Filter
Exclude
Time range
-
Near
Hon. Matangira: Madzishe vemasabhuku ndiyo yaive mvura, vanhu dziri hove, saka topa mbiri kuHove here? Jesu akaita mabasa asi akati mbiri ipapi kunaBaba #CAB3
1
89
Googleが運営する広告追跡ドメインDoubleClickを中継させ、メールゲートウェイのURL評価をすり抜けるマルスパムキャンペーンが報告されています。受信者のメールドメインから企業ロゴを、閲覧元IPから所在地を動的に取得して偽ページを生成する仕組みで、組織ごとにルアーを作り込む必要がないとのこと。最終的にはWindowsのマルウェア検査機構AMSIとイベント記録ETWを無効化し、正規のMicrosoft署名プロセスにマルウェアを注入するとされています。 ドメイン評価に頼ったメール防御ではこの種の中継を見分けにくいとして、GPOでスクリプトファイル(.js/.vbs/.hta)の既定の開き先をメモ帳に変更し初段階のスクリプト実行を封じる対策が推奨されています。 【要点の整理】 ・添付HTML(ドイツ語で「注文」を意味するBestellung_2026.html)を開くとHTMLの自動転送(meta-refresh)でad[.]doubleclick[.]netの追跡URLへ即座にリダイレクト。DoubleClickはGoogle所有の高信頼ドメインのため、メールゲートウェイのURL評価で許可されやすい。URLフラグメントにメールアドレスがなければBingへ転送し、自動解析を回避する仕組み ・企業ロゴはメールドメインをもとにClearbit、logo[.]dev、Googleファビコン等から動的に取得し、ipapi[.]coで閲覧元IPに基づく都市名と現地時刻を表示。組織固有データのハードコードはなく、メールアドレスを差し替えるだけでルアーが即座に切り替わる ・感染はHTML→JScript→PowerShell→.NETローダー→プロセスホローイング(正規プロセスのメモリを自前コードで上書きする手法)の5段階。PowerShell段階でWiresharkやany[.]run等の解析ツールを検出すると端末を強制再起動(Restart-Computer -Force)して解析を妨害 ・.NETローダーはWindows 11 24H2(ビルド26100以上)でNtManageHotPatchにパッチを当ててAMSIを阻止し、EtwEventWriteも即リターンに書き換えてETWの監視テレメトリを停止。Avast、AVG、Malwarebytesが動作していない環境ではDefenderのリアルタイム保護も無効化したうえで、InstallUtil.exeまたはMSBuild.exeへのプロセスホローイングで最終ペイロードを注入。NVIDIAのドライバーインストールを装ったフォルダ名やレジストリキー名で常駐化 ・指令サーバー(C2)との通信は動的DNS(DDNS)ベースのサーバーへTCPポート7211のAES暗号化。ペイロード取得にはIE8のUser-Agent文字列がハードコードされており、現代の環境では異常値として検知しやすい。初回通信でNVIDIA(GTX/RTX)やAMDのGPUをWMIとレジストリから列挙しており、暗号通貨マイニングが後続目的の可能性もあるとされる。当初DesckVB RATとされていたがコミュニティの指摘で再調査の結果、未特定の.NETローダーに訂正(6月5日追記)。Huntressが2026年5月のSOC対応で発見 詳細は以下を参照: huntress.com/blog/malspam-to…
3
23
1,792
Elastic Security Labs publishes comprehensive technical breakdown of Tycoon 2FA AiTM kit operations across Microsoft 365 and Google Workspace. Despite March 2026 takedown by Microsoft and Europol, operators rapidly adapted with OAuth device code flows. • **Technical Architecture**: Two-tier Microsoft operations (cloud VPS kit relay residential operator console) vs single-tier Google relay. Kit uses WebSocket C2, per-victim encryption, and extensive anti-analysis (IP filtering, debugger traps, DOM vanishing) • **Attack Chain**: Phishing → multi-layer redirects → AiTM proxy intercepts real MFA → session token theft → device registration for PRT persistence (Microsoft only). Google variant targets Chrome OAuth client `77185425430` with compressed ~1-second auth sequence • **Evasion Techniques**: Blocklists cloud provider IPs (api[.]ipapi[.]is checks), detects Selenium/PhantomJS, encrypts payloads with Caesar XOR cipher seeded per-session. Linux users get blank pages assuming researcher targeting • **Detection IOCs**: Microsoft kit relay uses Node.js UAs (`node`, `axios`, `undici`) from cheap hosting ASNs. Google variant shows impossible travel patterns across multiple ASNs with `token.authorize` events for Chrome client • **Graph API Enumeration**: Post-compromise recon hits 4 categories within 60 seconds: role discovery, cross-tenant mapping, mailbox settings, contact harvesting using `/beta/` endpoints with `$top=999` parameters #DFIR_Radar
