Monday, September 18, 2023
Yavor Kolev - Part Two
Applying for the Rewards for Justice on the Conti Ransomware Gang Program
Exposing the Bulgarian Cyber Army Cyber Threat Actor
Anonymous Bulgaria is your typical Anonymous “franchise” Anonymous hackers model where you have a group of people doing web site defacements and compromises of legitimate web sites and infrastructure and actually blame a bigger cause that they don’t really have anything to do with and don’t understand or know anything about it.
The ultimate goal here would be for the group to gain momentum including to attract followers where the ultimate goal would be to spread a message that they don’t often understand or have anything to do with low profile DDoS attacks or cyber attack attempts similar and typical to the Anonymous hackers collective idea.
Is it script kiddies or low profile wannabe hacker groups that basically have one social media account and are capable of launching low profile cyber attack attempts that often make the news or is it a bigger conspiracy where everyone doing the same can outsource their responsibility for doing it to the entire “idea” which basically represents an Anonymous set of people attempting to do low profile cyber attack attempts?
Let’s go for the first part.
The important part when dealing with this type of low profile threat actor is to usually keep track of their activities including social media profiles and activity and look for additional clues in terms of current and ongoing cyber attacks and most importantly look for additional clues such as personally identifiable information which would be later on used in a possible cyber threat actor attribution campaigns including for the actual enrichment of this PII for the purpose of looking for additional clues in terms of doing threat actor infrastructure reconnaissance on your way to look for additional clues such as related malicious and fraudulent including cybercrime activity including domains personally identifiable email address accounts or related social media accounts.
The ultimate goal when collecting these would be yo either build a database of the threat actor in question which could lead to a possible commercial or community driven project venture or to assist fellow researchers and Law Enforcement on its way go track down monitor and prosecute these individuals.
In this article I’ll discuss in-depth the Anonymous Bulgaria hacker franchise that basically just like many other Anonymous franchises across the globe basically represent low profile cyber attack attempts type of threat actors and will provide personally identifiable information on their online whereabouts.
Some of the other Bulgarian Web site defacement groups that are known to work and cooperate with Bulgarian Cyber Army include BG Worm, MTH Soft, Hack3D TeaM and EvilHack and Anonymous Bulgaria.
What’s specifically interesting about Bulgarian Cyber Army is that the group appears to be still and currently active and operational based on some of their latest web site defacement and Facebook activity.
Personally Identifiable Information on Bulgarian Cyber Army:
hxxp://facebook.com/hack3dteam
hxxp://vimeo.com/user16145338/videos
Personally Identifiable Information on Hack3d Team:
MaStErHaCk
Slackera
Tiger
RTFM
Sspdf11
PanteliX
Metalqear
MaStErChO
W!PS
TraferA
3ikmy
r00tkit
The Godfather
razora911
Personally Identifiable Information on EvilHack:
EvilHack[.]hmamail.com
anonyops[.]abv.bg
genadi_100[.]abv.bg
evil_hack[.]abv.bg
evilhack[.]bk.ru
evilhack000[.]gmail.com
clangrf[.]abv.bg
hxxp://anonymous-world.free.bg
hxxp://web-dangerous.free.bg
hxxp://evilhack-official.blogspot.com/
Personally Identifiable Information on Anonymous Bulgaria:
NoTolerance
Hades
PsychoPatternz
rootheR_
hxxp://anonbg.info
OSINT Round-Up of Russia-Based High-Profile Cybercriminals
In my line of work in specific when doing research and analysis I always stick to a common concept which has to do with the fact that “everything that can be found has already been found somewhere online”. Sticking to this basic methodology the only thing an individual or a researcher has to do is to look up the facts including all the relevant and necessary technical information on the individual or case they’re working on and basically come up with a proper analysis relying on publicly obtainable and publicly accessible information on their topic of interest.
In this rather long OSINT analysis article I’ll do a OSINT roundup of Russia-based high-profile ransomware cybercriminals with the idea to share my research and analysis on the topic and potentially assist other researchers and vendors including U.S Law Enforcement on its way to properly track down and monitor and prosecute these cybercriminals.
\I’ll begin this analysis with an emphasis and actual OSINT research and analysis on the Conti Ransomware Group in the context of demonstrating what real-time OSINT is which a pretty good and decent methodology that I’ve been relying and using over the years which works.
It all began with an internally leaked and made publicly accessible Conti Ransomware Gang’s internal communication where a security researcher or a set of security researchers appear to have compromised their internal server and have been collecting conversation logs between the cybercriminals which they later on made publicly accessible on Twitter in a specific for the purpose account that basically included direct download links to their internal communication.
From an OSINT perspective the first thing a researcher should do is to do their best to obtain access to these conversation logs and attempt to preserve them for current and future use which is something that I did almost immediately considering the possibility to monitor and track down who the actual individuals behind this massive ransomware campaign are.
The results? I’ve managed to successfully identify some of key individuals behind the Conti Ransomware Gang in terms of top management where my believe is that although it was a hired or outsourced “know-how” in the beginning quickly matured into a cybercrime enterprise where everyone who wanted to could join on a “franchise” based model and just do their work and earn fraudulently and maliciously obtained revenue from legitimate companies who are having their networks compromised and sensitive data and information made publicly accessible or basically encrypted in a way making it impossible for the actual organization and company to use.
What is the Conti ransomware gang up to in terms of top management? It appears that the gang’s top management in a way is involved in the fashion industry with the idea that some of the screenshots that I obtained and processed and analyzed which were leaked internally in the form of exchange of URLs between the gang’s members lead me to believe that the gang is involved in either investing in fashion brands or actually working on such with several successful public OSINT analyses on the topic where I’ve managed to identify some of the fashion brands behind the Conti Ransomware Gang’s top management and my goal here is to present the actual findings with the idea to bring this fact to more light in the context of providing information on the activity of the Conti Ransomware Gang’s top management members.
So basically once I came across their internal leaked communication made publicly accessible on Twitter I immediately aimed to obtain access to the leaked internal information of the Conti ransomware gang and preserve it before it goes online so that I can later on work with it and successfully produce the analysis including all the screenshots managed and operated by the Conti ransomware gang and here’s how I did it.
Basically once I obtained access to their internal leaked communication which was made publicly accessible I data mined the internal leaked communication looking for personally identifiable email address accounts and related URLs with success which is where I automatically visited these URLs which I data mined in the Conti ransomware gang’s internal leaked communication and basically grabbed all the live URLs information which is where the analysis and the screenshots including the actual report come from which I produced and have been working on to produce exclusively for fellow researchers and vendors including U.S Law Enforcement in order to assist everyone on their way to properly track down monitor and prosecute.
