Remove itl
article thumbnail

NIST Cybersecurity and Privacy International Engagement Updates

NSTIC

In the NIST Information Technology Laboratory (ITL), we have continued our international engagement in new and creative ways, leading to more robust and meaningful discussions with our stakeholders. A lot has changed for all of us over the last year as the result of the pandemic.

article thumbnail

Conti Leak Indicators – What to block, in your SOC….

Security Affairs

ITL Bulgaria [link]. If you want to extend your blocking further, look at the BGP AS associated to these subnets; and subsequently, check the prefixes listed for associated subnets. Data Room [link]. PlusServer [link]. BelCloud [link]. Looking at their infrastructures, other story?

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Researchers were able to access the payment portal of the Conti gang

Security Affairs

The latter is an IP address owned by Ukrainian web hosting company ITL LLC. The researchers were able to unmask the real IP address of Conti’s TOR hidden service and contirecovery.ws and 217.12.204.135.

article thumbnail

TA505 is expanding its operations

Security Affairs

The client establishes a new connection with the remote command and control server hosted on a Bulgarian remote host 217.12.201.159, part of a Virtual Dedicated Server subnet of the AS-21100, operated by ITL LLC. C2’s parameters. The attack is composed by a complex flow we synthesize in the following scheme: Figure 12. The TA505 Connection.

Retail 71