1
1
3
216
ping0和ippure是何意味,如果按照 IP 查询的权威度排序,正常的逻辑不应该先看这些吗? IPinfo ipregistry ipapi IP2Location AbuseIPDB
日常用 ippure.com 干净准确,推荐
3
924
🛠️ API Deposu'na bugün 11 API eklendi! Geliştirici araçları özel serisi: 📊 Image-Charts → Pasta, çubuk, çizgi grafik ve QR kod üretimi → Ücretsiz, auth yok, URL parametreleriyle anında görsel → 7 farklı grafik tipi destekli 📦 jsDelivr → npm/GitHub paket bilgisi ve indirme istatistikleri → Ücretsiz, auth yok, 9 farklı endpoint → Versiyon çözümleme, entrypoint ve platform bazlı analiz 🔢 Abacus → Sayfa hit ve olay sayacı servisi → Ücretsiz, auth yok, namespace bazlı izleme → 6 endpoint: hit, get, create, info, stats, healthcheck 🌐 ipapi .is → IP adresi geolocation, ASN ve VPN/proxy tespiti → Ücretsiz, auth yok, tek istekle kapsamlı bilgi → Şirket, hosting ve gizlilik verisi dahil 📍 IPLocate. io → IP geolocation ve tehdit verisi → Ücretsiz, auth yok, hosting/proxy algılama → Hızlı ve detaylı konum bilgisi 🔍 addr. zone → IP sınıflandırma ve güven skoru → Ücretsiz, auth yok, datacenter/proxy/VPN tespiti → Risk değerlendirmesi için ideal 💾 ExtendsClass JSON Storage → Ücretsiz JSON depolama servisi - CRUD API → Auth yok, anında bin oluştur, oku, güncelle → Prototipleme ve test için mükemmel 🐘 PHPhub → PHP kod doğrulama - 5.6'dan 8.3'e kadar → Ücretsiz, auth yok, 4 farklı PHP versiyonu → Syntax hatalarını anında tespit 🐍 Pythonium → Python kod doğrulama → Ücretsiz, auth yok, JSON ile kod gönder → Syntax kontrolü tek istekle 🗃️ SQLable → SQL sorgu doğrulama → Ücretsiz, auth yok, ham SQL gönder → Syntax hatalarını anında bul ☸️ Yamline → Kubernetes YAML manifest doğrulama → Ücretsiz, auth yok, Kubeconform tabanlı → Pod, Deployment, Service manifest kontrolü 👉 apideposu.com'da hepsini test edebilirsin 🚀 #API #Developer #DevTools #PHP #Python #SQL #Kubernetes #IPGeolocation #Charts #OpenSource #TürkçeAPI #APIDeposu
1
1
21
4,174
🚨#Tycoon2FA update @esthreat observed ProxyLine (RU proxy service) relaying phishing logins targeting M365 & Gmail accounts. They also query ipinfo/geojs/ipapi to redirect vendor traffic (Microsoft, Google, etc) to legit sites to hide their phishing pages.tinyurl.com/tycoon2FA
6
14
1,104
⚠️X的2大插件(Xhunt、Frontrun)被大佬源码解密:有风险,谨慎安装! 🚫1. Xhunt:高风险设计(重点警惕) 数据收集严重超出声明: 实际代码显示会上传真实 IP、城市、ISP、设备指纹(FingerprintJS)、以及访问的完整页面 URL。 多重定位追踪: 同时调用多个 IP 地理服务(ipapi、ip-api、ipinfo、ipify)进行精确定位。 刻意代码混淆: 使用 RC4 加密、String.fromCharCode 隐藏关键请求头(如 authorization 等),规避审查。 潜在高危能力:无限制 HTTP 代理(可访问内网/云元数据) 预留钱包注入接口(可远程激活) 使用阿里云 Nacos 做远程配置(可绕过商店审核动态改行为) 🚫2. Frontrun:中等风险(相对可控) 数据拦截范围广: 接入多个 𝕏 GraphQL 接口,并对加密网站请求(fetch/XHR/WebSocket)进行拦截。 数据用途差异: 大部分数据仅保存在本地,用于 UI 展示(不集中上传)。 外部数据上报行为:使用 Amplitude 记录平台访问、登录信息(邮箱/姓名) 错误日志上传(含设备信息、UA) 远程控制能力: 使用 GrowthBook 实现远程功能开关(无需更新即可改变行为) → 评价:存在隐私采集,但整体比 Xhunt 更克制。 #Xhunt #Frontrun
