OpenBLD.net
237 subscribers
121 photos
1 file
153 links
Official OpenBLD.net Service Channel
OpenBLD+, Feedback, another questions - @sysadminkz
Download Telegram
📢 Update Notice: Today I implemented new DoH/DoT balancer, Europe located, server in to RIC ecosystem.

If anyone who are using RIC will catching any gaps, notify me please.
Please open Telegram to view this post
VIEW IN TELEGRAM
😎31👏1
😡 OpenBLD.net Preventing: Malicious Campaign Impacting Azure Cloud Environments

New researched malicious campaign from Proofpoint researchers, detected integrating credential phishing and cloud account takeover (ATO) techniques...

This campaign contains multiple endpoints which also included domains used as malicious infrastructure...

So - All malicious infrastructure domains sent to OpenBLD.net ecosystem ✈️

Be safe and be focused my friends 😎
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1🙏1
😡 OpenBLD.net IoC's blocking of - New Turla wrapper of Kazuar

After intalls, malicious software will connect to C2 command servers...

https://lab52.io/blog/pelmeni-wrapper-new-wrapper-of-kazuar-turla-backdoor/
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1
📢 Take Control of Your Privacy! Join the OpenBLD.net PDP Beta! 😡

Do you want to protect your online privacy and the privacy of your family? Join the beta for OpenBLD.net Personal DoH Profiling (PDP), a new service that provides:

🔹 Complete isolation of your DNS requests, ensuring that no one can track your online activity.
🔹 Personalized DNS settings, so you can block ads, malicious websites, and other unwanted content.
🔹 Robust security with DNSSEC, TLSv1.2, and TLSv1.3.

Benefits of PDP

🔹Enhanced privacy: Your DNS requests will not be accessible to third parties, ensuring the confidentiality of your online activity.
🔹Security: Protection from malicious websites, phishing attacks, and other online threats.
🔹Control: Block ads, trackers, and other unwanted content.
🔹Ease of use: Easy to set up and use.
🔹Stability: All OpenBLD.net experiences under the hood.
🔹Support: Access to a personal support.

How to Join the Beta

Be among the first to test OpenBLD.net PDP! Fill out the form below to get access to all features which will available in March 2024.

🔻 Join to PDP Beta

What's Next?

See details on OpenBLD.net here.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥4
😡 OpenBLD.net - Phobos Ransomware Attack Mitigations

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint CSA, to disseminate known TTPs and IOCs associated with the Phobos ransomware variants observed as recently as February 2024...

Phobos actors run executables like 1saas.exe or cmd.exe to deploy additional Phobos payloads that have elevated privileges enabled. Additionally, Phobos actors can use the previous commands to perform various windows shell functions. The Windows command shell enables threat actors to control various aspects of a system, with multiple permission levels required for different subsets of commands.

How to mitigate risks:
- Secure RDP
- Reduce administratiove provigese scoping
- Stay updated
- Use OpenBLD.net or similar services

Technical details on CISA site:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a
Please open Telegram to view this post
VIEW IN TELEGRAM
1👨‍💻1
WogRat Malware C2C / Download Prevents

While attacks against Linux have not been found, it is assumed that in the case of malware targeting Windows systems, attacks are conducted by disguising themselves as legitimate utility tools based on filenames upon collection, prompting users into downloading malware.

https://t.me/sysadm_in_channel/5057

P.S. Malware domains already sent to OpenBLD.net ecosystem
🔥1🎉1
⚠️ Notice: Today I'll install some patches in to OpenBLD.net ecosystem. This actions shouldn't affect OpenBLD.net ecosystem, but i's can be cause an interrupt on few seconds.

If you notice a short timeout, don’t be alarmed, it's I’m "playing")
Please open Telegram to view this post
VIEW IN TELEGRAM
🌚2👍1
📢 Integration of OpenBLD.net with URLhaus by abuse.ch

URLhaus is a project operated by abuse.ch. Its purpose is to collect, track, and share malware URLs, aiding network administrators and security analysts in safeguarding their networks and customers from cyber threats.

Now, you can check the malicious domain ownership with OpenBLD.net alongside Quad9, AdGuard, Cloudflare, ProtonDNS on abuse.ch.

In addition, you can incorporate abuse.ch lists into your security solutions, just as OpenBLD.net does.

