Post #1534994
2025-06-13 15:21 UTC
Saw @censys awesome blog about Columbian C2 servers (https://censys.com/blog/unmasking-the-infrastructure-of-a-spearphishing-campaign) and thought I'd do a quick OSINT walkthrough.
Thread below !
(0/???)
#OSINT #OPSECFAIL #CTI #ThreatIntel
Replies (1)
-
@grey@infosec.exchange 2025-06-13 15:23
One of the best indicators Censys found for attribution is the email address accidentally left in a git commit: % git log commit fa480e80bc5b9e154fad138ef47191032e7ba4dd (HEAD -> main, origin/main, origin/HEAD) Author: Shadow GRT Date: Wed May 7 15:51:15 2025 +0000 Given this is a gmail the first tool we should immediately use is GHunt (https://github.com/mxrch/GHunt) (1/???) #OSINT #OPSECFAIL #CTI #ThreatIntel