@21code_talker34

💻️勉強中🖊️📖 AI🧠🤖,Cybersecurity🖥️🔑

🇯🇵
Joined April 2025
【Xの翻訳機能が、Grokへ】 これまでのように原文と訳文を併記してほしい.....
7
719
コード retweeted
Mentioned 'ssce5532.dll' as a #PlugX related sample uploaded @abuse_ch bazaar.abuse.ch/sample/1279f…
🚨 Mustang Panda Uses OIC Invitation to Deliver PlugX The infection begins with OIC_Invitation_General_Official.lnk, which launches PowerShell to download an archive, extract its contents, and execute GRrte.exe. 📦 🎭 The malware displays an OIC-themed PDF decoy in Adobe Acrobat while a Jarte-derived executable is abused to load the attacker-controlled ssce5532.dll through DLL side-loading. 🔍 The side-loaded DLL searches the local payload set and works with irun.dat — an XOR-obfuscated payload that decrypts with key 0x72, exposing an embedded PE image associated with the final PlugX stage. ⚙️ The malware installs its operational components under C:\Users\Public\JartePortable\ and establishes persistence through: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\JartePortable 🌐 The persisted Jarte.exe communicates over TCP/443 with infrastructure associated with castanaksa[.]com, providing capabilities including remote execution, file management, process control, host discovery, registry manipulation, and network communications. 🎯 The OIC-themed lure may indicate an attempt to attract recipients interested in Organization of Islamic Cooperation-related affairs, although the analyzed sample alone does not establish the exact victim profile. 🔎 Full analysis: buff.ly/xZo9K7f #MustangPanda #PlugX #Malware #ThreatIntel #CyberSecurity #APT #DFIR
4
1
8
1,177
いつもの
2026年8月のサイバーセキュリティレポートを発行しました。 ・米政府、民間企業による対サイバー犯罪攻撃制度を創設へ ・ロシア系APTによる公共Wi-Fi悪用攻撃「CaptiveCrunch」 ・中国系ルーターのバックドア事案が示した通信機器リスク jp.security.ntt/insights_res… #CSR #CyberSecurityReport #CyberSecurity #NTTSecurity
20
コード retweeted
Infrastructure linked to ShadowPad has been observed using TLS certificates impersonating well-known companies for years. 79.133.56[.]90, identified as a ShadowPad fallback C&C server in @proofpoint 's recent BlueMoon research revealed a self-signed certificate with an issuer and subject common name of "Google LLC." Pivoting on this name and the JA4x fingerprint (2bab15409345_2bab15409345_5318375af521) returned 8 IPs, some dating back to late 2024. The most recent servers returned from the query: 64.118.130[.]140 (AS138997) - qnap-connect[.]com - requests[.]it[.]com 223.26.61[.]236 (AS152194) - dns.asusrouterapi[.]com - dns.microsoftstoreapi[.]com 31.192.107[.]162 (AS50867) - work.officialm[.]com 157.20.182[.]150 (AS152485) 64.7.199[.]26 (AS399629)
3
17
64
3,859
コード retweeted
GPT-6 Astra is state-of-the-art on FrontierMath Tier 4, ARC-AGI 3, and TerminalBench-4.0. GPT‑6 Astra is also a major advance for scientific discovery, with state-of-the-art performance on Terminal-Bench Science 0.1 and HealthBench Pro.
206
1,103
1,038
10,307
5,323,969
キター!
This is GPT-6 Astra. Anything you can do on a computer, Astra can do for you. Fast.
