INDICATOR TYPE PULSE twitter.comdomainsummary for me twitter.comdomainfaceache spyware and covid 19 twitter.comdomain1 google search url ~ 24 extracted indicators ~ http://confused.com!! twitter.comdomain184.168.131.241 107.180.29.200 https://twitter.com/alexsmithfsb twitter.comdomainunknown search history in broken browser safari with google search named as mozilla netscape unmodified iphone8 twitter.comdomainFrankly iOS users globally…… FUCKED twitter.comdomainhttps://mobile.twitter.com/dorkingbeauty1/status/1304091492571656192 https://twitter.comdomainmobile.twitter.com cookie manipulation examples twitter.comdomaintr069 acs management server (ACS) domains historically & current exploiting tr064/tr069 twitter.comdomaincompromised iPhone hijacked by pegasus os – log files uploaded for 1-3 oct 2020 twitter.comdomain2020 meets 2099 pie 1 twitter.comdomainhttps://uk.host-tools.com/sitemap_online_1.xml …http://twitter.comdomainkey.financial-ombudsman.org.uk using a hooky copy of 2011 version symantec portal software from orange county gov in us- seems a bit fishy really twitter.comdomainHTTP headers aiding exploitation twitter.comdomainbingo – https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct… …http://twitter.comdomainkey.bankofsingapore.com/b/l.e – src: http://urlscan.io of http://keys.financial-ombudsman.org.uk twitter.comdomainA Fake or Corrupted or mimic version of http://hybrid-analysis.com i#crowdstrike #apt #imposter …http://twitter.comdomainwww.hybrid-analysis.com -otx http scans- something’s not right! twitter.comdomainPowersports University – 3.213.11.185 – x-poweredby:http://UrlWriter.NET 2.0.0 – support.g.c/websearch/answer1696588 twitter.comdomainunknown login notification within twitter acc upon clicking to change password, get lost connection and iphone pop up stating mobile data is off twitter.comdomainhttps://mobile.twitter.com/lukehgomes/status/1328507962185269248 twitter.comdomainhttps://mobile.twitter.com/yasalqaisi/status/1328382238195666952?s=19 twitter.comdomainhttps://mobile.twitter.com/codepo8/status/1328261903987171329 – EXPIRES: Tue, 31 Mar 1981 05:00:00 GMT – X-XSS-PROTECTION: 0 twitter.comdomainextraction from https://abs.twimg.com/responsive-web/client-web-legacy/vendors~main.68b1d365.js… twitter.comdomainedgeprism.4.7.3.1.server compromised bundle if joy twitter.comdomainhttps://twitter.com/messages/946895603983880192-946895603983880192/media/1214658446336937993 -twiter errors https://twitter.comdomainmobile.twitter.com is absolutely fucked twitter.comdomainthanks twitter …http://twitter.comdomaincid-99c9581a4ed90118.users.storage.live.com twitter.comdomainhttps://www.instagram.com/aldeem088 twitter.comdomain140.82.118.4 twitter.comdomain’Dirty methods’ in Brexit vote cited in push for new laws on Europe’s elections | European Union | The Guardian twitter.comdomaintwitter oddities twitter.comdomaintwitter analytics – last 7 days – by tweet and by day – 2 csv files uploaded to otx twitter.comdomainuk consumer twitter accounts being silently hijacked without trace twitter.comdomainbasically the internet is on fire across the globe twitter.comdomainSuggested Description: The full text of the final version of an anti-virus tool, created by http://Cloudflare.com, has been published. and is now available to view on the internet.  