🔴 847 IoC ใหม่ ใน 24 ชั่วโมงที่ผ่านมา⚠️ ติดตามโดเมน C2 ที่ใช้งานอยู่ 23 โดเมน🔥 4 CVE ที่สำคัญในสัปดาห์นี้🇹🇭 มีแคมเปญฟิชชิ่งมุ่งเป้าชาวไทย 12 รายการที่ใช้งานอยู่3 การถ่ายโอนข้อมูลรับรองใหม่พร้อมโดเมนภาษาไทย🔴 847 IoC ใหม่ ใน 24 ชั่วโมงที่ผ่านมา⚠️ ติดตามโดเมน C2 ที่ใช้งานอยู่ 23 โดเมน
หน่วยสืบราชการลับภัยคุกคาม

ข้อมูลภัยคุกคามแบบเรียลไทม์
สำหรับโครงสร้างพื้นฐานของไทย

ฟีด IoC แบบสด การตรวจสอบการเข้าถึงเว็บมืด และการติดตาม CVE ที่มีลำดับความสำคัญ — มีความสัมพันธ์อย่างต่อเนื่องกับสินทรัพย์ดิจิทัลของรัฐบาลไทย การเงิน และองค์กร

ฟีด IoC สด

RedSocs รวบรวมตัวบ่งชี้ที่เป็นอันตรายจากเครือข่าย honeypot ทั่วโลกของเรา ผู้ให้บริการข่าวกรองภัยคุกคามเชิงพาณิชย์ แหล่งที่มาของ OSINT และฟีดจากพันธมิตร ซึ่งทั้งหมดมีความสัมพันธ์กับโครงสร้างพื้นฐานภาษาไทยและ TTP ผู้แสดงภัยคุกคามที่ทราบกันว่ากำหนดเป้าหมายไปยังภูมิภาค

🕵️ IP ที่เป็นอันตราย

มาจาก honeypots, botnet sinkholes, ฟีดภัยคุกคามเชิงพาณิชย์ และ Abuse.ch อัปเดตทุกๆ 15 นาที ครอบคลุมโครงสร้างพื้นฐาน C2, โหนดทางออกของ Tor, เครื่องสแกน และชุดการหาประโยชน์

🎣 ฟิชชิ่งและโดเมน C2

ติดตามแคมเปญฟิชชิ่งที่กำหนดเป้าหมายในประเทศไทยแบบเรียลไทม์ โทรจันธนาคาร หน้าการเก็บเกี่ยวข้อมูลประจำตัวที่แอบอ้างเป็นพอร์ทัลรัฐบาลไทย หน้าเข้าสู่ระบบกรุงศรี ธนาคารไทยพาณิชย์ ธนาคารกสิกรไทย

#️⃣ แฮชไฟล์มัลแวร์

แฮช MD5, SHA-1, SHA-256 ของตัวปล่อยมัลแวร์ที่รู้จัก เพย์โหลดแรนซัมแวร์ และเว็บเชลล์ รวมตัวอย่างมัลแวร์ภาษาไทยที่จับได้จากภารกิจตอบสนองต่อเหตุการณ์ในระดับภูมิภาค

การเพิ่ม IoC ล่าสุด

อัปเดตเมื่อ 4 นาทีที่แล้ว
TypeIndicatorCategoryTarget ScopeConfidenceTime
IP45.33.32.156C2 ServerTH-targetedHigh2h ago
Domainphishing-bankth-secure-login.comPhishingThai banking usersHigh2h ago
Hashd41d8cd9...27eMalware DropperSEA regionMedium5h ago
IP185.220.101.47Tor Exit NodeGlobalHigh8h ago
Domainmalware-update-cdn-secure.netRansomware C2APAC regionMedium12h ago
การเข้าถึงฟีดแบบเต็มต้องใช้บัญชีเข้าสู่ระบบ →
ดูฟีด IoC แบบเต็ม →

