GhostWareOS

I haven’t seen it discussed anywhere yet and the way it’s setup looks pretty interesting to me. What do you guys think about it?

First time I’ve seen it. For now, we have to take it with a grain of salt.

I can’t access the page. For some reason, the domain frameusercontent.com is blocked (I think because it belongs to Adobe).

PS: The domain was created a few weeks ago and the page is hosted on a server in Ukraine. The domain points to two IP addresses that are dedicated to performing port scans (31.43.160.6, 31.43.161.6). It has two shared IP addresses assigned in the US (passive DNS) that are used to distribute malware (3.33.130.190, 15.197.148.33).

The domain also replicates on the IP (52.223.52.2) actively used for command and control.

I’m sorry, I don’t like it at all.

2 Likes

The website does not give me confidence in this being a legitimate service or business or whatever this is.

I don’t think people should take it seriously until we know a lot more about it.

4 Likes

Exactly. Till such time, better stay far away. Hence keep an eye on it; it may evolve into full-blown service; or may turn out to be scam…….

For time being, there is too many coming soon placeholders.

Suricata does not like the website:

2 Likes

Thanks for the feedback everyone

1 Like