Sample Internally Leaked URLs Courtesy of the Conti Ransomware Gang Obtained Using Public Sources
There are several other fashion brand themed screenshots which I also managed to obtain which appear to be directly related to the Conti ransomware gang.
Here are some of the “upcoming brands” courtesy of the Conti Ransomware Gang obtained using real-time OSINT and relying on their internally leaked communications proving the gang including its top management is into fashion brands and the industry:
Here’s some personally identifiable information on some of the brands using OSINT and public sources of information:
Leylo
Top Management Includes:
tel:+79126331303
Мария Сергеевна Ермолаева/Maria Ermolaeva (Chudnova)
Birthday: 5 July
hxxp://vk.com/id7326657
Maria Ermolaeva
Birthday: 5 July
г. Екатеринбург, ул. Репина, 95, офис 116
Телефон: +7 (912) 633–13–03
Е-mail: info@leylo.ru
leyloekb@gmail.com
hxxp://leylo.ru/
Danil Ermolaev
hxxp://vk.com/id4874860
Birthday: 7 August 1989
Sample Top Management Photos and Personally Identifiable Information of the Conti Ransomware Gang’s charity fund:
Tamila Kerimova
Conti Ransomware Gang’s Top Management Team
hxxp://impulse-life.ru
Tamila Kerimova
— Birthday: 4 April 1986
— hxxp://vk.com/id6515862
— Planet for beauty and development
— hxxp://irinaverhusha.com
Тел: +7 926 536–63–68
Email: impulse.life2020@gmail.com
Sample Internally Leaked Screenshots Courtesy of the Conti Ransomware Gang:
Sample Conti Ransomware Gang’s Internal Leaked Screenshots
Sample Related Internally Leaked Screenshots Courtesy of the Conti Ransomware Gang:
Sample Conti Ransomware Gang’s Internal Leaked Screenshots
Sample Conti Ransomware Gang’s Internal Leaked XMPP/Jabber Account IDs:
LiamNeeson@jabber.ru
arb_reserved@ubuntu-jabber.de
battletoad@jabbim.sk
begemot_sun@jabber.ru
crazy_digger@jabber.ru
gfh6776@jabb.im
ivanalert@jabber.ru
landslide@jabb.im
new_henry@jabber.cz
scopehope@jabb.im
ugly@1jabber.com
valerius2k@jabber.ru
vdx17@jabber.ru
337788@exploit.im
asteradminn@sure.im
benalen@exploit.im
bio@yax.im
crunch@exploit.im
daiverjm@exploit.im
dmanager@exploit.im
fuckUSAhahaha@exploit.im
fuckusa@exploit.im
gfh6776@jabb.im
goldcoin@exploit.im
jackiedugn@exploit.im
landslide@jabb.im
martiniden123@exploit.im
mr_loki@exploit.im
posi_tron@exploit.im
pravdazanami@exploit.im
rob0660@conversations.im
scopehope@jabb.im
soulst@exploit.im
time_t@exploit.im
trqa23rt@exploit.im
volhvb@exploit.im
yastreb@exploit.im
SamCodeSign@xmpp.jp
alieelu@xmpp.jp
baton@xmpp.jp
batono@xmpp.jp
benalien@xmpp.jp
cosm123@xmpp.jp
graddds@xmpp.jp
guliver@xmpp.sh
liamliam@xmpp.jp
ohmygod728@xmpp.jp
Denis Gennadievich Kulkov
Personal Photo of Denis Gannadievich Kulkov
Among the actual domains known to be part of the Try2Check cybercriminals enterprise include:
hxxp://try2services[.]pm
hxxp://try2services[.]cm
hxxp://try2services[.]vc
including the following domain:
hxxp://just-buy[.]it
including the following two ICQ numbers 855377 and 555724 and let’s don’t forget his personal email address accounts obtained using public sources which are polkas@bk.ru nordexin@ya.ru
and it doesn’t get any better than this as we’ve got a pretty good and informative domain portfolio registered by the same individual based on public information sharing the same domain registration details such as for instance hxxp://worldissuer[.]biz which actually are:
hxxp://cloud-mine[.]me
hxxp://gpucloud[.]org
hxxp://hyperhost[.]info
hxxp://miservers[.]info
hxxp://carterdns[.]com
hxxp://reshipping[.]us
hxxp://keyserv[.]org
hxxp://antmining[.]biz
hxxp://investmentauditor[.]com
hxxp://sunnylogistics[.]us
hxxp://try2services[.]cm
hxxp://greatwallhost[.]net
hxxp://jaqjckugrfffqa[.]com
hxxp://numberoneforyou[.]net
hxxp://getprofitnow[.]biz
hxxp://avsdefender[.]com
hxxp://spyware-defender[.]com
hxxp://beta-dns[.]net
hxxp://mpm-profit-method[.]com
hxxp://public-dns[.]us — related including this
hxxp://adobe-update[.]net — Email: krownymaradonna@onionmail.org related domains known to have been involved in the campaign include — hxxp://amazon-clouds[.]com; hxxp://microsoft-clouds[.]net; hxxp://telenet-cloud[.]com; hxxp://vmware-update[.]com
hxxp://kwitri[.]net
hxxp://dcm-trade[.]com
hxxp://karoospin[.]biz
hxxp://fastvps[.]biz
Evgeniy Mikhaylovich Bogachev
Sample Personal Photos of Evgeniy Mikhaylovich Bogachev:
Slavik’s IM and personal email including responding IP:
bashorg@talking.cc — 112.175.50.220
Personal Address:
Lermontova Str. Anapa, Russian Federation
Instant Messaging account:
lucky12345@jabber.cz
Related name servers:
ns.humboldtec.cz — 88.86.102.49
ns2.humboldtec.cz — 188.165.248.173
Related domains part of a C&C phone-back location:
hxxp://slaviki-res1.com
