge
#IoC #ClickFix | #ThreatHunting #Validin
cc : @500mk500 @MichalKoczwara @skocherhan @1ZRR4H](https://pbs.twimg.com/media/GwK-YG5bgAAWRbt.png)
ClickFix IoC : generali-fx[.]com generali-fx[.]com/cloudfare #IoCs #ClickFix | #Censys #ThreatHunting cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H
![soursecc's tweet image. ClickFix IoC :
generali-fx[.]com
generali-fx[.]com/cloudfare
#IoCs #ClickFix | #Censys #ThreatHunting
cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H](https://pbs.twimg.com/media/GwA6xbfbkAMzsTm.jpg)
![soursecc's tweet image. ClickFix IoC :
generali-fx[.]com
generali-fx[.]com/cloudfare
#IoCs #ClickFix | #Censys #ThreatHunting
cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H](https://pbs.twimg.com/media/GwA6ziObkAAjuD2.png)
ClickFix IoC : hrdepartments[.]org #IoCs #ClickFix | #Censys #ThreatHunting cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H
![soursecc's tweet image. ClickFix IoC :
hrdepartments[.]org
#IoCs #ClickFix | #Censys #ThreatHunting
cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H](https://pbs.twimg.com/media/Gv4bKk7WcAAnici.jpg)
![soursecc's tweet image. ClickFix IoC :
hrdepartments[.]org
#IoCs #ClickFix | #Censys #ThreatHunting
cc : @500mk500 @skocherhan @MichalKoczwara @malwrhunterteam @1ZRR4H](https://pbs.twimg.com/media/Gv4bPuvWYAAvTpU.jpg)
Fresh similar ones : /meet.google.webconnect58[.]com/ktb-gkc-xha /meet.google.web-connect[.]us /meet.google.webconnect49[.]com/krk-rvc-xwh/ /www.meet.google.webconnect88[.]com /meet.google.webconnect11[.]com #IoCs | #ThreatHunting #Censys cc : @500mk500 @moonlock_lab
Thanks for sharing! Looks like this domain plays a key role in this campaign too: meet[.]google[.]webconnect49[.]com We will be taking a closer look as well 👀
Phishing pages targeting @VALORANT gamers : /valorantid.ikwb[.]com/verify[.]php /valorantidn.duckdns[.]org/verify[.]php #IoCs #Valorant | #ThreatHunting #Censys cc: @500mk500
![soursecc's tweet image. Phishing pages targeting @VALORANT gamers :
/valorantid.ikwb[.]com/verify[.]php
/valorantidn.duckdns[.]org/verify[.]php
#IoCs #Valorant | #ThreatHunting #Censys
cc: @500mk500](https://pbs.twimg.com/media/Gv1Uhg3WEAAhzKc.jpg)
![soursecc's tweet image. Phishing pages targeting @VALORANT gamers :
/valorantid.ikwb[.]com/verify[.]php
/valorantidn.duckdns[.]org/verify[.]php
#IoCs #Valorant | #ThreatHunting #Censys
cc: @500mk500](https://pbs.twimg.com/media/Gv1UrDZa4AEGuLD.jpg)
![soursecc's tweet image. Phishing pages targeting @VALORANT gamers :
/valorantid.ikwb[.]com/verify[.]php
/valorantidn.duckdns[.]org/verify[.]php
#IoCs #Valorant | #ThreatHunting #Censys
cc: @500mk500](https://pbs.twimg.com/media/Gv1U_dKa4AIQ8YI.jpg)
Fresh IoCs for #ClickFix impersonating @bookingcom - 77.105.164[.]95/s/59ed1342-898f-4455-a521-dc4b737b6aea - booking.extranethelpid612[.]com - admin.extra-book3[.]com #IoCs | #Censys #ThreatHunting cc : @500mk500 @malwrhunterteam @MichalKoczwara @skocherhan @1ZRR4H
![soursecc's tweet image. Fresh IoCs for #ClickFix impersonating @bookingcom
- 77.105.164[.]95/s/59ed1342-898f-4455-a521-dc4b737b6aea
- booking.extranethelpid612[.]com
- admin.extra-book3[.]com
#IoCs | #Censys #ThreatHunting
cc : @500mk500 @malwrhunterteam @MichalKoczwara @skocherhan @1ZRR4H](https://pbs.twimg.com/media/GvsixzrWcAACHZ7.jpg)
![soursecc's tweet image. Fresh IoCs for #ClickFix impersonating @bookingcom
- 77.105.164[.]95/s/59ed1342-898f-4455-a521-dc4b737b6aea
- booking.extranethelpid612[.]com
- admin.extra-book3[.]com
#IoCs | #Censys #ThreatHunting
cc : @500mk500 @malwrhunterteam @MichalKoczwara @skocherhan @1ZRR4H](https://pbs.twimg.com/media/GvsjB4qWQAAzeST.jpg)
![soursecc's tweet image. Fresh IoCs for #ClickFix impersonating @bookingcom
- 77.105.164[.]95/s/59ed1342-898f-4455-a521-dc4b737b6aea
- booking.extranethelpid612[.]com
- admin.extra-book3[.]com
#IoCs | #Censys #ThreatHunting
cc : @500mk500 @malwrhunterteam @MichalKoczwara @skocherhan @1ZRR4H](https://pbs.twimg.com/media/GvsjRSbWgAAG00j.jpg)
Possible Scattered Spider Infra Targeting @iconectiv🕷️ /18.219.115[.]252 #IoCs #ScatteredSpider | #ThreatHunting #Censys cc : @500mk500 @MichalKoczwara @skocherhan @volrant136 @malwrhunterteam
![soursecc's tweet image. Possible Scattered Spider Infra Targeting @iconectiv🕷️
/18.219.115[.]252
#IoCs #ScatteredSpider | #ThreatHunting #Censys
cc : @500mk500 @MichalKoczwara @skocherhan @volrant136 @malwrhunterteam](https://pbs.twimg.com/media/Gvm74C4XwAAAQzA.jpg)
![soursecc's tweet image. Possible Scattered Spider Infra Targeting @iconectiv🕷️
/18.219.115[.]252
#IoCs #ScatteredSpider | #ThreatHunting #Censys
cc : @500mk500 @MichalKoczwara @skocherhan @volrant136 @malwrhunterteam](https://pbs.twimg.com/media/Gvm74twWwAAWenm.jpg)
![soursecc's tweet image. Possible Scattered Spider Infra Targeting @iconectiv🕷️
/18.219.115[.]252
#IoCs #ScatteredSpider | #ThreatHunting #Censys
cc : @500mk500 @MichalKoczwara @skocherhan @volrant136 @malwrhunterteam](https://pbs.twimg.com/media/Gvm75PPXAAA2qHe.jpg)
![soursecc's tweet image. Possible Scattered Spider Infra Targeting @iconectiv🕷️
/18.219.115[.]252
#IoCs #ScatteredSpider | #ThreatHunting #Censys
cc : @500mk500 @MichalKoczwara @skocherhan @volrant136 @malwrhunterteam](https://pbs.twimg.com/media/Gvm77nJXMAArlgc.jpg)