
Dancho Danchev's Blog
1000 FOLLOWERS
Mind Streams of Information Security Knowledge. Blog by Dancho Danchev, DNS Threat Researcher at WhoisXML API and expert in the field of cybercrime fighting & threat intelligence.
Dancho Danchev's Blog
3d ago
I've decided to share with everyone some actionable intelligence on one of the Russian Business Network's primary franchise networks in Turkey namely AbdAllah Internet Hizmetleri which back in the day used to be responsible for some pretty decent bulletproof hosting malicious and fraudulent cybercrime activity in particular to offer actionable intelligence on Mykhaylo Sergiyovich Rytikov it's owner who's currently on U.S Secret Service's most wanted cybercriminals list.
Known domains affiliated with AbdAllah Internet Hizmetleri:
hxxp://tiket[.]cc
hxxp://abdulla[.]cc
hxxp ..read more
Dancho Danchev's Blog
3d ago
I've just came across to a currently circulating Cobalt Strike serving malicious software campaign and I've decided to share the details with everyone reading this blog.
Original malware hosting location: hxxp://bsctech[.]ac[.]th/css/43[.]exe
MD5: d8d8cb60d196a26765261b1ca8604d1e
Sample C&C server IPs known to have been involved in the campaign include:
hxxp://5[.]253[.]234[.]40 -> hxxp://5[.]253[.]234[.]40/activity -> hxxp://5[.]253[.]234[.]40/activity/submit[.]php
Sample geolocation of the known C&C server IP:
Sample C&C server domains known to have been involved i ..read more
Dancho Danchev's Blog
3d ago
As I've been digging deep inside an old threat intelligence and technical collection archive and I've decided to share several screenshots worth everyone's while.
The following is basically several sample screenshots courtesy of the Zunker botnet C&C command and control interface which back in the day used to dominate the threat landscape including the sophisticated cybercrime ecosystem with some pretty interesting and sophisticated features.
Sample screenshots include ..read more
Dancho Danchev's Blog
1w ago
Can you slap it? Do you know that your degree of education is proportional with the price size of your t-shirt which means that we're not interested in counting that much I mean the almighty dollar which you can't behold yourself to all of its mightiness? "Give me a moron and I'll beat him" instead of "Give me an IP and I'll move the earth" type of mentality? Are you a retard or are you a moron or are you a dipshit where the word cannot really behold itself to its almighty awesomeness? Try the two of these as you're only a low waged moron that cannot really count anything between one or ..read more
Dancho Danchev's Blog
1M ago
Dear blog readers,
Interested in finding out the latest and very greatest malicious software download locations for research purposes? Check out the following compilation courtesy of my compiled exclusively using public sources.
Grab the compilation from here.
Stay tuned ..read more
Exposing a Portfolio of Fake News Disinformation and Misinformation Web Site Domains - A Compilation
Dancho Danchev's Blog
1M ago
Dear blog readers,
I've decided to share with everyone a currently active domain portfolio of fake news disinformation and misinformation web sites which I obtained using technical collection with the idea to assist everyone in their cyber attack campaign attribution efforts.
Download the compilation here.
Stay tuned ..read more
Dancho Danchev's Blog
1M ago
Dear blog readers,
Hot off the press. Grab the Torrent.
Sample photo:
Stay tuned ..read more
Dancho Danchev's Blog
1M ago
In a world dominated by a countless number of malicious and fraudulent cyber threat actor adversaries including the rise of the "penetration testing" crowd whose ultimately goal is to actually lower down the entry barriers into the World of Information Security potentially resulting in thousands of ethical and unethical penetration testing aware users across the globe who have the capacity and the potential to target thousands of legitimate Web sites in an attempt to take advantage of the "low-hanging fruit" it should be clearly noted that throughout the past couple of years a new generation ..read more
Dancho Danchev's Blog
1M ago
Dear blog readers,
This is Dancho and I'm further expanding the last post of the "Dancho Danchev's Disappearance and Kidnapping and Home Molestation Attempt Circa 2010" blog post series with a variety of personal photos and personally identifiable information.
I wanted to say big thanks to everyone who knew me back then and basically participated in this. Big "thanks".
Sample photos include:
Personally identifiable information:
Pavlin Georgiev Hristov:
https://www.facebook.com/profile.php?id=100005932519460
Vasil Moev Gachevski:
https://www.facebook.com ..read more