If anyone who are using RIC will catching any gaps, notify me please.
Please open Telegram to view this post
VIEW IN TELEGRAM
😎3❤1👏1
New researched malicious campaign from Proofpoint researchers, detected integrating credential phishing and cloud account takeover (ATO) techniques...
This campaign contains multiple endpoints which also included domains used as malicious infrastructure...
So - All malicious infrastructure domains sent to OpenBLD.net ecosystem
Be safe and be focused my friends
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1🙏1
After intalls, malicious software will connect to C2 command servers...
https://lab52.io/blog/pelmeni-wrapper-new-wrapper-of-kazuar-turla-backdoor/
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1
Do you want to protect your online privacy and the privacy of your family? Join the beta for OpenBLD.net Personal DoH Profiling (PDP), a new service that provides:
Benefits of PDP
How to Join the Beta
Be among the first to test OpenBLD.net PDP! Fill out the form below to get access to all features which will available in March 2024.
What's Next?
See details on OpenBLD.net here.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥4
The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint CSA, to disseminate known TTPs and IOCs associated with the Phobos ransomware variants observed as recently as February 2024...
Phobos actors run executables like 1saas.exe or cmd.exe to deploy additional Phobos payloads that have elevated privileges enabled. Additionally, Phobos actors can use the previous commands to perform various windows shell functions. The Windows command shell enables threat actors to control various aspects of a system, with multiple permission levels required for different subsets of commands.
How to mitigate risks:
- Secure RDP
- Reduce administratiove provigese scoping
- Stay updated
- Use OpenBLD.net or similar services
Technical details on CISA site:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👨💻1
WogRat Malware C2C / Download Prevents
While attacks against Linux have not been found, it is assumed that in the case of malware targeting Windows systems, attacks are conducted by disguising themselves as legitimate utility tools based on filenames upon collection, prompting users into downloading malware.
https://t.me/sysadm_in_channel/5057
P.S. Malware domains already sent to OpenBLD.net ecosystem
While attacks against Linux have not been found, it is assumed that in the case of malware targeting Windows systems, attacks are conducted by disguising themselves as legitimate utility tools based on filenames upon collection, prompting users into downloading malware.
https://t.me/sysadm_in_channel/5057
P.S. Malware domains already sent to OpenBLD.net ecosystem
🔥1🎉1
If you notice a short timeout, don’t be alarmed, it's I’m "playing")
Please open Telegram to view this post
VIEW IN TELEGRAM
🌚2👍1
📢 Integration of OpenBLD.net with URLhaus by abuse.ch
URLhaus is a project operated by abuse.ch. Its purpose is to collect, track, and share malware URLs, aiding network administrators and security analysts in safeguarding their networks and customers from cyber threats.
Now, you can check the malicious domain ownership with OpenBLD.net alongside Quad9, AdGuard, Cloudflare, ProtonDNS on abuse.ch.
In addition, you can incorporate abuse.ch lists into your security solutions, just as OpenBLD.net does.
You can check this as example on:
🔹 https://urlhaus.abuse.ch/host/licocojambamarketplace.com/
Here's to security for us all. Cheers!)
URLhaus is a project operated by abuse.ch. Its purpose is to collect, track, and share malware URLs, aiding network administrators and security analysts in safeguarding their networks and customers from cyber threats.
Now, you can check the malicious domain ownership with OpenBLD.net alongside Quad9, AdGuard, Cloudflare, ProtonDNS on abuse.ch.
In addition, you can incorporate abuse.ch lists into your security solutions, just as OpenBLD.net does.
You can check this as example on:
Here's to security for us all. Cheers!)
Please open Telegram to view this post
VIEW IN TELEGRAM
👏5🔥2🍾2
Personal DoH Profiling (PDP) started yesterday. 🚀
This is a beta feature. The main goal is to make individuality even more pronounced!
First results from PDP users:
🔹 PDP Service - works stably!
🔹 DNS Leak Test - requests do not leak to third parties!
🔹 DNS Check Tools - DNS responses are authenticated with DNSSEC!
One of the testers asked me (thanks, prgm ✌️):
- What should I check? Is everything working? Where can I look for bugs?
- When everything works and the user does not encounter bugs but observes speed, stability, and performance - this is the essence of testing's value and the primary value of the product and service!
