Set of most likely #Ryuk infrastructure registered on 10/20:

servicereader[.]com (45.153.241[.]158, rel files 6c4dacbefca90dad7ef318604e635e89, ed0f520d410a684c6d0548dbf4caea98)
backups1helper[.]com (45.153.241[.]134)...

In @ThreatConnect: app.threatconnect.com/auth/incident/…
Cont...
driver-boosters[.]com (45.153.241[.]139)
driver1downloads[.]com (45.153.241[.]138)
service-hel[.]com (45.153.241[.]153)
service1update[.]com (45.153.241[.]14)
service1view[.]com (45.153.241[.]141)...
servicehel[.]com (45.153.241[.]146)
top3servicebooster[.]com (45.147.231[.]222)
view-backup[.]com (45.153.241[.]167)

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Kyle Ehmke

Kyle Ehmke Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @kyleehmke

14 Jan
So just to be explicit about our research @ThreatConnect, we initially came across the cubenergy-my-sharepoint[.]com by exploiting some consistencies that we've seen in previous Fancy Bear infrastructure.
To be specific, the use of a PositiveSSL certificate in conjunction with a Sharepoint-related string, has been used several times previously by Fancy Bear and not widely seen elsewhere.
Notably, that was seen in several of the Fancy Bear domains spoofing NGOs that Microsoft sinkholed earlier this year, like soros-my-sharepoint[.]com and transparencyinternational-my-sharepoint[.]com.
Read 9 tweets
16 Dec 19
Heads up on some suspicious domains spoofing UKR organizations registered in the last year:
cubenergy-my-sharepoint[.]com
dpkshodnya-mysharepoint[.]com
kub-gas[.]com
kvatral95[.]com
my-ukr[.]net

More context in @ThreatConnect: app.threatconnect.com/auth/campaign/… (1/6)
Relevant hosting IPs:
91.132.139[.]155
184.164.139[.]238
94.158.245[.]28
185.174.174[.]34

Also mail server mail.kvatral95[.]com is hosted on a probable dedicated server at 45.89.175[.]235. (2/6)
Identified registrants:
tgamelin@barid[.]com
isobelmoss@barid[.]com
fvjdjf3@barid[.]com (3/6)
Read 6 tweets
26 Jun 19
On the info ops front, the Facebook page for The Right News seemingly serves as an echo chamber for The Daily Wire. Based on that page and WHOIS history for therightnews[.]net, The Right News probably is actively working on behalf of The Daily Wire without openly stating so. 1/15
In terms of background, The Right News' Facebook page was created on 11/22/13, has over 193k followers, and claims to be a Media/News company. The page posts political commentary, conservative articles, and memes. 2/15
The website listed on The Right News' Facebook page -- therightnews[.]net -- was also registered on 11/22/13 using privacy protection. Historical versions of the domain show that it was used similarly -- to share conservative, political commentary. 3/15
Read 16 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!