Here's a list of 698 ACTIVE #KeitaroTDS domains identified via @ValidinLLC. While these domains aren't inherently harmful, they are frequently utilized for advertising campaigns, misinformation (DoppelGaenger), and harmful activities. Therefore, it might be prudent to block them as a precautionary measure.

https://github.com/Gi7w0rm/MalwareConfigLists/blob/main/Suspicious/KeitaroTDS.txt

MalwareConfigLists/Suspicious/KeitaroTDS.txt at main · Gi7w0rm/MalwareConfigLists

Just some lists of Malware Configs. Contribute to Gi7w0rm/MalwareConfigLists development by creating an account on GitHub.

GitHub

Observed a few possible upcoming #KeitaroTDS domains via Silent Push. Found in research, not observed in any compromised sites yet. #SocGholish #TA569.

designinteractiveplatform[.]club
ajaxapiendpoint[.]cloud
codingmastermindhub[.]club
apivuecomponent[.]com

Here's a deep dive into the history of the #KeitaroTDS, the malicious activity that's been documented over the course of about a decade, and the company's explanations for the extensive abuse of its product. https://www.techtarget.com/searchsecurity/feature/Why-the-Keitaro-TDS-keeps-causing-security-headaches
Why the Keitaro TDS keeps causing security headaches | TechTarget

Security vendors refer to Keitaro as a legitimate entity, but the company's TDS keeps getting flagged in threat reports.

Security
Most TDSes used by cybercriminals – BlackTDS, Prometheus, Parrot, 404 – are underground/black market tools. #KeitaroTDS is different. It's a commercial offering from a software company in Estonia that is viewed as legitimate by vendors like Microsoft.

New #SocGholish #KeitaroTDS domain:
eeatgoodx[.]com/gSyTvKB9
81[.]94.150.21
Keitaro Cookie: 7e4fc

Seen redirecting to Vextrio

Some nice #SocGholish #KeitaroTDS traffic observed tonight, also got a FBU from the same site, so it's serving both.

#KeitaroTDS infection chain:
victim site
-->
frightyserver[.]org/Bgkc244P
-->
winvipbonus[.]life/
-->
weapkd4.jarteaused[.]live
-->
Google play store

Using set-cookie 7e4fc

Detected #SocGholish #KeitaroTDS:

debasesingle[.]life/9hFXWz7m
debasesingle[.]life
193[.]106.175.40

Certificate not valid before 2024-01-11 09:26:11

Detected #SocGholish #KeitaroTDS:

biggerfun[.]org/HQn5BKC3
biggerfun[.]org
193[.]106.175.40

Detected #SocGholish #KeitaroTDS:

biggerfun[.]org/7FxjK9kQ
biggerfun[.]org
193[.]106.175.40

Detected #SocGholish #KeitaroTDS:

catsndogz[.]org/HpsQLk2N
catsndogz[.]org
193[.]106.175.40