To operate seamlessly, unnoticed, like clockwork...!
I'm very happy; do not hesitate to get in touch if you have any questions!
👻 OpenBLD.net PDP Testing Usage Manual
1️⃣ Take Control of Your Privacy! Join the OpenBLD.net PDP Beta
Peace ✌️
This is a beta feature. The main goal is to make individuality even more pronounced!
First results from PDP users:
One of the testers asked me (thanks, prgm ✌️):
- What should I check? Is everything working? Where can I look for bugs?
- When everything works and the user does not encounter bugs but observes speed, stability, and performance - this is the essence of testing's value and the primary value of the product and service!
To operate seamlessly, unnoticed, like clockwork...!
I'm very happy; do not hesitate to get in touch if you have any questions!
👻 OpenBLD.net PDP Testing Usage Manual
1️⃣ Take Control of Your Privacy! Join the OpenBLD.net PDP Beta
Peace ✌️
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3👍1
Received the Featured status in Chrome web store!
This is additional extensions for OpenBLD.net service.
Note: OpenBLD.net setup is required before using the Browser extension:
Recommended for ⚔ blocking malicious content from some URLs
Install and try from chrome web store
Please open Telegram to view this post
VIEW IN TELEGRAM
👍2
Please open Telegram to view this post
VIEW IN TELEGRAM
🤝 OpenBLD.net and Veesp.com Cooperation
🚀 Now it's can unload existing servers for - Estonia, Latvia, Lithuania, Moldova, Poland..!
Fast server in Europe with - NVME SSD, 8Gb RAM, 4 vCores, 500Mbps Bandwidth!
Really fast KVM-Based VPS at current time from Veesp.com I think it will help relieve the overall load)
let's move on!..🛞
Fast server in Europe with - NVME SSD, 8Gb RAM, 4 vCores, 500Mbps Bandwidth!
Really fast KVM-Based VPS at current time from Veesp.com I think it will help relieve the overall load)
let's move on!..
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥6🤩1
🛠 Notice: Today, will update the PDP functionality on ADA.
After testing, troubleshooting, and various adjustments, I have resolved some issues.
What's new:
🔹 User profile orchestration functionality (centralized management).
🔹 PDP management by server groups ADA/RIC.
🔹 Real-time synchronization of profiles.
PDP steel in testing stage, thanks all who joined to PDP Beta 🤝
What is PDP - Personal DoH Profiling, additional details see here:
- Beta Join: https://openbld.net/blog/2024-03-12-openbld-pdp-testing-usage/
- PDP Benefins: https://openbld.net/blog/2024-02-19-openbld-pdp-beta-join/
After testing, troubleshooting, and various adjustments, I have resolved some issues.
What's new:
PDP steel in testing stage, thanks all who joined to PDP Beta 🤝
What is PDP - Personal DoH Profiling, additional details see here:
- Beta Join: https://openbld.net/blog/2024-03-12-openbld-pdp-testing-usage/
- PDP Benefins: https://openbld.net/blog/2024-02-19-openbld-pdp-beta-join/
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ DinodasRAT Linux implant targeting entities worldwide
...and today, after discovering this backdoor, RAT C2 domain sent to OpenBLD.net ecosystem.
Take care of yourself with OpenBLD.net🛡
DinodasRAT technical analysys:
https://securelist.com/dinodasrat-linux-implant/112284/
...and today, after discovering this backdoor, RAT C2 domain sent to OpenBLD.net ecosystem.
Take care of yourself with OpenBLD.net
DinodasRAT technical analysys:
https://securelist.com/dinodasrat-linux-implant/112284/
Please open Telegram to view this post
VIEW IN TELEGRAM
⚡2👍1
As a result, Ada-h1 may experience intermittent availability.
Here's a comment from the hoster support team:
"We occasionally face intense attacks on our infrastructure. While we're working tirelessly to mitigate the impact on client servers, there may be disruptions in access.
We apologize for any inconvenience caused and assure you that we're striving to restore normalcy as soon as possible."
