Advertisement · 728 × 90

Posts by Florian Roth

Preview
Florian Roth ⚡️ on X: "Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe - file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll - network IOCs https://t.co/UlLkyZM6eC" / X Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe - file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll - network IOCs https://t.co/UlLkyZM6eC

FYI we got some IOCs from @rapid7.com
x.com/cyb3rops/sta...

2 months ago 5 0 0 0

Write-up says update traffic was selectively redirected to attacker-controlled servers & hints at a CN state group

If that’s the case, there must be at least some infra IOCs: IPs/FQDNs, redirect URL

Even if you don’t have package hashes, can you share infra IOCs so people can check proxy/DNS logs?

2 months ago 24 0 1 0

Never give up! We got your back

1 year ago 1 0 0 0
Post image

🫶😹

1 year ago 0 0 0 0
Post image
1 year ago 23 1 0 1