You can check this as example on:
🔹 https://urlhaus.abuse.ch/host/licocojambamarketplace.com/

Here's to security for us all. Cheers!)
Please open Telegram to view this post
VIEW IN TELEGRAM
👏5🔥2🍾2
Personal DoH Profiling (PDP) started yesterday. 🚀

This is a beta feature. The main goal is to make individuality even more pronounced!

First results from PDP users:

🔹 PDP Service - works stably!
🔹 DNS Leak Test - requests do not leak to third parties!
🔹 DNS Check Tools - DNS responses are authenticated with DNSSEC!

One of the testers asked me (thanks, prgm ✌️):

- What should I check? Is everything working? Where can I look for bugs?
- When everything works and the user does not encounter bugs but observes speed, stability, and performance - this is the essence of testing's value and the primary value of the product and service!

To operate seamlessly, unnoticed, like clockwork...!

I'm very happy; do not hesitate to get in touch if you have any questions!

👻 OpenBLD.net PDP Testing Usage Manual
1️⃣ Take Control of Your Privacy! Join the OpenBLD.net PDP Beta

Peace ✌️
Please open Telegram to view this post
VIEW IN TELEGRAM
3👍1
😡 OpenBLD.net Blocker Browser Extension

Received the Featured status in Chrome web store! 🎉

This is additional extensions for OpenBLD.net service.

Note: OpenBLD.net setup is required before using the Browser extension:
🔹 Where to start: https://openbld.net/docs/get-started/where-to-start/
🔹 Main Goals: https://openbld.net/docs/overwiew/main-goals/
🔹 OpenBLD Plus: https://openbld.net/docs/overwiew/openbld-plus/
🔹 Donation and Contribution: https://openbld.net/docs/donation/

Recommended for blocking malicious content from some URLs

Install and try from chrome web store
Please open Telegram to view this post
VIEW IN TELEGRAM
👍2
⚙️ Notice. Today will updated ADA/RIC certs in OpenBLD.net ecosystem, it's won't affect anyone, just keep it in mind)
Please open Telegram to view this post
VIEW IN TELEGRAM
🤝 OpenBLD.net and Veesp.com Cooperation

🚀 Now it's can unload existing servers for - Estonia, Latvia, Lithuania, Moldova, Poland..!

Fast server in Europe with - NVME SSD, 8Gb RAM, 4 vCores, 500Mbps Bandwidth!

Really fast KVM-Based VPS at current time from Veesp.com I think it will help relieve the overall load)

let's move on!.. 🛞
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥6🤩1
🛠 Notice: Today, will update the PDP functionality on ADA.

After testing, troubleshooting, and various adjustments, I have resolved some issues.

What's new:

🔹 User profile orchestration functionality (centralized management).
🔹 PDP management by server groups ADA/RIC.
🔹 Real-time synchronization of profiles.

PDP steel in testing stage, thanks all who joined to PDP Beta 🤝

What is PDP - Personal DoH Profiling, additional details see here:
- Beta Join: https://openbld.net/blog/2024-03-12-openbld-pdp-testing-usage/
- PDP Benefins: https://openbld.net/blog/2024-02-19-openbld-pdp-beta-join/
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ DinodasRAT Linux implant targeting entities worldwide

...and today, after discovering this backdoor, RAT C2 domain sent to OpenBLD.net ecosystem.

Take care of yourself with OpenBLD.net 🛡

DinodasRAT technical analysys:

https://securelist.com/dinodasrat-linux-implant/112284/
Please open Telegram to view this post
VIEW IN TELEGRAM
2👍1
⚠️⚠️ Attention! One of OpenBLD.net Hoster is currently under attack

As a result, Ada-h1 may experience intermittent availability.

Here's a comment from the hoster support team:

"We occasionally face intense attacks on our infrastructure. While we're working tirelessly to mitigate the impact on client servers, there may be disruptions in access.

We apologize for any inconvenience caused and assure you that we're striving to restore normalcy as soon as possible."