Mar 23
I guess most of the CT users often use fonrtun pro extension or xhunt extension (specially in the chinese community this is very popular), people see open source on github and just trust it. so today, I checked both xhunt and frontrun to see what is really going on under the hood and tbh some of this stuff is wild. xhunt is open source, it is true but being open source doesn't always mean safe. their README says "local-only data storage, no sensitive information uploads" which is a straight up lie. i checked the actual code and every single API call sends your real IP address, physical city, ISP and even persistent device fingerprint using FingerprintJS and the full url of every single page you visit on twitter, all going to their server at kb(.)xhunt(.)ai. they hit 4 different IP geolocation services [ipapi(.)co, ip-api(.)com, ipinfo(.)io, ipify(.)org] just to figure out where you are. even worse, they deliberately use RC4 encryption and String.fromCharCode arrays to hide header names like "authorization" and "x-user-id" and "x-window-location-href" from anyone reviewing the code. tbh legit developers don't do that. they also have a completely unrestricted HTTP proxy in the background script (EXECUTE_REQUEST handler) with zero URL validation, means any code can tell your browser to fetch literally anything, your local network, cloud metadata, whatever. and there is an empty wallet injection function already wired up with world:MAIN access just sitting there waiting to be activated. their remote config runs on Alibaba Nacos so they can push changes server-side in minutes without any chrome store review. frontrun is a lil bit different. it hooks into 12 𝕏 GraphQL endpoints : your feed, followers, following, searches, community posts, all of it and monkey-patches fetch, XHR, and WebSocket on 8 crypto platforms. the intercepted API data from 𝕏 and crypto platforms stays in your browser for the overlay, but every time you open a crypto site, frontrun pings Amplitude with the platform name, when you log in it sends your email and name to Amplitude and on errors it uploads logs with your device ID and user agent to their own server at loadbalance(.)frontrun(.)pro but the key difference is that intercepted data mostly stays local in your browser for the overlay UI. it's not being sent to their servers the way xhunt does it. it worth noting that frontrun also uses GrowthBook for remote feature flags so they can change extension behavior server-side without a chrome store update too. but overall, frontrun is much less shady than xHunt in practice. neither extension is stealing your keys or draining wallets today. but the infrastructure is there in the case of xhunt. remote config systems that can push silent changes, aggressive permissions, and in xhunt's case deliberate code obfuscation to hide what they are doing. just be aware of what you are installing.