hxxp://slavik1.com — 91.213.72.115
hxxp://slavik2.com
hxxp://slavik3.com
Slavik’s primary email:
luckycats2008@yahoo.com
Slavik’s ICQ numbers:
ICQ — 42729771
ICQ — 312456
Related emails known to have participated in the campaign:
alexgarbar-chuck@yahoo.com
bollinger.evgeniy@yandex.ru
charajiang16@gmail.com
Related domains known to have participated in the campaign:
hxxp://visitcoastweekend.com — 103.224.182.253; 70.32.1.32; 192.184.12.62; 141.8.224.93; 69.43.160.163
hxxp://incomeet.com — 192.186.226.71; 66.199.248.195
hxxp://work.businessclub.so
Real Name: Galdziev Chingiz
Related domains known to have participated in the campaign:
hxxp://fizot.org
hxxp://fizot.com — 50.63.202.35; 184.168.221.33
hxxp://poymi.ru — 109.206.190.54
Related name servers known to have participated in the campaign:
ns1.fizot.com — 35.186.238.101
ns2.fizot.com
Related domain including an associated email using the same name server:
hxxp://averfame.org — harold@avereanoia.org
Google Analytics ID: UA-3816538
Related domains known to have participated in the campaign:
hxxp://awmproxy.com
hxxp://pornxplayer.com
Related emails known to have participated in the campaign:
fizot@mail.ru
xtexgroup@gmail.com
xtexcounter@bk.ru
Related domains known to have responded to the same malicious and fraudulent IP — 178.162.188.28:
hxxp://dnevnik.cc
hxxp://xvpn.ru
hxxp://xsave.ru
hxxp://anyget.ru
hxxp://nezayti.ru
hxxp://proproxy.ru
hxxp://hitmovies.ru
hxxp://appfriends.ru
hxxp://naraboteya.ru
hxxp://naraboteya.ru
hxxp://awmproxy.com
hxxp://zzyoutube.com
hxxp://pornxplayer.com
hxxp://awmproxy.net
hxxp://checkerproxy.net
Related domains known to have participated in the campaign:
hxxp://fizot.livejournal.com/
hxxp://russiaru.net/fizot/
Instant Messaging Account:
ICQ — 795781
Related personally identifiable information of Galdziev Chingiz:
hxxp://phpnow.ru
ICQ — 434929
Email: info@phpnow.ru
Related domains known to have participated in the campaign:
hxxp://filmv.net
hxxp://finance-customer.com
hxxp://firelinesecrets.com
hxxp://fllmphpxpwqeyhj.net
hxxp://flsunstate333.com
Related individuals known to have participated in the campaign:
Slavik, Monstr, IOO, Nu11, nvidiag, zebra7753, lexa_Mef, gss, iceIX, Harderman, Gribodemon, Aqua, aquaSecond, it, percent, cp01, hct, xman, Pepsi, miami, miamibc, petr0vich, Mr. ICQ, Tank, tankist, Kusunagi, Noname, Lucky, Bashorg, Indep, Mask, Enx, Benny, Bentley, Denis Lubimov, MaDaGaSka, Vkontake, rfcid, parik, reronic, Daniel, bx1, Daniel Hamza, Danielbx1, jah, Jonni, jtk, Veggi Roma, D frank, duo, Admin2010, h4x0rdz, Donsft, mary.J555, susanneon, kainehabe, virus_e_2003, spaishp, sere.bro, muddem, mechan1zm, vlad.dimitrov, jheto2002, sector.exploits
Related Instant Messaging accounts and emails known to have participated in the campaign:
iceix@secure-jabber.biz
shwark.power.andrew@gmail.com
johnlecun@gmail.com
gribodemon@pochta.ru,
glazgo-update-notifier@gajim.org
gribo-demon@jabber.ru
aqua@incomeet.com
miami@jabbluisa.com
um@jabbim.com
hof@headcounter.org
theklutch@gmail.com
niko@grad.com
Johnny@guru.bearin.donetsk.au
petr0vich@incomeet.com
mricq@incomeet.com
T4ank@ua.fm
tank@incomeet.com
getreadysafebox.ru
john.mikleymaiI.com
aIexeysafinyahoo.corn
rnoscow.berlin@yahoo.com
cruelintention@email.ru,
bind@ernail.ru
firstmen17@rarnbler.ru
benny@jabber.cz
airlord1988@gmail.com
bxl@hotmail.com
i_amhere@hotmail.fr
daniel.h.b@universityofsutton.com
princedelune@hotmail.fr
bxl_@msn.com
danibxl@hotmail.fr
danieldelcore@hotmail.com.
d.frank@jabber.jp
d.frank@0nl1ne.at
duo@jabber.cn
fering99@yahoo.com
secustar@mail.ru
h4x0rdz@hotmail.com
Donsft@hotmail.com
mary.j555@hotmail.com
susanneon@googlemail.com
kainehabe@hotmail.com
virus_e_2003@hotmail.com
spanishp@hotmail.com
sere.bro@hotmail.com
lostbuffer@hotmail.com
lostbuffer@gmail.com
vlad.dimitrov@hotmail.com
jheto2002@gmail.com
sector.exploits@gmail.com
Aleksei Belan
Sample Personal Photo of Aleksei Belan
Sample domains known to have been involved in the campaign:
Sample personally identifiable email address accounts known to have been involved in the campaign:
moy.yawik@gmail.com
moy-yawik@bk.ru
Sample known responding IPs known to have been involved in the campaign include:
77.221.159.235
62.76.182.72
62.76.190.68
185.50.25.13
104.18.41.143
198.54.117.212
104.18.40.143
Mykhaylo Sergiyovich Rytikov
Sample Personal Photo of Mykhaylo Sergiyovich Rytikov
Known domains affiliated with AbdAllah Internet Hizmetleri:
hxxp://tiket[.]cc
hxxp://abdulla[.]cc
hxxp://privateforum[.]cn — upomajuliya745@gmail.com; xpj88kf@gmail.com; 316411856@qq.com
Related known domains affiliated with AbdAllah Internet Hizmetleri:
hxxp://ns1[.]srv4u[.]biz
hxxp://bulletproof-service[.]com — Email: support@hosting-offshore.biz — 202.83.212.250