twitter.comdomainThe following is the full text of the text below: £3.3m, £2.5m..com, €1.8m; http://twitter.comdomainstspg.io – some rather unexpected output redirected from https://status.otx.alienvault.com/incidents/yzgmgln5btz3?u=g5mrd8ls0tm7… twitter.comdomainhttps://demo.webtitancloud.com:8443/history-x.php twitter.comdomaingoo drive files -ad fraud and a lot of int strings and data generated from hybrid-a scan twitter.comdomainbotnet by car -fm/am radio marine shipping gps/2-3g unified infrastructure -sdr and sds twitter.comdomainhttps://www.whatdotheyknow.com/request/253848/response/625592/attach/3/AppendixA.pdf?cookie_passthrough=1 twitter.comdomainhttps://khoros.com/powered-by-khoros – CVE-2017-014 – This is a supply chain attack starting point for many big corps twitter.comdomainunusual activity on http://nih.gov 12-24 Dec 2020 brief move from static ip to private ip 3days connx err’s either side twitter.comdomain1 mobile.twitter url = Ad/click fraud #APT #infrastructure #Espionage #global #telco #supplychain http://twitter.comdomainBt.bt.com #telcos around the world implanted 6 years ago http://twitter.comdomainboredpanda.com twitter.comdomainAtt App Attack on British Consumer routing traffic through US twitter.comdomainhttps://mobile.twitter.com/i/connect_people?user_id= twitter.comdomainappapple twitter.comdomainappapple- http://otx.alienvault.com/pulse/5fffac7f8ece4a71c2b9190… twitter.comdomainAcknowledgement …http://twitter.comdomainnamsafe10.safelinks.protection.outlook.com – should be renamed “unsafe” http://twitter.comdomainotx.alienvault.com – http://urlscan.io twitter.comdomainim a spy and a runner for $50billion twitter.comdomaincolbalt strike kryptik on bitbucket twitter.comdomainrepeat repeat repaet twitter.comdomainJA3 Client Dst iP – Malware twitter.comdomainhttps://twitter.com/home http://twitter.comdomaindfrobot.com – http://urlscan.io more on HCR_Mobile_Platform_with_Omni_Wheels_SKU__ROB0124-DFRobot twitter.comdomainhttps://mobile.twitter.com/ian_leonard twitter.comdomainhttps://twitter.com/?logout=1613849316353 twitter.comdomainhttps://twitter.com/login?redirect_after_login=https%3A%2F%2Fanalytics.twitter.com%2Fuser%2Fdorkingbeauty1%2Ftweets twitter.comdomainAPT sets up private netw and web servers using google and facebook ads to disguise a multitude of vadness twitter.comdomainiptv and sip fraud globally using ispmobile netw supply chain twitter.comdomainiptv and sip fraud globally using ispmobile netw supply chain twitter.comdomain109.157.227.142 – This is all APT setup – Everything looks like plain ordinary consumer set up ie normal… but its really bad pivoting of ms exchange twitter.comdomainMy Activity History Google Search History download…. Apparently my history twitter.comdomainMy Activity History – Category Image search twitter.comdomainrandom open tabs twitter.comdomain104.244.42.65 – unknown device login on UK twitter acc http://api.w.org-lencr.org-2m.con-roksit.com twitter.comdomainhttp://www.hp.com/go/reach – direct footer link from https://www8.hp.com/uk/en/company_registration_details.html… twitter.comdomainPDF file has an embedded URL – http://ww25.mbrs6sky.cn/?subid1=20210312-1237-4209-8d38-ea46ea2fccc2… twitter.comdomainA VirusTotal scan result: £1.5m..com (3.2m euros) – – is the result of a virus attack on the Windows operating system. http://twitter.comdomaintwitter.com http://twitter.comdomainvmap.grabyo.com and apl known indicators twitter.comdomain9 months ago i created this pulse with log files from my iphone 8 (patched) which i uploaded to otx twitter.comdomaindomain http://vidlox.tv URL http://vidlox.tv/rr01xh3jg7lr twitter.comdomainhttps://www.bbc.co.uk/news/magazine-35506591?ns_mchannel twitter.comdomainhttp scan reqs for http://jkg.dbd.myftpupload.com 13.107.21.200IPv4aug 2018 twitter facebook & http://actionfraud.police.uk https://13.107.21.200IPv4mobile.twitter.com is absolutely fucked r3.o.lencr.orghostname104.244.42.65 – unknown device login on UK twitter acc http://api.w.org-lencr.org-2m.con-roksit.com microsoft.comdomainaug 2018 twitter facebook & http://actionfraud.police.uk s3.amazonaws.comhostnamelist of server:-app-US1.com, the company that owns Apple, Google, Facebook, Twitter, Instagram and other major web sites. 72.21.91.29IPv4aug 2018 twitter facebook & http://actionfraud.police.uk