1
6
2,271
Mar 23
Dịch cho anh em dễ hóng Dưới đây là bản tổng hợp (tóm tắt) nội dung văn bản bằng tiếng Việt, tập trung vào các điểm chính một cách rõ ràng và ngắn gọn: Tổng quan về hai extension: xHunt và Frontrun Nhiều người dùng CT (có lẽ là Crypto Twitter) thường sử dụng các extension như Frontrun Pro hoặc xHunt (đặc biệt phổ biến trong cộng đồng Trung Quốc). Họ tin tưởng vì mã nguồn mở trên GitHub, nhưng việc mã nguồn mở không đồng nghĩa với an toàn. Tác giả đã kiểm tra mã nguồn và phát hiện nhiều vấn đề đáng lo ngại. xHunt: Mã nguồn mở nhưng không an toàn: README tuyên bố lưu trữ dữ liệu chỉ cục bộ và không upload thông tin nhạy cảm – điều này là dối trá. Thu thập dữ liệu: Mọi cuộc gọi API đều gửi địa chỉ IP thực, thành phố, ISP, dấu vân tay thiết bị (sử dụng FingerprintJS) và URL đầy đủ của mọi trang bạn truy cập trên Twitter đến server kb(.)xhunt(.)ai. Theo dõi vị trí: Sử dụng 4 dịch vụ geolocation (ipapi(.)co, ip-api(.)com, ipinfo(.)io, ipify(.)org) để xác định vị trí. Che giấu mã: Sử dụng mã hóa RC4 và mảng String.fromCharCode để ẩn tên header như "authorization", "x-user-id", "x-window-location-href" – điều mà lập trình viên hợp pháp không làm. Rủi ro lớn: Có proxy HTTP không giới hạn trong script nền (xử lý EXECUTE\_REQUEST) mà không kiểm tra URL, cho phép lấy bất kỳ thứ gì (mạng nội bộ, metadata cloud). Có hàm chèn wallet rỗng đã sẵn sàng với quyền truy cập "world:MAIN". Sử dụng config từ xa trên Alibaba Nacos để thay đổi server-side nhanh chóng mà không cần duyệt Chrome Store. Frontrun: Khác biệt: Can thiệp vào 12 endpoint GraphQL của 𝕏 (Twitter) như feed, followers, searches, và vá fetch, XHR, WebSocket trên hơn 8 nền tảng crypto. Xử lý dữ liệu: Dữ liệu chặn từ 𝕏 và crypto chủ yếu lưu cục bộ cho giao diện overlay. Tuy nhiên, khi mở site crypto, nó gửi tên nền tảng đến Amplitude; khi đăng nhập, gửi email và tên; lỗi thì upload log với ID thiết bị và user agent đến server loadbalance(.)frontrun(.)pro. Tính năng từ xa: Sử dụng GrowthBook cho flag tính năng từ xa, cho phép thay đổi hành vi mà không cập nhật Chrome Store. Ít mờ ám hơn: Dữ liệu không bị gửi ra ngoài như xHunt, nên ít rủi ro hơn. Kết luận: Hiện tại, cả hai extension chưa đánh cắp khóa ví hoặc rút tiền, nhưng xHunt có hạ tầng sẵn sàng cho các hành vi xấu (config từ xa, quyền cao, mã che giấu). Frontrun ít đáng ngờ hơn. Hãy cẩn thận khi cài đặt và nhận thức rõ rủi ro!