This can affect only ADA and DNS IP users. RIC users can relax. 😎
Status page - https://bld-status.sys-adm.in/
Let's hope for a swift resolution. Stay safe and patient. Peace ✌️
Up
I updated iOS profile for Apple users, its shall be fix connectivity problems if you have it:
Up2
Attacks end now. Everything ok. Looking forward, crossing fingers 🤞)
Please open Telegram to view this post
VIEW IN TELEGRAM
🤯3😢2👨💻1
Forwarded from Sys-Admin InfoSec
📢 Оптимизированный профиль для устройств Apple
После последних атак на одного из хостинг-провайдеров
Загрузите оптимизированный профиль с сайта проекта и просто установите его поверх существующего:
👉 openbld.net/docs/get-started/setup-mobile-devices/apple/
Если ваша система работает нормально, обновление не обязательно. Просто помните, что такая возможность существует. Мир ✌️
P.S. Будут вопросы по обновлению - Welcome😎
--- En ---
📢 Optimized Profile for Apple Devices
Following recent attacks on one of the hosting providers within
Download the optimized profile from the project website and simply install it over your existing one:
👉 openbld.net/docs/get-started/setup-mobile-devices/apple/
If your system is functioning normally, updating is not mandatory. Just remember that the option is available. Peace! ✌️
P.S. If you have any questions regarding the update - Welcome😎
После последних атак на одного из хостинг-провайдеров
OpenBLD.net, я обновил топологию серверов для оптимизации доставки контента, особенно для пользователей Apple.Загрузите оптимизированный профиль с сайта проекта и просто установите его поверх существующего:
👉 openbld.net/docs/get-started/setup-mobile-devices/apple/
Если ваша система работает нормально, обновление не обязательно. Просто помните, что такая возможность существует. Мир ✌️
P.S. Будут вопросы по обновлению - Welcome
--- En ---
📢 Optimized Profile for Apple Devices
Following recent attacks on one of the hosting providers within
OpenBLD.net, I have updated the server topology to optimize content delivery, especially for Apple users.Download the optimized profile from the project website and simply install it over your existing one:
👉 openbld.net/docs/get-started/setup-mobile-devices/apple/
If your system is functioning normally, updating is not mandatory. Just remember that the option is available. Peace! ✌️
P.S. If you have any questions regarding the update - Welcome
Please open Telegram to view this post
VIEW IN TELEGRAM
👌1
Android banking malware Vultur have been spotted adding new technical features, which allow the malware operator to further remotely interact with the victim’s mobile device.
Vultur has also started masquerading more of its malicious activity by encrypting its C2 communication, using multiple encrypted payloads that are decrypted on the fly, and using the guise of legitimate applications to carry out its malicious actions...
Technical analysis:
- https://blog.fox-it.com/2024/03/28/android-malware-vultur-expands-its-wingspan/
Take care of yourself
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1👨💻1
Today I reviewed official Notepad++ help message about of harmful clone
notepad[.]plus site.Be careful, before downloading and using third-party software
Official Notepad++ notice:
- https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2👍2
Starting today, IPv6 support has been added to the RIC OpenBLD.net ecosystem!
What does this mean for you? Now you can enjoy all the benefits of IPv6 in our network, including faster and more efficient data transmission, enhanced security, and flexibility when working with modern networks.
We are constantly striving to improve the OpenBLD.net service to provide you with the best experience possible. With the addition of IPv6 support, we are taking another step forward in ensuring you have access to the most modern technologies and capabilities.
Simply use RIC DoH or PDP DoH, and if your network supports IPv6, everything will start working automatically! 🚀
See more news in OpenBLD.net Blog:
Happy browsing!
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2👨💻2
In recent days, I've uncovered some alarming threats infiltrating our digital space, using command servers cleverly disguised as innocuous domains:
These threats are not to be taken lightly. The most concerning aspect? These stealthy stealers sidestep traditional antivirus measures by operating directly in your system's memory. But fear not! We have a formidable shield against these malicious intruders - OpenBLD.net!
Your support fuels my relentless pursuit to keep cyberspace safe and secure. Together, we can fortify our defenses and thwart even the most cunning threats.
Remember, every contribution, no matter how small, makes a monumental difference. Your generosity empowers me to stay ahead of the curve, protecting not just ourselves, but the entire online community.
🌟 Safeguard your digital world. Support our mission today:
https://openbld.net/docs/donation/#donation
Thank you for being a vital part of our journey to a safer cyberspace. Together, we can make a real impact! ✊
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2