invoke-eric · @invoke_eric
5 followers · 2 posts · Server infosec.exchange

The registrant "genafontc" appears to be shared by some domains like manigiajabae32[.]com
ktalarisa18[.]com
aonukanand11[.]com

#netsupportrat #c2

Last updated 3 years ago

Brad · @malware_traffic
2180 followers · 97 posts · Server infosec.exchange

2023-01-18 (Wednesday) - malspam pushes - Saw many of the same IOCs last month, reported at: github.com/pan-unit42/tweets/b

Email attachment (zip archive) available at: bazaar.abuse.ch/sample/be7b369

Last month, it was a link to download the zip archive. This month, the zip archive is an attachment. Otherwise, same infection traffic.

#netsupportrat

Last updated 3 years ago

da_667 · @da_667
3307 followers · 142 posts · Server infosec.exchange

Found this article in my threat intel feed:

asec.ahnlab.com/en/45312/

Looks like NetSupport RAT?

C2 domain/port: tradinghuy.duckdns[.]org:1488.

We have rules in the ETOPEN ruleset to catch NetSupport CnC Checkin, and the response from the server:

2035892 (NetSupport Remote Admin Checkin)
2035895 (NetSupport Remote Admin Response)

#threatintel #malware #netsupportrat #snort #suricata #iocsharing #ioc

Last updated 3 years ago

Brad · @malware_traffic
1958 followers · 65 posts · Server infosec.exchange

Available at: malware-traffic-analysis.net/2

- Traffic from (two split pcaps) of the infection

- A Fiddler capture for traffic leading to an initial zip download

- USPS-themed example

- Some malware/artifacts from this infection

#pcap #malspam #netsupportrat

Last updated 3 years ago

Brad · @malware_traffic
1958 followers · 65 posts · Server infosec.exchange

Tweet I wrote for: twitter.com/Unit42_Intel/statu

2022-12-28 (Wednesday): USPS-themed pushing - Some indicators available at: github.com/pan-unit42/tweets/b

If I get the time, I'll post a blog for some of the malware/artifacts/traffic. You know the deal....

#malspam #netsupportrat

Last updated 3 years ago

Jérôme Segura · @malwareinfosec
174 followers · 22 posts · Server infosec.exchange

The campaign which normally delivers , or is currently redirecting to a tech support scam :blobeyes:​

friscomusicgroup[.]com/br2

existsupport22[.]z13[.]web[.]core[.]windows[.]net

#sczriptzzbn #netsupportrat #solarmarker #icedid

Last updated 3 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

‘Coronavirus Report’ Emails Spread NetSupport RAT, Microsoft Warns - Attackers used malicious Excel 4.0 documents to spread the weaponized NetSupport RAT in a spear-ph... more: threatpost.com/coronavirus-ema -19 .0

#excel4 #covid #microsoft #coronavirus #websecurity #spearphishing #netsupportrat #remoteaccesstool #microsoftsecurityintelligence

Last updated 6 years ago