Mar 23
I guess most of the CT users often use fonrtun pro extension or xhunt extension (specially in the chinese community this is very popular), people see open source on github and just trust it. so today, I checked both xhunt and frontrun to see what is really going on under the hood and tbh some of this stuff is wild. xhunt is open source, it is true but being open source doesn't always mean safe. their README says "local-only data storage, no sensitive information uploads" which is a straight up lie. i checked the actual code and every single API call sends your real IP address, physical city, ISP and even persistent device fingerprint using FingerprintJS and the full url of every single page you visit on twitter, all going to their server at kb(.)xhunt(.)ai. they hit 4 different IP geolocation services [ipapi(.)co, ip-api(.)com, ipinfo(.)io, ipify(.)org] just to figure out where you are. even worse, they deliberately use RC4 encryption and String.fromCharCode arrays to hide header names like "authorization" and "x-user-id" and "x-window-location-href" from anyone reviewing the code. tbh legit developers don't do that. they also have a completely unrestricted HTTP proxy in the background script (EXECUTE_REQUEST handler) with zero URL validation, means any code can tell your browser to fetch literally anything, your local network, cloud metadata, whatever. and there is an empty wallet injection function already wired up with world:MAIN access just sitting there waiting to be activated. their remote config runs on Alibaba Nacos so they can push changes server-side in minutes without any chrome store review. frontrun is a lil bit different. it hooks into 12 𝕏 GraphQL endpoints : your feed, followers, following, searches, community posts, all of it and monkey-patches fetch, XHR, and WebSocket on 8 crypto platforms. the intercepted API data from 𝕏 and crypto platforms stays in your browser for the overlay, but every time you open a crypto site, frontrun pings Amplitude with the platform name, when you log in it sends your email and name to Amplitude and on errors it uploads logs with your device ID and user agent to their own server at loadbalance(.)frontrun(.)pro but the key difference is that intercepted data mostly stays local in your browser for the overlay UI. it's not being sent to their servers the way xhunt does it. it worth noting that frontrun also uses GrowthBook for remote feature flags so they can change extension behavior server-side without a chrome store update too. but overall, frontrun is much less shady than xHunt in practice. neither extension is stealing your keys or draining wallets today. but the infrastructure is there in the case of xhunt. remote config systems that can push silent changes, aggressive permissions, and in xhunt's case deliberate code obfuscation to hide what they are doing. just be aware of what you are installing.
1
2
119
Mar 23
For chinese users : 我估计大部分CT用户都在用Frontrun Pro或者xHunt扩展(尤其在华语社区特别流行), 大家看到GitHub上开源就直接信了。 所以今天我把xHunt和Frontrun都拆开看了一下, 看看底层到底在搞什么, 说实话有些东西确实离谱。 xHunt是开源的没错, 但开源不代表安全。他们的README上写着"仅本地数据存储, 不上传敏感信息", 这完全是在扯淡。 我看了实际代码, 每一个API请求都会发送你的真实IP地址、所在城市、ISP, 甚至通过FingerprintJS生成的持久设备指纹, 以及你在Twitter上访问的每个页面的完整URL, 全部发到他们的服务器kb(.)xhunt(.)ai。他们调用了4个不同的IP定位服务 [ipapi(.)co, ip-api(.)com, ipinfo(.)io, ipify(.)org] 就为了搞清楚你在哪。 更离谱的是, 他们故意用RC4加密和String.fromCharCode数组来隐藏像"authorization"、"x-user-id"和"x-window-location-href"这些请求头名称, 不让审查代码的人发现。说实话正经开发者不会这么干。 他们还在后台脚本里内置了一个完全不受限的HTTP代理(EXECUTE_REQUEST处理器), 零URL验证, 意味着任何代码都能让你的浏览器去请求任何东西, 你的本地网络、云元数据、随便什么都行。而且还有一个空的钱包注入函数, 已经用world:MAIN权限接好了, 就放在那里等着被激活。他们的远程配置跑在阿里Nacos上, 所以可以在几分钟内从服务端推送更改, 完全不需要Chrome商店审核。 Frontrun有点不一样。它挂钩了12个𝕏的GraphQL端点: 你的时间线、关注者、正在关注的人、搜索记录、社区帖子等等, 并且在8个以上的加密平台上对fetch、XHR和WebSocket进行了monkey-patch。 从𝕏和加密平台拦截的API数据留在你的浏览器里用于覆盖层显示, 但每次你打开一个加密网站, Frontrun都会向Amplitude发送平台名称, 当你登录时它会把你的邮箱和姓名发送到Amplitude, 出现错误时它会把日志连同你的设备ID和User Agent一起上传到loadbalance(.)frontrun(.)pro 但关键区别是拦截到的数据大部分留在你的浏览器本地, 用于覆盖层UI, 不像xHunt那样全部发到他们的服务器。 值得注意的是Frontrun也用GrowthBook做远程功能开关, 所以他们也能在不经过Chrome商店更新的情况下改变扩展行为。但总体来说Frontrun在实际操作上比xHunt安全得多。 这两个扩展今天都没有在偷你的私钥或者清空你的钱包。但在xHunt的情况下那些基础设施已经就位了。可以静默推送更改的远程配置系统, 激进的权限, 以及xHunt故意混淆代码来隐藏他们在做什么。注意你装的东西。
21
15
92
25,656
Mar 23
