On 7/7/23 at 1:39am, the CloudExis Security Operations Center was notified of numerous emails coming ...
show moreOn 7/7/23 at 1:39am, the CloudExis Security Operations Center was notified of numerous emails coming from a "John Blue". At this time, 57 emails were recorded, all using domains that followed a similar format, 4 numbers followed by .com. Example: 5739.com
Scam was a blackmail scam that demanded $750 to not release footage the malicious actor claimed they had recorded via webcam.
show less
On 7/7/23 at 1:39am, the CloudExis Security Operations Center was notified of numerous emails coming ...
show moreOn 7/7/23 at 1:39am, the CloudExis Security Operations Center was notified of numerous emails coming from a "John Blue". At this time, 57 emails were recorded, all using domains that followed a similar format, 4 numbers followed by .com. Example: 5845.com
Scam was a blackmail scam that demanded $750 to not release footage the malicious actor claimed they had recorded via webcam.
show less
CloudExis LLC received an abuse report on May 10th, 2023 regarding this attack, as the company has y ...
show moreCloudExis LLC received an abuse report on May 10th, 2023 regarding this attack, as the company has yet to remove the rDNS that points to our company. See below, submitted by [email protected]
-----------------------------------------------------------------------------------------
| IP-NUMBER: 45.150.53.97/32 |
| HOSTNAME : n/a |
-----------------------------------------------------------------------------------------
| TIMESTAMP | ATTACKS | Port | TARGET-HOST |
-----------------------------------------------------------------------------------------
| 2023-05-10T08:57:35+02:00 | portflood: syn | | host173.checkdomain.de |
| 2023-05-10T08:57:18+02:00 | portflood: syn | | host133.kunde24.de |
| 2023-05-10T08:56:26+02:00 | portflood: syn | | host161.checkdomain.de |
show less
Sent spoofed email that was redirected to a secondary mailbox. Author attempted to get recipient to ...
show moreSent spoofed email that was redirected to a secondary mailbox. Author attempted to get recipient to pay $200USD to a bitcoin address. Title of email: "Security vulnerabilities!"
show less
Triggered Fail2Ban over acceptable limits -
2022-05-22 06:46:03,110 fail2ban.filter [30902]: INF ...
show moreTriggered Fail2Ban over acceptable limits -
2022-05-22 06:46:03,110 fail2ban.filter [30902]: INFO [ssh] Found 51.222.143.59 - 2022-05-22 06:56:19
2022-05-22 06:46:03,112 fail2ban.filter [30902]: INFO [ssh] Found 51.222.143.59 - 2022-05-22 06:56:19
2022-05-22 06:46:07,401 fail2ban.filter [30902]: INFO [ssh] Found 51.222.143.59 - 2022-05-22 06:56:06
show less
Triggered Fail2Ban over acceptable limits - 2022-05-22 06:46:03,110 fail2ban.filter [30902]: INF ...
show moreTriggered Fail2Ban over acceptable limits - 2022-05-22 06:46:03,110 fail2ban.filter [30902]: INFO [ssh] Found 43.154.132.95 - 2022-05-22 06:46:03
show less