hxxp://tarahost[.]net — Email: konstantin@karyaev.com — 89.108.73.93
Related domains known to have been registered by the same domain registrant:
hxxp://all-mafia[.]net
hxxp://shampanskoe[.]info
hxxp://mashost[.]org
hxxp://flexi-domains[.]com
hxxp://5pagess[.]net
hxxp://extrasoft[.]biz
hxxp://golovolomka[.]info
hxxp://optical-coatings[.]info
hxxp://polevoi[.]info
hxxp://belorussia[.]info
hxxp://3alab[.]com
hxxp://prezervativ[.]org
hxxp://brodyaga[.]net
hxxp://skramedia[.]com
hxxp://tarafree[.]com
hxxp://mp3-mmf[.]com
hxxp://myproga[.]net
hxxp://extrahost[.]su
hxxp://garanthost[.]com
hxxp://grand-host[.]net
hxxp://technormativ[.]info
hxxp://xp-hosting[.]net
hxxp://kredits[.]cn
hxxp://tarahost[.]biz
hxxp://tarahost[.]org
hxxp://optical-coatings-design[.]info
hxxp://extrasoft-outsourcing[.]info
hxxp://pm-tost[.]net
hxxp://pm-sotovik[.]net
hxxp://pm-ranlix[.]net
hxxp://pm-holland[.]net
hxxp://swlu[.]info
hxxp://valdiss[.]info
hxxp://karyaev[.]com
hxxp://x450[.]info
hxxp://grand-host[.]biz
hxxp://flexi-classifieds[.]com
hxxp://flexi-sitebuilder[.]com
hxxp://flexi-projects[.]com
hxxp://bloggast[.]info
hxxp://pereezd-pro[.]info
hxxp://eduaction[.]info
hxxp://wmnakovalnya[.]com
hxxp://retro80x[.]com
hxxp://tarafree[.]net
hxxp://skramedia[.]org
hxxp://oldactors[.]net
hxxp://tarahost[.]net
hxxp://janimation[.]net
hxxp://tarahost[.]com
hxxp://skramedia[.]biz
hxxp://vv-want[.]info
hxxp://skramedia[.]net
hxxp://olimp-sport[.]com
hxxp://youhouse[.]biz
hxxp://kroleki[.]com
hxxp://extrasoft-projects[.]info
hxxp://zelenaya[.]com
hxxp://cazinowm[.]com
hxxp://extrasoft-outsourcing[.]net
Related domains known to have been involved with AbdAllah Internet Hizmetleri:
hxxp://magic-jackpot-cas[.]com
hxxp://euro-vip-casino[.]com
hxxp://royal-casino-vip[.]com
hxxp://sexrusfuck[.]com
hxxp://royal-cas-vip[.]com
hxxp://2400-usd-casino[.]com
hxxp://royalcasino-vip[.]com
hxxp://2400usd-casino[.]net
hxxp://eurocasino-vip[.]com
hxxp://sinlife[.]cn
hxxp://byron-consulting-group[.]com
hxxp://28–07[.]com
hxxp://28–07[.]net
hxxp://job-consults[.]org
hxxp://837–86[.]org
hxxp://expressdeal[.]biz
hxxp://cron[.]li
hxxp://crons[.]cc
hxxp://cronos[.]mn
hxxp://crinc[.]mn
hxxp://crinc[.]li
hxxp://ultrasmoke[.]cn
hxxp://supersmoke[.]cn
hxxp://globalsmoke[.]cn
hxxp://937–86[.]org
hxxp://cronco[.]li
hxxp://tradegroup-ha[.]com
hxxp://ha-tradegroup[.]com
hxxp://crinc[.]jp
hxxp://tradegroup-ha[.]net
hxxp://investmentcron[.]cn
hxxp://glb-soft[.]com
hxxp://croninv[.]cc
hxxp://cronis[.]cn
hxxp://crons[.]ac
hxxp://cronn[.]eu
hxxp://dkebooks[.]com
hxxp://cronoi[.]cc
hxxp://jieod[.]com
hxxp://midgejs[.]com
hxxp://crin[.]ac
hxxp://aoejf[.]com
hxxp://yseac[.]com
hxxp://kaserid[.]com
hxxp://crin[.]cc
hxxp://jekdoe[.]com
hxxp://ujeose[.]com
hxxp://masiwer[.]com
hxxp://reusiwe[.]com
hxxp://kaoeds[.]com
hxxp://iwoser[.]com
hxxp://planet0day[.]biz
hxxp://xeirod[.]com
hxxp://neusoas[.]com
hxxp://geoepd[.]com
hxxp://efuyr[.]com
hxxp://ziude[.]com
hxxp://polsenstanford[.]com
hxxp://heyud[.]com
hxxp://woqkr[.]com
hxxp://seiudr[.]com
hxxp://aosier[.]com
hxxp://dueor[.]com
hxxp://crins[.]ac
hxxp://verbespecially[.]com
hxxp://fivejoy[.]com
hxxp://riverwomen[.]com
hxxp://trianglesentence[.]com
hxxp://floorside[.]com
hxxp://developtail[.]com
hxxp://womanfinish[.]com
hxxp://alwaysfell[.]com
hxxp://differcollect[.]com
hxxp://goodalso[.]com
hxxp://kingbrought[.]com
hxxp://findcharacter[.]com
hxxp://chanceexpect[.]com
hxxp://beardictionary[.]com
hxxp://forwardfield[.]com
hxxp://tinydown[.]com
hxxp://jobwhether[.]com
hxxp://numeralcity[.]com
hxxp://cronin[.]jp
hxxp://equalcatch[.]com
hxxp://streamwho[.]com
hxxp://selectmonth[.]com
hxxp://propercame[.]com
hxxp://grewsoil[.]com
hxxp://townslip[.]com
hxxp://stationheavy[.]com
hxxp://charactereven[.]com
hxxp://milk0soft[.]com
hxxp://goldverb[.]com
hxxp://windowlisten[.]com
hxxp://bqgqnfc[.]cn
hxxp://wrbhnuw[.]cn
hxxp://a9da6[.]org
hxxp://04ccc408[.]org
hxxp://bdb7beb6[.]org
hxxp://scalespread[.]com
hxxp://thencloud[.]com
hxxp://figurespoke[.]com
hxxp://fullfraction[.]com
hxxp://propertytall[.]com
hxxp://beautyfig[.]com
hxxp://hadover[.]com
hxxp://followsalt[.]com
hxxp://staysay[.]com
hxxp://herexcept[.]com
hxxp://thanscore[.]com
hxxp://humanthus[.]com
hxxp://branchfelt[.]com
hxxp://areacountry[.]com
hxxp://meetduring[.]com
hxxp://movestood[.]com
hxxp://stillverb[.]com
hxxp://suggesteye[.]com
hxxp://preparebut[.]com
hxxp://hurrysound[.]com
hxxp://cookcompare[.]com
hxxp://0daycod[.]biz
hxxp://europeansmoke[.]cn
hxxp://sprybog[.]net
hxxp://taybaol[.]com
hxxp://polsenstanford[.]com
hxxp://bconsgroup[.]com
GRU’s Unit 74455 “NotPetya”
Sample screenshots of the GRU’s Unit 74455 “NotPetya” malware gang obtained using public sources:
Igor Dehtyarchuk
Sample Personal Photo of Igor Dehtyarchuk
Sample emails known to have been involved in the campaign include:
abuse@shopsn.su
dimetr801@mail.ru
admin@4server.su
ssg.apple77@gmail.com
Sample domains known to have been involved in the campaign include:
hxxp://4server.su
hxxp://csgoacc.ru
hxxp://marketsales.su
hxxp://zarmo.su
hxxp://4domains.su
hxxp://ebayshop.su
hxxp://globus-base.su
hxxp://broshop.su
hxxp://deer.su
hxxp://shopsn.su
hxxp://cjmarket.net
hxxp://vkaccounts.com
hxxp://cheapaccounts.su
hxxp://ytuber.su
hxxp://vds4u.su
hxxp://4host.su
hxxp://tgshop.su
hxxp://xn — 227-qdd4dec.xn — p1acf
hxxp://4dedic.su
hxxp://time-hack.su
hxxp://4ns.su
Sample screenshot:
Oleksandr Vitalyevich Ieremenko
Sample Personal Photo of Oleksandr Vitalyevich Ieremenko
Handle: Zl0m; Lamarez; Ded.MCz; l@m@rEz
Email: lamarez@mail.ru; uaxakep@gmail.com — xeljanzusa.com — 62.109.25.228 (hxxp://www.secureworks.com/research/point-of-sale-malware-threats); 62.109.1.69
Commpany: 2016 Кзерокс
Phone: +7 951 366 17 17
ICQ: 123424
Web Money: 258807111393
Related URLs:
hxxp://ageline.ru/lamarez.php
hxxp://k0x.ru/md5.salt.tx
hxxp://k0x.ru/_bot.exe — 82.146.60.59
hxxp://k0x.ru/black_energy_31337_/stat.php
hxxp://k0x.ru/siicywu36dswh/addddos.php
hxxp://xtoolz.ru
hxxp://cup.su
hxxp://xwarez.us
hxxp://kinoafisha.ua/news/lamarez-was-here
hxxp://post-tracker.ru
hxxp://zr.ru
hxxp://business-gazeta.ru
hxxp://proshkolu.ru
hxxp://opengost.ru
hxxp://krokha.ru
hxxp://eurolab.ua
hxxp://newsdon.info
hxxp://dirt.ru
hxxp://anime-zone.ru
hxxp://rus.kg
hxxp://badger.ru
hxxp://fedpress.ru
hxxp://carsguru.net
hxxp://findfood.ru
hxxp://beboss.ru
hxxp://vidal.ru
hxxp://reghelp.ru
hxxp://rabotagrad.ru
hxxp://proshkolu.ru
hxxp://muztorg.ru
hxxp://mirf.ru
hxxp://medgorodok.ru
hxxp://dobrota.ru
hxxp://cooksa.ru
hxxp://consmed.ru
hxxp://buro247.ru
hxxp://3dmir.ru
hxxp://novorus.info
hxxp://kidbe.ru
hxxp://eknigi.org
hxxp://2×2.su
Exante LTD — XNT Ltd. — exante.eu
Danil Potekhin
Sample personal Web site: hxxp://agressivex.com
Sample personal email: potekhinl4@bk.ru
Sample MD5 known to have participated in the campaign:
MD5: ecb347518230e54c773646075e2cc5ea269dcf8304ad102cee4aae75524e4736
Happy research!
Blog Archive
About Me
- Dancho Danchev
- Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
Total Pageviews
Labels
- 29A (1)
- 29A Virus Coding Group (1)
- 419 Scam (4)
- AbdAllah (1)
- Abdallah Internet Hizmetleri (1)
- Able Danger (1)
- Abuse Department (1)
- Active Security Monitor (1)
- Advance Fee Scam (2)
- Advanced Persistent Threat (2)
- Advertising (3)
- Adware (3)
- Affiliate Network (7)
- Ahmad Al Agha (1)
- Al Qaeda (3)
- Aleksandr Zhukov (1)
- Allied Group Inc (1)
- Amazon AWS (1)
- ANA Spoofer Project (1)
- Android (2)
- Anonymity (31)
- Anonymizer (1)
- Anonymous (1)
- Anonymous Hacking Collective (1)
- Anti-Phishing Group (1)
- Antivirus (6)
- Antivirus Signatures (3)
- Anton Nikolaevich Korotchenko (1)
- AOL (2)
- API (1)
- Apple (1)
- APT (1)
- Aqua ZeuS Gang (1)
- Armadillo Phone (2)
- Ashiyane Digital Security Team (5)
- ASProx (2)
- Astalavista (7)
- Astalavista Security Group (1)
- Astalavista.box.sk (4)
- ATM Skimmer (1)
- ATS (1)
- Australia (1)
- Authentication (2)
- Avalance Botnet (2)
- Avast (1)
- Background Check (1)
- BadB (1)
- Bahama Botnet (1)
- BakaSoftware (1)
- Bantu (1)
- BBC (1)
- Bebo (1)
- Bed Time Reading (1)
- Behrooz Kamalian (2)
- Best Practices (2)
- BGP (1)
- Big Brother (3)
- Bill Gates Botnet (1)
- Biography (1)
- Biometrics (1)
- Bitcoin (1)
- Bjorn Andreasson (1)
- Black Energy (1)
- Blackhat SEO (27)
- Blood and Honor (1)
- Blood and Honor Bulgaria (1)
- Boeing (1)
- Bogus Account (1)
- bother (1)
- Botners (1)
- Botnet (160)
- Botnets (21)
- Box.sk (1)
- Brian Krebs (1)
- Brute-Forcing (1)
- Bulgaria (18)
- Bulgaria Law Enforcement (14)
- Bulgarian Cyber Army (1)
- Bulgarian Cyber Army Hacking Group (1)
- Bullet Proof Hosting (1)
- Bust (1)
- C4I (2)
- CALEA (1)
- Caller ID (1)
- Caller ID Spoofer (1)
- Candid Wuest (1)
- CAPTCHA (2)
- Career Enrichment (1)
- Cash Transfers (1)
- CCTV (1)
- CDT (1)
- Cell Phone Monitoring (1)
- Cell Phone Surveillance (1)
- CellDEK (1)
- Censorship (28)
- Center for Democracy and Technology (1)
- CERT (1)
- Cheyenne Mountain Operations Center (1)
- China (9)
- China Eagle Union (1)
- CIA (15)
- CipherTrust (1)
- Classified Information (1)
- Client-Side Exploits (30)
- Client-Side Vulnerabilities (30)
- CNO (1)
- COCOM (1)
- Cold War (1)
- COMINT (1)
- Competitive Intelligence (3)
- Compliance (3)
- Computer Crime Survey (1)
- Computer Network Operation (1)
- Conficker (1)
- Confidential Connections (1)
- Conspiracy (1)
- Conspiracy Theory (1)
- Conti (8)
