abuse.ch :verified: · @abuse_ch
1232 followers · 54 posts · Server ioc.exchange

RAT dropped by Pay-Per-Install (PPI) campaign πŸ”₯

Payload URLs:
🌐 urlhaus.abuse.ch/url/2693412/
🌐 urlhaus.abuse.ch/url/2693420/

Botnet C2 domains:
πŸ“ž threatfox.abuse.ch/ioc/1143951
πŸ“ž threatfox.abuse.ch/ioc/1143952

Botnet C2 server hosted Vultr πŸ‡ΊπŸ‡Έ:
πŸ€– threatfox.abuse.ch/ioc/1143953

#netsupport #gcleaner

Last updated 1 year ago

James_inthe_box · @james_inthe_box
173 followers · 48 posts · Server infosec.exchange

Lots' to look at...this drops all manner of junk...including a recent (Dec 13)

app.any.run/tasks/a2c31fa0-84f

app.any.run/tasks/54a6b1cf-db6

c2: luaobe32[.]top

#gcleaner #cryptbot

Last updated 2 years ago

abuse.ch · @abuse_ch
62 followers · 2 posts · Server ioc.exchange

Dear - just because you use "itsnotmalware" in your URL path it doesn't mean that you are actually not malware πŸ˜‚

Sample:
πŸ“„ bazaar.abuse.ch/sample/bdb90c7

GCleaner botnet C2:
πŸ‘‰ threatfox.abuse.ch/ioc/1021151

#gcleaner

Last updated 2 years ago