28
コード retweeted
日本語ばらまきマルウェアメールの接到を観測しています。『観測数多めです』 件名 : 【全社通知】給与改定および人事異動について 件名 : 【ご挨拶】製品の直接仕入れ・お取引検討に関するご連絡/社名 など。。。 Sample : tria.ge/260902-brmglsej3w/be… C2 : 204.194.50[.]231 #valleyRAT
19
1
34
4,027
We identified multiple LNK samples showing strong technical and thematic overlap with recent #Kimsuky activity described by ENKI WhiteHat. The campaign targeted South Korean and Japanese victims through phishing emails delivering OneDrive-hosted ZIP archives containing malicious LNK files. The identified LNK samples use suspicious command-line execution, embedded/script-like content, URL-based payload retrieval, and in several cases unusually large LNK files. Further pivoting uncovered multiple samples matching the THOR/Valhalla rule: SUSP_LNK_SuspiciousCommands_Jan23_3 The overlap is particularly interesting because the reported Kimsuky chain uses a malicious LNK to execute PowerShell and curl, download logo.png as bot.vbe into %APPDATA%, and execute the VBScript. The broader campaign then establishes persistence through a scheduled task and deploys additional PowerShell-based capabilities for system discovery, Thunderbird/Outlook email collection, keylogging, and installation of legitimate remote-access tools including Chrome Remote Desktop and AnyDesk. Several of the samples we identified also use Japanese/Korean-themed filenames and exhibit LNK characteristics including url-pattern, long-command-line-arguments, large-file, high-entropy, and executes-dropped-file. Valhalla / THOR Rules: SUSP_LNK_SuspiciousCommands_Jan23_3 valhalla.nextron-systems.com… SUSP_LNK_Dec24 valhalla.nextron-systems.com… SUSP_LNK_Curl_Download_Jul22_2 valhalla.nextron-systems.com… SUSP_LNK_Big_Link_File valhalla.nextron-systems.com… SUSP_Dir_Ref_in_File_AppData valhalla.nextron-systems.com… Report: enki.co.kr/en/media-center/b… Samples: 6e6addf3e7287cf160054ef4647f8c67754f3cdc6efbdf21f117cb98c4c95534 49000d685f7c2ae1ddd5d40ca754562318e49c3a2534540951490f22756a3227 44dc1939dcaea681f5c39ed6f5f81a80ca5f59e72be7f938ac3afe5adb484042 018c31af135a0bc5e068df26d866440b28164aa4a659ea7df47bcbaab4a898cd 864ed6df1ba1b615f2db460666e2aee72a025754f5d78be3d83ec8e3c41d4a09 169586b6eb36b17520ef5afd206da86c4de89eb01d6294ba9631414271ba752f
1
32
1
73
7,364
コード retweeted
ValleyRAT is a signed adware-backed backdoor that uses DLL sideloading, disables defenses, and loads encrypted payloads to exfiltrate keystrokes, screenshots, and system data, with Silver Fox likely behind it. securelist.com/valleyrat-bac…
2
11
1,073
コード retweeted
We asked an unreleased research version of Claude to take a stab at the Riemann hypothesis. It didn’t solve it, but it did make strides on a related problem: it increased the lower bound for the fraction of zeros of the Riemann zeta function that satisfy the hypothesis from 41.6% to 67.2%. anthropic.com/research/riema…
939
2,001
1,338
18,301
10,314,406
【Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia】 We identified several Kimsuky spear phishing campaigns against South Korean and Japanese targets in the first half of 2026. enki.co.kr/en/media-center/b…
1
2
186
IoC(IP) ・103.77.242[.]187  →VPSMMO COMPANY LIMITED ・160.187.147[.]119  →INTERDIGI JOINT STOCK COMPANY ・84.247.145[.]65  →Contabo Asia Private Limited ・210.183.177[.]217  →Korea Telecom ・103.249.117[.]183  →FUTE JOINT STOCK COMPANY
1
2
164
IoC ・sweet-iki-4263.holy[.]jp  → 118.27.125[.]235(GMO Internet, Inc.)
1
41
コード retweeted
The ENKI WhiteHat Threat Research Team has identified a number of recent Kimsuky spear-phishing cases against South Korean and Japanese targets. The threat actor spread LNK malware through phishing emails carrying OneDrive share links. enki.co.kr/en/media-center/b…
1
11
53
2,639
コード retweeted
日本語マルウェアメールの接到を確認しています。 #ValleyRAT 件名: 【お見積り依頼】商品調達に関するご相談(添付資料あり)  【お見積り・お取引のご相談】新規調達に関するお問い合わせ 添付ファイル: 20260824[.]zip  20260824.img 通信先: 202[.]61[.]140[.]222:448
1
6
1
7
1,694