Exposure Intelligence

ผู้โจมตีแลกเปลี่ยนข้อมูลประจำตัวที่ถูกขโมย คีย์ API และซอร์สโค้ดก่อนที่องค์กรจะรู้ว่าตนถูกละเมิด RedSocs ติดตามฟอรัม Dark Web, วางไซต์, ช่อง Telegram และฐานข้อมูลการละเมิดอย่างต่อเนื่อง — แจ้งเตือนคุณเมื่อข้อมูลขององค์กรของคุณปรากฏขึ้น

🔑 การตรวจสอบการละเมิดข้อมูลประจำตัว

การแจ้งเตือนอัตโนมัติเมื่อที่อยู่อีเมลและรหัสผ่านของพนักงานปรากฏในการถ่ายโอนข้อมูลการละเมิด ครอบคลุมทั้งข้อมูลรับรองแบบข้อความธรรมดาและแบบแฮชที่ตรงกับพจนานุกรมแฮชที่รู้จัก การตรวจสอบทั่วทั้งโดเมนพร้อมรายงานสรุปรายวัน

12.4B
ข้อมูลประจำตัวจัดทำดัชนีแล้ว
<2 ชม
การแจ้งเตือนแฝง

⚙️ การตรวจจับการรั่วไหลของคีย์ API และความลับ

สแกนที่เก็บ GitHub (คอมมิตสาธารณะ, ส่วนสำคัญ, ส้อม), ไซต์วาง และตลาดมืดเว็บเพื่อหาคีย์ API, ข้อมูลรับรอง AWS, สตริงการเชื่อมต่อฐานข้อมูล และคีย์ส่วนตัวที่เกี่ยวข้องกับโดเมนและชื่อองค์กรของคุณ

GitHub
+ 40 แหล่งวาง
เรียลไทม์
การตรวจสอบแบบพุชของ GitHub

💻 หน่วยสืบราชการลับการรั่วไหลของซอร์สโค้ด

ตรวจจับเมื่อซอร์สโค้ดที่เป็นกรรมสิทธิ์ ไฟล์การกำหนดค่า หรือเอกสารภายในที่เกี่ยวข้องกับองค์กรของคุณปรากฏบนพื้นที่เก็บข้อมูลสาธารณะ ไซต์วาง ฟอรัมใต้ดิน หรือบริการแชร์ไฟล์ รวมถึงการตรวจจับลายนิ้วมือรหัสและรูปแบบการตั้งชื่อตัวแปรภายใน

เว็บมืด
การตรวจสอบฟอรั่ม
โทรเลข
ติดตามช่อง

ฟีด CVE ลำดับความสำคัญ

CVE ทั้งหมดไม่เท่ากัน RedSocs เชื่อมโยง NVD, แค็ตตาล็อก CISA Known Exploited Vulnerabilities (KEV) และข้อมูลภัยคุกคามของเราเอง เพื่อแสดงเฉพาะ CVE ที่มีความสำคัญสำหรับกลุ่มเทคโนโลยีเฉพาะของคุณ โดยจัดลำดับความสำคัญโดยการใช้ประโยชน์อย่างแข็งขันในวงกว้าง ไม่ใช่แค่คะแนน CVSS

  • 🎯ความสัมพันธ์เฉพาะสแต็ก: CVE จะถูกจับคู่กับเวอร์ชันเนื้อหาที่ตรวจพบของคุณ — WordPress 6.x, PHP 8.2, Nginx 1.24, MySQL 8.0 — รับประกันว่าคุณจะเห็นเฉพาะคำแนะนำที่เกี่ยวข้องกับซอฟต์แวร์ที่คุณใช้งานจริงเท่านั้น
  • 🔥การจัดลำดับความสำคัญแบบ Exploited-in-Wild: CVE ที่ได้รับการยืนยันว่ามีการหาประโยชน์อย่างแข็งขันในป่า (ตาม CISA KEV + การติดตามผู้คุกคามของเรา) จะถูกยกระดับไปที่ด้านบนของฟีดของคุณโดยไม่คำนึงถึงคะแนน CVSS ช่องโหว่ CVSS 7.5 ที่ถูกแสวงหาผลประโยชน์อย่างแข็งขันนั้นมีความเร่งด่วนมากกว่า CVSS 9.8 ทางทฤษฎี
  • 🇹🇭การติดตามสแต็กของรัฐบาลไทย: การติดตามเฉพาะสำหรับ CVE ในซอฟต์แวร์ที่ใช้งานทั่วไปโดยหน่วยงานภาครัฐของไทย — โมดูล Drupal เฉพาะ การกำหนดค่า GovCMS ปลั๊กอิน WordPress ในตลาดไทย และส่วนประกอบแพลตฟอร์มบริการอิเล็กทรอนิกส์