I guess most of the CT users often use fonrtun pro extension or xhunt extension (specially in the chinese community this is very popular), people see open source on github and just trust it. so today, I checked both xhunt and frontrun to see what is really going on under the hood and tbh some of this stuff is wild. xhunt is open source, it is true but being open source doesn't always mean safe. their README says "local-only data storage, no sensitive information uploads" which is a straight up lie. i checked the actual code and every single API call sends your real IP address, physical city, ISP and even persistent device fingerprint using FingerprintJS and the full url of every single page you visit on twitter, all going to their server at kb(.)xhunt(.)ai. they hit 4 different IP geolocation services [ipapi(.)co, ip-api(.)com, ipinfo(.)io, ipify(.)org] just to figure out where you are. even worse, they deliberately use RC4 encryption and String.fromCharCode arrays to hide header names like "authorization" and "x-user-id" and "x-window-location-href" from anyone reviewing the code. tbh legit developers don't do that. they also have a completely unrestricted HTTP proxy in the background script (EXECUTE_REQUEST handler) with zero URL validation, means any code can tell your browser to fetch literally anything, your local network, cloud metadata, whatever. and there is an empty wallet injection function already wired up with world:MAIN access just sitting there waiting to be activated. their remote config runs on Alibaba Nacos so they can push changes server-side in minutes without any chrome store review. frontrun is a lil bit different. it hooks into 12 𝕏 GraphQL endpoints : your feed, followers, following, searches, community posts, all of it and monkey-patches fetch, XHR, and WebSocket on 8 crypto platforms. the intercepted API data from 𝕏 and crypto platforms stays in your browser for the overlay, but every time you open a crypto site, frontrun pings Amplitude with the platform name, when you log in it sends your email and name to Amplitude and on errors it uploads logs with your device ID and user agent to their own server at loadbalance(.)frontrun(.)pro but the key difference is that intercepted data mostly stays local in your browser for the overlay UI. it's not being sent to their servers the way xhunt does it. it worth noting that frontrun also uses GrowthBook for remote feature flags so they can change extension behavior server-side without a chrome store update too. but overall, frontrun is much less shady than xHunt in practice. neither extension is stealing your keys or draining wallets today. but the infrastructure is there in the case of xhunt. remote config systems that can push silent changes, aggressive permissions, and in xhunt's case deliberate code obfuscation to hide what they are doing. just be aware of what you are installing.
92
40
490
44,867
Wadii i bought mine in october last year, for 180usd straight on website. Zvese ipapi ikauya ne dhl . I subscribe 30usd per month kumasvingo.. but nema charges it cost around 37usd. So ndinotova ne referal code if you want to biy yours you get a waiver of 1 month .
3
2
8
915
Feb 18
Replying to @kyiioru @phoonfps
o nome ja fala VPN virtual private network o IP que é exposto no radmin nao é o seu real, é um IP """privado""" que o driver do radmin cria pra te expor pra quem esta conectado na sua rede do radmin por isso que quando vc instala o radmin e digita "ipconfig" no terminal vc vai ver uma config de rede APENAS pro radmin se vc pega esse ip gerado e coloca no ipapi[.]co por exemplo, ele nunca vai te trazer localização de nada o ip gerado entra numa classificação específica, que é a classe de ip A(ou 1) que na subrede fica como 26.0.0.0/8 so que olha q doido, mesmo estando na classe pública ela nao é pública de verdade mas isso é pra evitar conflito Lan ja que é menos comum o uso deles então não, o uso do radmin nao vai mandar seu IP "de verdade" pra outros
7
1
117
2,196
Implemented a more consent-based location using flow, instead of the ipapi way of learning a user's city through their ip address. Knowing how the app gets to know oyur location helps building trust with the user and reply better. With drissea, you can also search google maps for services and location reviews too.
