Tarnkappe.info · @tarnkappeinfo
2039 followers · 4373 posts · Server social.tchncs.de
abuse.ch · @abuse_ch
475 followers · 27 posts · Server ioc.exchange

Malvertising campaign on Google Search, targeting Nvidia. But the malware page is actually Java-themed 🤔 Spreading

Payload domains:
🔥 nvidia .services
🔥 nvidia1 .top

Payload URL:
🌐 urlhaus.abuse.ch/url/2540641/

Payload:
📄 bazaar.abuse.ch/sample/1136c9d

AuroraBotnet C2:
📣 threatfox.abuse.ch/ioc/1069795

#aurorastealer

Last updated 1 year ago

ISC diary: @malware_traffic finds Google Ad --> fake Notepad++ page --> i5c.us/d29448

#aurorastealer

Last updated 2 years ago