Brad · @malware_traffic
2344 followers · 132 posts · Server infosec.exchange

2023-03-02 (Thursday) - pushes loader that retrieves malware. , malware/artifacts, and IOCs available at malware-traffic-analysis.net/2

#rigek #RedLineStealer #pcap

Last updated 1 year ago

Brad · @malware_traffic
2260 followers · 114 posts · Server infosec.exchange

Also posted at: twitter.com/malware_traffic/st

2023-02-03 (Friday) - DEV-0569 activity: Google ad fake CPUID page --> "FakeBat" Loader --> Redline Stealer & Gozi/ISFB/Ursnif

IOCs, pcap of the infection, and associated malware/artifacts available at: malware-traffic-analysis.net/2

Tags:

Hopefully, recent blogs about all these malicious Google ads will force Google to change something. But I have a feeling Google will keep on being Google.

#dev0569 #fakebat #gozi #isfb #malware #pcap #redline #RedLineStealer #ursnif

Last updated 2 years ago

Opalsec :verified: · @Opalsec
77 followers · 43 posts · Server infosec.exchange

Looks like the has gotten in on the action, using it to deliver a malicious .bat file that kicks off a PowerShell stager script:

twitter.com/Unit42_Intel/statu

Original Tweet Content:
A new method for delivering via attachments was observed (e03d1dc90b981455ff453c996a919848074c6e735719148eeb8e1185935c28b3). Extracted C2 configuration: {"C2 url": ["172.245.45.213:3235"], "Bot Id": "Skijay2"}

We've published an article on how OneNote works as a maldoc format, and provide a few tips and tools to help in analysis: opalsec.substack.com/p/onenote

#redline #infostealer #onenote #RedLineStealer #malware #infosec

Last updated 2 years ago

Colin Cowie · @th3_protoCOL
642 followers · 193 posts · Server infosec.exchange

Picking backup with Day 1️⃣​6️⃣​- Fake installers archives with adobe AfterFX
🔗​ github.com/colincowie/100DaysO

Recently @rmceoin shared details about a malvertizing campaign using fake installers:
📖​ infosec.exchange/@rmceoin/1097

Todays yara rule looks for these archives by detecting on the packaged legit adobe file, `AfterFXLib.dll`. Some of the themes found were:
📍​ LastPass
📍​ OnionBrowser
📍​ Rufus
📍​ Notepad++

#100DaysofYARA #RedLineStealer #malware

Last updated 2 years ago

Walker · @Walker
32 followers · 154 posts · Server infosec.exchange

Has anyone seen compromise , either directly or through Chrome plugins?

What would connections to Redline C2 IPs from Google Chrome Helper or com.apple.WebKit.Networking mean?

I have only foud a few artilces on Mac impacted by Redline so I dont know if it is a thing yet.

#RedLineStealer #macs #threatintel #malware

Last updated 2 years ago

John F · @Abjuri5t
7 followers · 3 posts · Server infosec.exchange

Cluster of servers hosted by on 77.73.133[.]0/24 ☢️

Includes:
- bot 🤖
- 🕵️‍♂️​
- - especially active at 77.73.133[.]20, 77.73.133[.]93, 77.73.133[.]120
- 🕵️

I’m working to rebuild my automated C2 tracking over on abjuri5t.github.io/SarlackLab/. Figured I’d start sharing some of the data I have gathered with the community.

As per @pixelnull‘s suggestion, I’m tagging this with for threat intel visibility

#c2 #partnerllc #lilith #raccoonstealer #cobaltstrike #RedLineStealer #ioc

Last updated 2 years ago

John F · @Abjuri5t
57 followers · 11 posts · Server infosec.exchange

Cluster of servers hosted by on 77.73.133[.]0/24 ☢️

Includes:
- bot 🤖
- 🕵️‍♂️​
- - especially active at 77.73.133[.]20, 77.73.133[.]93, 77.73.133[.]120
- 🕵️

I’m working to rebuild my automated C2 tracking over on abjuri5t.github.io/SarlackLab/. Figured I’d start sharing some of the data I have gathered with the community.

As per @pixelnull‘s suggestion, I’m tagging this with for threat intel visibility

#c2 #partnerllc #lilith #raccoonstealer #cobaltstrike #RedLineStealer #ioc

Last updated 2 years ago

Jérôme Segura · @malwareinfosec
189 followers · 27 posts · Server infosec.exchange

using CVE-2021-26411 to drop

adsgoandway[.]xyz
45.138.26[.]85
5e3cb42e4207ab074e2d8564867cf94fb3f414d414ebc055d9c784a462dc150e

#rigek #RedLineStealer

Last updated 2 years ago

Dmitry Bestuzhev · @dimitribest
28 followers · 11 posts · Server infosec.exchange

drop via

Initial OLE: twitter.com/InQuest/status/159

Final payload:
7735fa649a6443d05bcac59678d03556 *ddd.exe

#RedLineStealer #bitbucket

Last updated 2 years ago

0xSaiyanGod · @0xSaiyanGod
9 followers · 24 posts · Server infosec.exchange

So I went on a hunt and ran into I had to set up some analysis but eventually ended up running it and watching it phone home to a known server

#RedLineStealer #malware #infosec #hunter #legendarysaiyanhacker

Last updated 2 years ago

Dmitry Bestuzhev · @dimitribest
28 followers · 11 posts · Server infosec.exchange
Tarnkappe.info · @tarnkappeinfo
1530 followers · 3787 posts · Server social.tchncs.de