toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

227
active users

#nanocore

0 posts0 participants0 posts today
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://hostsharing.coop/@cdonat" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>cdonat</span></a></span> <span class="h-card" translate="no"><a href="https://toots.ch/@dalai" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>dalai</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@ip6li" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ip6li</span></a></span> also ich würde darüber garnicht erst diskutieren:</p><p>Entweder fliegt sower hochkant und ich krieg' den Job &amp; Gehalt oder ich gehe und das <a href="https://infosec.space/tags/BSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BSI</span></a> zerlegt den Laden so heftig dass keiner der CxO's mehr irgendwo nen Job bekommt, noch nichtmals als Lieferfahrer*in!</p><p><a href="https://infosec.space/@kkarhan/114621798932871398" translate="no" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1146217</span><span class="invisible">98932871398</span></a></p><p>Ich meine wo kommen wir da hin? Leute die <a href="https://infosec.space/tags/NanoCore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NanoCore</span></a> unsarkastisch zur <a href="https://infosec.space/tags/Administration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Administration</span></a> von <em>'<a href="https://infosec.space/tags/WindowsServer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WindowsServer</span></a>"</em> nutzen?</p><p><a href="https://infosec.space/tags/NotLegalAdvice" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NotLegalAdvice</span></a> <a href="https://infosec.space/tags/Sarkasmus" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sarkasmus</span></a> <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a> <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a></p>
SarlackLab<p>live <a href="https://ioc.exchange/tags/nanocore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nanocore</span></a> <a href="https://ioc.exchange/tags/C2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C2</span></a> server<br>157.97.11[.]134:80</p><p>confirmed 2025-01-28</p>
SarlackLab<p>live <a href="https://ioc.exchange/tags/nanocore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nanocore</span></a> <a href="https://ioc.exchange/tags/C2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C2</span></a> server<br>78.148.197[.]237:54984<br>josh289232[.]duckdns[.]org<br>confirmed 2024-10-20</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@stman" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>stman</span></a></span> <a href="https://infosec.space/tags/NSOgroup" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NSOgroup</span></a> are <a href="https://infosec.space/tags/CyberMercenaries" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberMercenaries</span></a> and in their actions ain't better than <a href="https://infosec.space/tags/CyberCriminals" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberCriminals</span></a> like <a href="https://infosec.space/tags/RacoonStealer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RacoonStealer</span></a> or Skiddies reselling hosted versions of <a href="https://infosec.space/tags/NanoCore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NanoCore</span></a> on the DarkWebz...</p>
Not Simon<p><strong>Fortinet</strong> reports on a recent phishing campaign containing Scalable Vector Graphics (SVG) files. The malicious attachment downloads a ZIP file and begins the infection chain. ScrubCrypt, described as an "antivirus evasion tool", is used to load the final payload VenomRAT while maintaining a connection with the C2 server to install plugins like XWorm, NanoCore, RemcosRAT and a crypto wallet stealer. They provides detailed insights into how the threat actor distributes VenomRAT and other plugins. IOC listed. 🔗 <a href="https://www.fortinet.com/blog/threat-research/scrubcrypt-deploys-venomrat-with-arsenal-of-plugins" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">fortinet.com/blog/threat-resea</span><span class="invisible">rch/scrubcrypt-deploys-venomrat-with-arsenal-of-plugins</span></a></p><p><a href="https://infosec.exchange/tags/ScrubCrypt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ScrubCrypt</span></a> <a href="https://infosec.exchange/tags/VenomRAT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VenomRAT</span></a> <a href="https://infosec.exchange/tags/RemcosRAT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RemcosRAT</span></a> <a href="https://infosec.exchange/tags/XWorm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XWorm</span></a> <a href="https://infosec.exchange/tags/NanoCore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NanoCore</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>threatintel</span></a> <a href="https://infosec.exchange/tags/IOC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IOC</span></a></p>
SarlackLab<p>live <a href="https://ioc.exchange/tags/nanocore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nanocore</span></a> <a href="https://ioc.exchange/tags/C2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C2</span></a> server</p><p>patyneduchez3212[.]duckdns[.]org<br>confirmed 2023-07-09</p>
SarlackLab<p>live <a href="https://ioc.exchange/tags/nanocore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nanocore</span></a> <a href="https://ioc.exchange/tags/C2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C2</span></a> server<br>185.252.179[.]198:8282</p><p>confirmed 2023-07-09</p>
Kevin Karhan :verified:<p><span class="h-card"><a href="https://toot.site/@katnjiapus" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>katnjiapus</span></a></span> <span class="h-card"><a href="https://fosstodon.org/@suprjami" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>suprjami</span></a></span> <span class="h-card"><a href="https://tilde.zone/@aks" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>aks</span></a></span> you can with <a href="https://mstdn.social/tags/NanoCore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NanoCore</span></a>!</p>
SarlackLab<p>live <a href="https://ioc.exchange/tags/nanocore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nanocore</span></a> <a href="https://ioc.exchange/tags/C2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C2</span></a> server<br>198.12.123[.]17:6700<br>celesperial[.]ddns[.]net<br>confirmed 2023-06-11</p>