Shreshta - Uncovering badness

15 Followers
17 Following
41 Posts

We are a Cyber Threat Intelligence company based in India with a secret passion for uncovering badness in the DNS. Under this account, we share malicious domain names (phishing, C2, etc.)

All posts are TLP: CLEAR.

Websitehttps://shreshtait.com
Bloghttps://shreshtait.com/blog/
Linkedinhttps://www.linkedin.com/company/shreshta/
Githubhttps://github.com/shreshta-labs/

Good news for everyone involved in meetings where TLP classifications play a crucial role! I've just updated my repository with the latest, second edition of the TLP Classification Meeting Posters. These are handy tools to explicitly display the TLP classification in use during your meetings.

🔗 Grab the PDF and ODT versions here - https://git.foo.be/adulau/tlp-meeting

Updates are welcome, like better design, translation or alike.

#tlp #classification #meeting #infosec #TrafficLightProtocol #csirt #cert

tlp-meeting

Traffic Light Protocol - meeting classification

Forgejo: adulau git carryall - git.foo.be

Did you know that #czechia put an end date to the IPv4 infrastructure of the state? They will stop using IPv4 in 6 June 2032! Only DNSSEC and #IPv6 after that! https://konecipv4.cz/en/

Bye bye IPv4!!
#ipv4 #ipv4end #ipv6only

Homepage - Konec IPv4

We’ve been tracking phishing campaigns targeting online shopping users in India.

Aside from the threat actors obtaining PII, debit/credit card details, social engineering users to install(sideload) an APK features prominently.

Full blog post - https://shreshtait.com/blog/2024/01/online-shopping-frauds-in-india/

#threatintel #phishing #socialengineering #threatintelligence

New breach: Indian ISP Hathway allegedly had 4.7M unique email addresses and hundreds of GB of data breached last month. The incident included name, physical and IP address, password hashes and support tickets. 50% were already in @haveibeenpwned. More: https://restoreprivacy.com/hacker-allegedly-holds-data-of-41-million-hathway-customers/
Hacker Allegedly Holds Data of 41 Million Hathway Customers

A threat actor is selling what he claims to be the personal data of 41.5 million customers of Hathway on a hacking forum for $10,000.

RestorePrivacy

We just published a blog post on the "Police Trojan" which impersonates the National Crime Records Bureau. While it primarily targets and affects general users, I have witnessed its impact on them.

The "Police Trojan" is an old scareware that continues to exist in 2024, targeting users in India. The website messaging uses social engineering tactics to scare the user that the Government of India knows about the user's access to pornographic content and that the only way to stay out of jail is by making a payment of Rs. 33900.

The impact of cyber crime isn't just about financial crime, data, etc. It's also about its effect on the user's state of mind.

Full blog post and analysis - https://shreshtait.com/blog/2024/01/national-crime-records-bureau-your-browser-has-been-locked/

#threatintel #threatintelligence #scareware #scam

download-telegram[.]online serving an Adware android apk: telegram-nofilter.apk

sha-256: e6784c8efaede4f523d694bec960d2bbcb244b5e480a63cb7fa5694100ff25ce

Domain name was registered on 2023-11-10 and is pointing at AS47583

#threatintelligence #threatintel

@feature They have also released the ebook(pdf) recently. That's tempting since it will constantly get updated.

A new addition to our office #infosec bookshelf.

#osint #threatintelligence #uncoveringbadness

Suspicious domain name decathlonsportsindia[.]in registered on 2024-01-01.

The domain name is currently pointing at AS46606.

#threatintel #phishing