- Conti Ransomware (7)
- Conti Gang (8)
- Conti Ransomware (7)
- Conti Ransomware Gang (8)
- Cookies (1)
- CoolWebSearch (4)
- Corporate Risk Management (4)
- Counter Espionage (2)
- Counter Intelligence (1)
- Credit Cards (7)
- Crimeware (3)
- Critical Infrastructure (2)
- Crusade Affiliates (1)
- Crypters (1)
- Cryptography (6)
- Cryptome (2)
- Cryptoviral Extortion (2)
- CSIA (2)
- CVE (1)
- Cyber Attack (61)
- Cyber Espionage (73)
- Cyber Insurance (1)
- Cyber Jihad (34)
- Cyber Militia (7)
- Cyber Security Industry Alliance (1)
- Cyber Security Investment (9)
- Cyber Terrorism (40)
- Cyber Threat Actor Attribution Maltego Graphs (2)
- Cyber Warfare (68)
- Cyber Weapon (1)
- Cyber Weapons (1)
- CyberCamp 2016 (1)
- Cybercrime (334)
- Cybercrime Ecosystem (21)
- Cybercrime Forum (36)
- Cybercrime Forum Data Set (13)
- Cybercrime Incident Response (1)
- Cybercrime Incident Response Maltego Graphs (1)
- Cybercrime Search Engine (1)
- Cybercriminal (1)
- Cyberpunk (4)
- Cyberspace (22)
- Cybertronics (3)
- Daniel Brandt (1)
- Dark Vader (1)
- Dark Forum (1)
- Dark Web (10)
- Dark Web Onion (5)
- Dark Web Search Engine (2)
- DarkComet RAT (1)
- Darkode (1)
- Darkode Forum Community (1)
- Data Acquisition (1)
- Data Breach (10)
- Data Center (1)
- Data Leak (2)
- Data Mining (6)
- David Endler (2)
- DCLeaks (1)
- DDoS (10)
- DDoS For Hire (1)
- Defense Complex (1)
- Delicious Information Warfare (1)
- Denmark (1)
- Department of Defense (2)
- DHS (1)
- DIA (1)
- Digital Armaments (1)
- Digital Forensics (2)
- Digital Rights (8)
- Dilbert (1)
- Distributed Computing (4)
- Distributed Computing Project (4)
- Distributed Project (4)
- DNS (2)
- DNS Changer (1)
- DoD (3)
- DoJ (1)
- DotCom (1)
- DreamHost (1)
- Dropbox (1)
- Durzhavna Sigurnost (3)
- DVD of the Weekend (5)
- E-Banking (2)
- E-Business (3)
- E-Commerce (2)
- E-Shop (2)
- Eavesdropping (24)
- Ebay (1)
- ECHELON (2)
- ECOFIN Projects (1)
- Economics (3)
- eID (1)
- Electric Universe (1)
- Electromagnetic Pulse Weapons (3)
- Electronic Banking (1)
- ELINT (1)
- Emotet (2)
- Emotet Botnet (1)
- EMP (3)
- Encrochat (1)
- Encrochat Database Leak (1)
- Encrypted Communication (6)
- Encrypted Phone (1)
- Encryption (8)
- Enigma (2)
- ENISA (1)
- Enki Bilal (1)
- Enron (1)
- Erasmus Bridge (1)
- Eric Goldman (2)
- Espionage (6)
- Espionage Movie (2)
- Evgeniy Mikhaylovich Bogachev (1)
- Exmanoize (1)
- Exploit Broker (10)
- Exploit Kit (2)
- Exploits (39)
- Eyeball Series (1)
- F-Secure (1)
- Facebook (15)
- Fake Account (1)
- Fake Adobe Flash Player (4)
- Fake Certificate (1)
- Fake Chrome Extension (1)
- Fake Chrome Update (1)
- Fake Code Signing Certificate (1)
- Fake Confirmed Facebook Friend Request Email (1)
- Fake Documents (7)
- Fake Facebook Appeal (1)
- Fake Facebook Notification (1)
- Fake Facebook Profile Spy Application (1)
- Fake Firefox Update (1)
- Fake Hosting Provider (1)
- Fake ID (7)
- Fake Internet Explorer Update (1)
- Fake Passport (8)
- Fake Personal ID (1)
- Fake Safari Update (1)
- Fake Security Software (48)
- Fake Tech Support Scam (1)
- Fake Utility Bill (4)
- Fake Video Codec (2)
- Fake Visa (1)
- Fake Visa Application (1)
- Fake Web Site (1)
- Fake Who's Viewed Your Facebook Profile Extension (4)
- Fake YouTube Player (1)
- Fast-Flux (3)
- FBI (4)
- FBI Most Wanted (5)
- FCC (1)
- FDIC (1)
- Financial Management (1)
- Firas Nur Al Din Dardar (1)
- FireEye (1)
- Flashpoint Intel (1)
- Foreign Influence Operations (2)
- Forensics (2)
- Forwarderz (2)
- FoxNews (1)
- Fraud (17)
- Free Speech (17)
- FSB (2)
- FTLog (1)
- FTLog Worm (1)
- Gartner (1)
- Gavril Danilkin (1)
- GazTranzitStroyInfo (1)
- GCHQ (8)
- GDBOP (1)
- Generation I (1)
- George Bush (1)
- Georgi Markov (1)
- Georgia (4)
- Germany (1)
- Gift Cards (1)
- GiveMeDB (1)
- Global Security Challenge (1)
- Goa Trance (1)
- GoDaddy (1)
- Google (11)
- Google Firebase (1)
- Google Ads (1)
- Google Docs (6)
- Google Earth (4)
- Google Groups (1)
- Google Hacking (2)
- Google Maps (3)
- Google Play (1)
- Google Store (1)
- Greece (1)
- Growth Hacker (2)
- GRU (1)
- Guccifer 2.0 (1)
- GUI (1)
- Gumblar (1)
- Hacked Database (5)
- Hacked Web Site (5)
- Hacker (2)
- Hackers (2)
- Hacking (233)
- Hacking Book (1)
- Hacking Forum (1)
- Hacking Group (5)
- Hacking Groups (1)
- Hacking Tools (1)
- HackPhreak (1)
- HackPhreak Hacking Group (1)
- Hacktivism (5)
- Haiti (1)
- Hamas (1)
- Hezbollah (1)
- High Tech Brazil Hack Team (1)
- Hilary Kneber (4)
- HKLeaks (1)
- Home Molestation (8)
- Homebrew (1)
- Honeynet Project (1)
- Honker Union of China (1)
- HUMINT (2)
- ICBM (1)
- ID Theft (4)
- iDefense (3)
- Identity Theft (4)
- Illegal Arrest (13)
- Illegal Hosting (1)
