
Will
@bushidotoken
Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Previously @Equinix | @darknetdiaries #126: REvil
ID: 1252623560
http://BushidoToken.net 08-03-2013 20:06:48
12,12K Tweet
34,34K Followers
3,3K Following

Thanks for the report Arctic Wolf! Further connected infrastructure based on upstream traffic patterns: 2.56.127.158 - cypowertech[.]org 94.131.108.94 - techzcore[.]org (recent & potentially live campaign) All four IPs in the attached image were suspended THE.Hosting 🐉🤝🤖
![Team Cymru Threat Research (@teamcymru_s2) on Twitter photo Thanks for the report <a href="/AWNetworks/">Arctic Wolf</a>!
Further connected infrastructure based on upstream traffic patterns:
2.56.127.158 - cypowertech[.]org
94.131.108.94 - techzcore[.]org (recent & potentially live campaign)
All four IPs in the attached image were suspended <a href="/the_hosting_/">THE.Hosting</a> 🐉🤝🤖 Thanks for the report <a href="/AWNetworks/">Arctic Wolf</a>!
Further connected infrastructure based on upstream traffic patterns:
2.56.127.158 - cypowertech[.]org
94.131.108.94 - techzcore[.]org (recent & potentially live campaign)
All four IPs in the attached image were suspended <a href="/the_hosting_/">THE.Hosting</a> 🐉🤝🤖](https://pbs.twimg.com/media/GwoO9tEWAAIwRG7.jpg)


Resharing this useful catalog of various EDR products "shell" and response functionalities by Chris Beckett related to the Thread discussion below 👇 github.com/cbecks2/edr-ar…

EDR-on-EDR Violence 1/🧵 Will called out that EDR products were being abused by threat actors. Ezra Woods & I realized a free trial of an attacker controlled EDR can be used to kill the existing EDR. spencer mRr3b00t JS0N Haddix github.com/CroodSolutions…


Meet us at BSides Bournemouth on August 16 where our own Jake S will deliver an interactive workshop called 'Captain Hook’s urlscan Bootcamp'. Learn how to hunt phishing on urlscan.io: urlscan.io/blog/2025/07/2…





Was enlightened today that TEAM CYMRU has a nice whois server that anyone can use. Use the following Bash and replace xyz with any ASN you want and you can dump what CIDR ranges it has: whois -h whois.cymru.com " -v dump ASxyz"