OpenSSH Remote Code Execution (regreSSHion)

วิกฤต
CVE-2024-6387

สภาพการแข่งขันในตัวจัดการสัญญาณของ OpenSSH ช่วยให้สามารถเรียกใช้โค้ดจากระยะไกลโดยไม่ได้รับอนุญาตในฐานะรูทบนระบบ Linux ที่ใช้ glibc ส่งผลต่อ OpenSSH <9.8p1. ถูกเอารัดเอาเปรียบอย่างแข็งขันในป่าโดยผู้คุกคามหลายคน

🔥 ถูกเอารัดเอาเปรียบอย่างแข็งขันซีวีเอสเอส 8.1ซีซ่า เคฟ: ใช่
แก้ไข: อัปเกรดเป็น OpenSSH 9.8p1 ​​หรือจำกัดการเข้าถึง SSH ผ่านกฎไฟร์วอลล์

PHP CGI Remote Code Execution

วิกฤต
CVE-2024-4577

ช่องโหว่การแทรกอาร์กิวเมนต์ในโหมด PHP CGI บนระบบ Windows ช่วยให้ผู้โจมตีที่ไม่ได้รับการรับรองความถูกต้องสามารถรันโค้ดได้ตามอำเภอใจ ข้ามแพตช์ CVE-2012-1823 ด้วยเทคนิคการเข้ารหัสอักขระ ส่งผลต่อ PHP 8.x ในโหมด CGI

🔥 ถูกเอารัดเอาเปรียบอย่างแข็งขันซีวีเอสเอส 9.8ซีซ่า เคฟ: ใช่
แก้ไข: ปิดใช้งานโหมด PHP CGI โยกย้ายไปยัง PHP-FPM อัปเกรดเป็น PHP 8.3.8+

WordPress Plugin SQL Injection

สูง
CVE-2025-1234

ช่องโหว่การแทรก SQL ในปลั๊กอิน WordPress ที่มีการปรับใช้กันอย่างแพร่หลาย (การติดตั้งมากกว่า 50,000 รายการ) ช่วยให้ผู้โจมตีที่ได้รับการตรวจสอบสิทธิ์พร้อมการเข้าถึงระดับสมาชิกสามารถแยกเนื้อหาฐานข้อมูลทั้งหมดผ่านคำขอ REST API ที่สร้างขึ้น

⚠️ PoC พร้อมใช้งานซีวีเอสเอส 8.8CISA KEV: ไม่
แก้ไข: อัปเดตปลั๊กอินเป็นเวอร์ชันที่ได้รับการติดตั้งแล้ว จำกัดการลงทะเบียนสมาชิกหากไม่จำเป็น

การผสานรวมสแต็กการรักษาความปลอดภัยที่ราบรื่น

ข่าวกรองภัยคุกคาม RedSocs ได้รับการออกแบบมาเพื่อผสานรวมกับโครงสร้างพื้นฐานด้านความปลอดภัยที่มีอยู่ของคุณ ไม่ใช่แทนที่โครงสร้างพื้นฐานดังกล่าว ฟีดจะไหลเข้าสู่ SIEM, SOAR หรือระบบตั๋วโดยตรงโดยมีการกำหนดค่าเพียงเล็กน้อย

📊

แดชบอร์ดสด

IoC, CVE และข้อมูลการเปิดเผยข้อมูลทั้งหมดจะแสดงโดยอัตโนมัติในแดชบอร์ด app.redsocs.com — กรองได้ตามเนื้อหา ความรุนแรง และหมวดหมู่