- Illegal Restraint (3)
- IMINT (2)
- IMLogic (3)
- India (1)
- India Company (1)
- Indicator of Compromise (1)
- Information Operations (2)
- Information Security (598)
- Information Security Forum (1)
- Information Security Market (5)
- Information Warfare (67)
- Infrastructure Security (1)
- InFraud (1)
- InFraud Cybercrime Gang (1)
- InFraud Cybercrime Syndicate (1)
- InFraud Organization (1)
- InqTana Mac OS X Malware (1)
- Insider (8)
- Insider Monitoring (2)
- Insider Threat (9)
- Instant Messaging (6)
- Intellectual Property (1)
- Intelligence (19)
- Intelligence Agency (17)
- Intelligence Community (35)
- Internal Revenue Service (1)
- International Exploit Shop (2)
- Internet (15)
- Internet Censorship (23)
- Internet Economy (4)
- Internet Relay Chat (1)
- Investment Banking (6)
- IoC (1)
- IP Cloaking (2)
- IP Hiding (1)
- IP Spoofing (1)
- iPowerWeb (1)
- IPSec (1)
- IPv4 (1)
- IPv6 (2)
- Iran (19)
- Iran Election (1)
- Iran Election 2009 (1)
- Iran Hacker Groups (7)
- Iran Hacking Groups (7)
- Iran Mabna Hackers (1)
- IRC (1)
- IRS (1)
- ISIS (1)
- Israel (1)
- Jabber (5)
- JabberZeuS (2)
- Javor Kolev (1)
- Jeffrey Carr (1)
- Joanna Rutkowska (1)
- Johannes Ullrich (2)
- John Young (1)
- K Rudolph (1)
- Kaseya (1)
- Kaseya Ransomware Attack (1)
- Katrina (1)
- Keylogger (1)
- KGB (7)
- Kidnapping (14)
- Koobface (29)
- Koobface Botnet (3)
- Korean Demilitarized Zone (1)
- KrotReal (1)
- Latest News Articles (2)
- Latvia (1)
- Law Enforcement (29)
- Lawful Interception (5)
- Leaks (1)
- Lenovo (3)
- Liberty Front Press Network (1)
- Lizamoon (2)
- Loads.cc (1)
- Localization (1)
- Location Tracking (2)
- Lockheed Martin (1)
- Logicube (1)
- Lone Gunmen (3)
- Lovely Horse (2)
- Lubyanka Square Headquarters (1)
- M4 Project (1)
- Mac OS X (3)
- Malicious Software (190)
- Maltego (6)
- Maltego Graphs (1)
- Malvertising (4)
- Malware (49)
- Malware Information Sharing Platform (1)
- Marketing (2)
- Mass Web Site Defacement (10)
- Mastercard (1)
- McAfee (3)
- MD5 (1)
- Media Methane (1)
- Memoir (2)
- Metrics (1)
- Microsoft (3)
- Microsoft Live (1)
- Military Communications (2)
- Ministry of Interior (1)
- MISP (1)
- Missile Base (1)
- Mobile (5)
- Mobile Application (2)
- Mobile Communication Censorship (1)
- Mobile Internet (3)
- Mobile Location Tracking (5)
- Mobile Malware (10)
- Mobile Security (2)
- Mohammad Sagegh Ahmadzadegan (1)
- Money Laundering (24)
- Money Mule (26)
- Money Mule Recruitment (26)
- Monoculture (1)
- Morgan Stanley (1)
- Moses Staff (1)
- Most Wanted Cybercriminals (1)
- MSN (3)
- MSRC (1)
- MSRC Researcher Recognition Program (1)
- Muhammad Cartoons (1)
- MVR (1)
- MyWebFace (1)
- NASA (1)
- National Cyber Security Centre (1)
- National Security (2)
- Native Intelligence (1)
- NBC (2)
- NCSC (1)
- NetAssist LLC (1)
- NetCraft (1)
- Network Centric Warfare (1)
- Network Solutions (3)
- New Media (9)
- Nikolay Nedyalkov (1)
- Nikopol Trilogy (1)
- Nintendo (1)
- Nintendo DS (1)
- NordVPN (1)
- Norman Sandbox (1)
- North Korea (3)
- North Korea Missile Launch Pad (1)
- NSA (16)
- NSO Group (1)
- NSO Group Spyware (1)
- Nuclear Weapons (3)
- Nyxem (1)
- OEM (1)
- Offensive Cyber Warfare (1)
- OMEMO (1)
- Omerta (1)
- One-Time Password (1)
- One-Time Passwords In Everything (2)
- OneCare (1)
- Online Advertising (5)
- Online Fraud (12)
- Online Marketing (3)
- Online Propaganda Campaign (1)
- Online Scam (3)
- Open Source Malware (3)
- Operation EQUALIZER (1)
- Operation Uncle George (8)
- OPIE (1)
- OPSEC (1)
- Osama Bin Laden (1)
- OSINT (118)
- OSINT Training (1)
- OTC (1)
- OTP (1)
- Over-The-Counter (1)
- Packers (1)
- Parked Domains (1)
- Passwords (2)
- Pavlin Georgiev (1)
- Pay Per Install (3)
- PayPal (1)
- Perplex City (1)
- Persistent Cookies (1)
- Personal Career (1)
- Personal Data (4)
- Pharmaceutical Scams (1)
- Phileas Crawler (1)
- Phishing (12)
- Phishing Campaign (8)
- Phishing Domain Farm (1)
- Phishing Toolbar (2)
- PhishTube (1)
- Phreedom (1)
- Physical Security (1)
- Pinterest (1)
- Piracy (1)
- PlushForums (1)
- Podcast (2)
- Point of Sale Terrminal (1)
- Politics (1)
- PornTube (1)
- POS (1)
- Potentially Unwanted Application (2)
- PR (1)
- Press Coverage (1)
- Privacy (34)
- Project RAHAB (1)
- Prolexic (1)
- Protonmail (4)
- Proxy Service (1)
- Psychedelic Trance (2)
- PSYOPS (2)
- Psytrance (2)
- Psytrance Song of the Day (2)
- Qassam Cyber Fighters (2)
- Radicati Group (1)
- Ransomware (20)
- RAT (1)
- Ray Kurzweil (1)
- RBN (1)
- Reconnaissance Satellite (2)
- Red Joan (1)
- Regulation (1)
- Remote Access Tool (4)
- Reporters Without Borders (1)
- Return On Investment (9)
- Return On Security Investment (10)
- REvil Ransomware Group (1)