This can affect only ADA and DNS IP users. RIC users can relax. 😎

Status page - https://bld-status.sys-adm.in/

Let's hope for a swift resolution. Stay safe and patient. Peace ✌️

Up

I updated iOS profile for Apple users, its shall be fix connectivity problems if you have it:
🔹 https://openbld.net/docs/get-started/setup-mobile-devices/apple/

Up2

Attacks end now. Everything ok. Looking forward, crossing fingers 🤞)
Please open Telegram to view this post
VIEW IN TELEGRAM
🤯3😢2👨‍💻1
Forwarded from Sys-Admin InfoSec
📢 Оптимизированный профиль для устройств Apple

После последних атак на одного из хостинг-провайдеров OpenBLD.net, я обновил топологию серверов для оптимизации доставки контента, особенно для пользователей Apple.

Загрузите оптимизированный профиль с сайта проекта и просто установите его поверх существующего:
👉 openbld.net/docs/get-started/setup-mobile-devices/apple/

Если ваша система работает нормально, обновление не обязательно. Просто помните, что такая возможность существует. Мир ✌️

P.S. Будут вопросы по обновлению - Welcome 😎

--- En ---

📢 Optimized Profile for Apple Devices

Following recent attacks on one of the hosting providers within
OpenBLD.net, I have updated the server topology to optimize content delivery, especially for Apple users.

Download the optimized profile from the project website and simply install it over your existing one:
👉
openbld.net/docs/get-started/setup-mobile-devices/apple/

If your system is functioning normally, updating is not mandatory. Just remember that the option is available. Peace! ✌️

P.S. If you have any questions regarding the update - Welcome
😎
Please open Telegram to view this post
VIEW IN TELEGRAM
👌1
OpenBLD.net pinned a photo
📢 OpenBLD.net Blocked: Android Vultur Malware

Android banking malware Vultur have been spotted adding new technical features, which allow the malware operator to further remotely interact with the victim’s mobile device.

Vultur has also started masquerading more of its malicious activity by encrypting its C2 communication, using multiple encrypted payloads that are decrypted on the fly, and using the guise of legitimate applications to carry out its malicious actions...

Technical analysis:

- https://blog.fox-it.com/2024/03/28/android-malware-vultur-expands-its-wingspan/

Take care of yourself 🔐
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1👨‍💻1
📢 OpenBLD.net Blocked: Notepad++ Parasite Website

Today I reviewed official Notepad++ help message about of harmful clone notepad[.]plus site.

Be careful, before downloading and using third-party software

Official Notepad++ notice:

- https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/
Please open Telegram to view this post
VIEW IN TELEGRAM
2👍2
🆕 IPv6 Available Now in OpenBLD.net RIC Scoping 🎉


Starting today, IPv6 support has been added to the RIC OpenBLD.net ecosystem!

What does this mean for you? Now you can enjoy all the benefits of IPv6 in our network, including faster and more efficient data transmission, enhanced security, and flexibility when working with modern networks.

We are constantly striving to improve the OpenBLD.net service to provide you with the best experience possible. With the addition of IPv6 support, we are taking another step forward in ensuring you have access to the most modern technologies and capabilities.

Simply use RIC DoH or PDP DoH, and if your network supports IPv6, everything will start working automatically! 🚀

See more news in OpenBLD.net Blog:
🔹 https://openbld.net/blog/

Happy browsing! 🌐
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2👨‍💻2
😠 Faked NordVPN and Fileless Stealer

In recent days, I've uncovered some alarming threats infiltrating our digital space, using command servers cleverly disguised as innocuous domains:

🔹 Beware of the counterfeit NordVPN ads circulating through Bing.
🔹 Stay cautious of stealthy stealers hitching a ride in your email inbox.

These threats are not to be taken lightly. The most concerning aspect? These stealthy stealers sidestep traditional antivirus measures by operating directly in your system's memory. But fear not! We have a formidable shield against these malicious intruders - OpenBLD.net! 😎

Your support fuels my relentless pursuit to keep cyberspace safe and secure. Together, we can fortify our defenses and thwart even the most cunning threats.

Remember, every contribution, no matter how small, makes a monumental difference. Your generosity empowers me to stay ahead of the curve, protecting not just ourselves, but the entire online community.

🌟 Safeguard your digital world. Support our mission today:

https://openbld.net/docs/donation/#donation

Thank you for being a vital part of our journey to a safer cyberspace. Together, we can make a real impact!
Please open Telegram to view this post
VIEW IN TELEGRAM
2