3
7
93
10 Dec 2025
ipapiのapi自体はipでBANされているわけではなかったのでおそらくUAでブロックされているんじゃないでしょうか
1
2
694
22 Nov 2025
bahagia ya yang banyak juhoon, imami, ipapi🫰
22 Nov 2025
🎥 #juhoon
1
2
169
19 Nov 2025
mdrrrrr papi freezia (ipapi) decouvre les memes d'internet comme la fois ou il m'a dit fierement "ouais je sais d'ou vient 67 pcq je comprennais pas 😃"
2
85
PHISHING ALERT — cPanel / Webmail Credential Harvesting with IP Enrichment & Telegram Exfiltration. KnowBe4 Threat Labs observed two near-identical fake cPanel/Webmail pages used to harvest credentials. One version enriches victim metadata (IP/country) before submission. The other immediately exfiltrates credentials to a Telegram bot and redirects victims back to the real webmail page to avoid suspicion. 2. Attack Chain The attack follows a concise 5-stage process: Stage 1 — Lure: Victim lands on a fake cPanel/Webmail login page (crafted UI, localized text). Stage 2 — Capture: User enters username/password into the page form. Stage 3 — Enrich (Optional): Page optionally queries ipapi[.]co/json to capture client IP & country. Stage 4 — Exfiltrate: Credentials forwarded to attacker via Telegram bot API in real-time. Stage 5 — Cover: Victim redirected to legitimate webmail port/page (e.g., :2095) to reduce detection. 3. Lure Details Common Subject Patterns: [Action Required]: This is your Final Warning WebMail Account User@[recipient's email domain] will expire on 11/6/2025 2:50:54 a.m. someone added you as their recovery email Someone added you as their recovery email Spoofed Sender Addresses: The email’s sender address is spoofed to fit the recipient's email domain. cpanel@[recipient's email domain] no-reply@[recipient's email domain] 4. Indicators of Compromise Malicious URLs: hxxps://gh9btsdium[.]us-west-2[.]awsapprunner[.]com/ hxxps://online[.]sequentials[.]click/ longtiadi[.]com hxxps://68f4ce4b2e8a87f970d5e70f-heartfelt[.]netlify[.]app/ hxxp://bafkreifzko3fvymsequtnrstsnedfkfbru33hma3xfdbbi6squcsfvcvfy[.]ipfs[.]dweb[.]link/ hxxps://pub-5b40e70a41a4485f8ae926e12cb1faf7[.]r2[.]dev hxxps://fly2europetraval[.]com kalcij[.]cyberfolks[.]hr Exfiltration & Enrichment Endpoints Telegram Exfil Endpoint (Bot Token Present): hxxps://api[.]telegram[.]org/bot8253956668:AAEDUVImzy6z9kRj5VsLe_7AJhvDxizaLIY/sendMessage Telegram chat_id: 7933672071 Bot First Name: OrangePageWebmail Bot Username: localman404Bot #Phishing #EmailSecurity #Credentailharvesting #Webmail #KnowBe4 #Securityawareness
4
6
643
New Music Featuring @Spacely1z & @SUPAGAETA Out Now 🚨 Produced by Legendary Ipapi easternchild.lks.to/TwiddleF…
5
5
181
10 Oct 2025
my man launched his 2nd @raycast extension dealing w/ ip addresses 👏. coincidentally, on 7th oct i also updated my extension that uses ipapi dot is api to give ip/asn information; the extension is now available on windows! see ip, company, address, vpn and more info.
9 Oct 2025
My @ipinfo @raycast extension just got published to the store. You can: - Get information about your IP address - Get extensive information about any IP address - View all you IP address lookup history with their responses raycast.com/narghev/ipinfo
1
3
274
Replying to @IanSmiththe3rd
Yah ipapi manje ndopakadhakirwa zanu vanhu dsi vangotovauraya team re military risati rasvika chii chakadaro
2
29