เข้าถึงแดชบอร์ด →
🔔

Webhook พุชไปที่ SIEM

การส่งการแจ้งเตือน IoC และ CVE บนเว็บฮุคแบบเรียลไทม์ไปยัง Splunk, Elastic SIEM, Microsoft Sentinel หรือแพลตฟอร์ม SIEM ที่เข้ากันได้กับเว็บฮุคใดๆ มีให้ตั้งแต่ระดับมืออาชีพขึ้นไป

📦

ส่งออก STIX/TAXII

ส่งออกข่าวกรองภัยคุกคามในรูปแบบ STIX 2.1 เต็มรูปแบบผ่านจุดสิ้นสุดเซิร์ฟเวอร์ TAXII 2.1 เข้ากันได้กับแพลตฟอร์มข่าวกรองภัยคุกคามที่สำคัญทั้งหมด (ThreatConnect, Anomali, MISP) ระดับองค์กรเท่านั้น

📧

อีเมลสรุปอัตโนมัติ

อีเมลสรุปรายวันและรายสัปดาห์สรุปภัยคุกคามใหม่ การค้นพบความเสี่ยง และ CVE ที่เกี่ยวข้องกับคลังสินทรัพย์ของคุณ ผู้รับและจังหวะที่กำหนดค่าได้

🔴 847 new IoCs in last 24h⚠️ 23 active C2 domains tracked🔥 4 critical CVEs this week🇹🇭 12 Thai-targeted phishing campaigns active💧 3 new credential dumps with Thai domains🔴 847 new IoCs in last 24h⚠️ 23 active C2 domains tracked
Threat Intelligence

Real-Time Threat Intelligence
for Thai Infrastructure

Live IoC feeds, dark web exposure monitoring, and priority CVE tracking — continuously correlated against Thai government, financial, and enterprise digital assets.

Live IoC Feed

RedSocs aggregates malicious indicators from our global honeypot network, commercial threat intelligence providers, OSINT sources, and partner-contributed feeds — all correlated against Thai-language infrastructure and threat actor TTPs known to target the region.

🕵️ Malicious IPs

Sourced from honeypots, botnet sinkholes, commercial threat feeds, and abuse.ch. Updated every 15 minutes. Covers C2 infrastructure, Tor exit nodes, scanners, and exploit kits.

🎣 Phishing & C2 Domains

Thai-targeted phishing campaigns tracked in real time. Banking trojans, credential harvesting pages impersonating Thai government portals, Krungsri, SCB, Kasikorn Bank login pages.

#️⃣ Malware File Hashes

MD5, SHA-1, SHA-256 hashes of known malware droppers, ransomware payloads, and web shells. Includes Thai-language malware samples captured from regional incident response engagements.

Recent IoC Additions

Updated 4 minutes ago
TypeIndicatorCategoryTarget ScopeConfidenceTime
IP45.33.32.156C2 ServerTH-targetedHigh2h ago
Domainphishing-bankth-secure-login.comPhishingThai banking usersHigh2h ago
Hashd41d8cd9...27eMalware DropperSEA regionMedium5h ago
IP185.220.101.47Tor Exit NodeGlobalHigh8h ago
Domainmalware-update-cdn-secure.netRansomware C2APAC regionMedium12h ago
Full feed access requires account.Sign in →
View Full IoC Feed →

Exposure Intelligence

Attackers trade stolen credentials, API keys, and source code long before organisations know they've been breached. RedSocs continuously monitors dark web forums, paste sites, Telegram channels, and breach databases — alerting you when your organisation's data appears.

🔑 Credential Breach Monitoring

Automated alerts when employee email addresses and password combinations appear in breach dumps. Covers both plaintext and hashed credentials matched against known hash dictionaries. Domain-wide monitoring with daily digest reports.