- Revolution in Militvry Affairs (1)
- RIPA (1)
- Risk Management (2)
- Rogue Account (1)
- Rogue Chrome Extension (1)
- Rogue Facebook Appeal (1)
- Rogue Security Software (2)
- Rogue Video Codec (1)
- Rogue YouTube Player (1)
- Rogueware (3)
- ROI (3)
- Roman Polesek (1)
- Root Server (2)
- Rootkit (1)
- ROSI (7)
- RSA (1)
- RSA Conference (1)
- Russia (12)
- Russia Small Group (1)
- Russian (1)
- Russian Bomber (1)
- Russian Business Network (4)
- Russian Submarine (1)
- Safe Harbor (1)
- Satellite Imagery (3)
- Satellite Jamming (1)
- Satellite SIGINT (1)
- Scam (4)
- Scams (9)
- Scandoo (1)
- ScanSafe (1)
- Scareware (50)
- Scientific Intelligence (1)
- Scribd (1)
- Search Engine (16)
- Search Engine Optimization (26)
- SEC (1)
- SecondEye Solutions (2)
- Secret Service (1)
- Secure Communication (1)
- SecureDrop (1)
- Securities and Exchange Commission (1)
- Security (645)
- Security Awareness (2)
- Security Book (1)
- Security Breach (4)
- Security Conference (2)
- Security Directory (1)
- Security Education (1)
- Security Event (2)
- Security Forum (1)
- Security Game (1)
- Security Industry (6)
- Security Interviews (3)
- Security Investment (5)
- Security Metrics (3)
- Security Podcast (2)
- Security Project (1)
- Security Research (1)
- Security Statistics (3)
- Security Training (1)
- Security Trends (8)
- Sensitive Information (2)
- SEO (2)
- Shadow Server (1)
- ShadowCrew (5)
- SIGINT (2)
- Silent Circle (1)
- Sipco Systems (1)
- SIPRNET (2)
- SITE Institute (1)
- SiteAdvisor (4)
- Skype (2)
- Sniffing (1)
- Social Engineering (4)
- Social Network Analysis (5)
- SocialMediaSystem (1)
- Software Piracy (1)
- Solarwinds (1)
- Song of the Day (2)
- Sophos (1)
- Soviet Union (1)
- Space Warfare (3)
- Space Weapons (1)
- Spam (10)
- Spam Campaign (7)
- Spam Operations (7)
- Spear Phishing (2)
- Spoofing (1)
- Sprott Asset Management (1)
- Spyware (3)
- SQL Injection (3)
- SSL (2)
- SSN (1)
- Stalkware (1)
- Starlight (1)
- Stealth Ideas Inc (1)
- Steganography (1)
- STIX (3)
- STIX2 (3)
- Stolen Credit Card (9)
- Stolen Credit Cards (5)
- Stolen Gift Cards (1)
- Strider Crawler (1)
- Sub7 (1)
- Suri Pluma (1)
- Surveillance (24)
- Swine Flu (1)
- Symantec (5)
- Symbian (1)
- Syria (2)
- Syrian Electronic Army (1)
- Syrian Embassy (1)
- Taia Global (1)
- TAN (1)
- TAXII (3)
- TDoS (1)
- Team Code Zero (1)
- Team Code Zero Hacking Group (1)
- Tech Support Scam (1)
- Technical Collection (73)
- Technical Mujahid (1)
- Telephony Denial of Service Attack (1)
- Terrorism (8)
- th3j35t3r (1)
- THAAD (1)
- The Bunker (1)
- The Immortals (1)
- The Lawnmower Man (2)
- The Outer Limits (4)
- Thought Leadership (1)
- Thousand Talents Program (1)
- Threat Intelligence (18)
- Threat Intelligence Feed (2)
- Threat Intelligence Report (1)
- TIA (4)
- Tipping Point (1)
- Top Secret Program (1)
- Tor (1)
- Tor Project (1)
- Torrent (1)
- TorrentReactor (1)
- Total Information Awareness (4)
- Travel Without Moving (9)
- TrendMicro (2)
- Trickbot (1)
- Trickbot Gang (1)
- Trickbot Malware (1)
- Trickbot Malware Gang (1)
- Trifinite Group (1)
- Trojan Horse (2)
- TROYAK-AS (2)
- Tutanota (2)
- Twitter (4)
- Two Factor Authentication (1)
- Two-Factor Authentication (3)
- Typosquatting (3)
- U.K National Cyber Security Centre (1)
- U.S Bureau of Engraving and Printing (2)
- U.S Cyber Command (1)
- U.S Driving License (1)
- U.S Elections (3)
- U.S Sanctions (1)
- U.S Secret Service (1)
- Underground Search Engine (1)
- United Kingdom (4)
- University ID Card (1)
- Vasil Moev Gachevski (1)
- Vault 7 (1)
- VeriSign (1)
- Vertex Net Loader (1)
- Virtual Private Network (2)
- Virtual Reality (5)
- Virtual Reality Social Network (4)
- Virtual World (4)
- Virus (1)
- Virus for You (1)
- Virus Map (1)
- Virus Recovery Button (1)
- Viruses (2)
- VirusTotal (1)
- Visa (1)
- Visual Information System (2)
- Visualization (3)
- Void Balaur Malware Gang (1)
- VoIP (2)
- VPN (3)
- Vulnerabilities (39)
- Vulnerability Broker (10)
- War Driving (1)
- War Games (1)
- Weapon Systems (1)
- Web 2.0 (3)
- Web Application Worm (1)
- Web Crawler (2)
- Web Inject (1)
- Web Proxy Service (1)
- Web Shells (1)
- Web Site Defacement (10)
- Web Site Defacement Groups (4)
- Webroot (2)
- WHGDG (1)
- WhoisXML API (10)
- WhoisXML API Jabber ZeuS Gang (1)
- Wireless (2)
- Wireless Hacking (1)
- Wireless Internet (2)
- Wiretapping (10)
- WMF Vulnerability (2)
- World Hacker Global Domination Group (1)
- X-Files (2)
- X-Tunnel (1)
- XMPP (4)
- XSS (1)
- Yahoo (2)
- Yaroslav Vasinskyi (1)
- Yavor Kolev (1)
- YouTube (1)
- ZDNet (1)
- ZDNet Zero Day Blog (1)
- Zero Day Exploit (6)
- Zero Day Initiative (2)
- Zerodium (1)
- ZeuS (4)
- Zombie Alert (2)
- Zone-H (2)
- Zotob (1)