12.4B
Credentials indexed
<2h
Alert latency

⚙️ API Key & Secret Leak Detection

Scans GitHub repositories (public commits, gists, forks), paste sites, and dark web marketplaces for API keys, AWS credentials, database connection strings, and private keys associated with your domains and organisation name.

GitHub
+ 40 paste sources
Real-time
GitHub push monitoring

💻 Source Code Leak Intelligence

Detects when proprietary source code, configuration files, or internal documentation associated with your organisation appears on public repositories, paste sites, underground forums, or file-sharing services. Includes detection of code fingerprints and internal variable naming patterns.

Dark Web
Forum monitoring
Telegram
Channel tracking

Priority CVE Feeds

Not all CVEs are equal. RedSocs correlates the NVD, CISA Known Exploited Vulnerabilities (KEV) catalog, and our own threat intelligence to surface only the CVEs that matter for your specific technology stack — prioritised by active exploitation in the wild, not just CVSS score.

  • 🎯Stack-Specific Correlation: CVEs are matched against your detected asset versions — WordPress 6.x, PHP 8.2, Nginx 1.24, MySQL 8.0 — ensuring you only see advisories relevant to software you actually run.
  • 🔥Exploited-in-Wild Prioritisation: CVEs confirmed to have active exploitation in the wild (per CISA KEV + our threat actor tracking) are elevated to the top of your feed regardless of CVSS score. A CVSS 7.5 actively exploited vulnerability is more urgent than a theoretical CVSS 9.8.
  • 🇹🇭Thai Government Stack Tracking: Dedicated tracking for CVEs in software commonly deployed by Thai government agencies — specific Drupal modules, GovCMS configurations, Thai-market WordPress plugins, and e-services platform components.

OpenSSH Remote Code Execution (regreSSHion)

CRITICAL
CVE-2024-6387

Race condition in OpenSSH's signal handler allows unauthenticated remote code execution as root on glibc-based Linux systems. Affects OpenSSH <9.8p1. Actively exploited in the wild by multiple threat actors.

🔥 Actively ExploitedCVSS 8.1CISA KEV: Yes
Fix: Upgrade to OpenSSH 9.8p1 or restrict SSH access via firewall rules.

PHP CGI Remote Code Execution

CRITICAL
CVE-2024-4577

Argument injection vulnerability in PHP CGI mode on Windows systems allows unauthenticated attackers to execute arbitrary code. Bypasses the CVE-2012-1823 patch via character encoding tricks. Affects PHP 8.x in CGI mode.

🔥 Actively ExploitedCVSS 9.8CISA KEV: Yes
Fix: Disable PHP CGI mode. Migrate to PHP-FPM. Upgrade to PHP 8.3.8+.

WordPress Plugin SQL Injection

HIGH
CVE-2025-1234

SQL injection vulnerability in a widely-deployed WordPress plugin (50,000+ active installs) allows authenticated attackers with Subscriber-level access to extract full database contents via crafted REST API requests.

⚠️ PoC AvailableCVSS 8.8CISA KEV: No
Fix: Update plugin to patched version. Restrict subscriber registration if not needed.

Seamless Security Stack Integration

RedSocs threat intelligence is designed to integrate with your existing security infrastructure — not replace it. Feeds flow directly into your SIEM, SOAR, or ticketing system with minimal configuration.

📊

Live Dashboard

All IoC, CVE, and exposure intelligence surfaces automatically in the app.redsocs.com dashboard — filterable by asset, severity, and category.

Access Dashboard →
🔔

Webhook Push to SIEM

Real-time webhook delivery of new IoCs and CVE alerts to Splunk, Elastic SIEM, Microsoft Sentinel, or any webhook-compatible SIEM platform. Available on Professional tier and above.

📦

STIX/TAXII Export

Full STIX 2.1 formatted threat intelligence export via TAXII 2.1 server endpoint. Compatible with all major threat intelligence platforms (ThreatConnect, Anomali, MISP). Enterprise tier only.

📧

Automated Email Digests

Daily and weekly digest emails summarising new threats, exposure findings, and CVEs relevant to your asset inventory. Configurable recipients and cadence.