Geekmaster 👽:system76: · @Geekmaster
147 followers · 1108 posts · Server ioc.exchange

admin will be extradited to the US, charged for computer crimeshttps://www.malwarebytes.com/blog/news/2022/11/racoon-stealer-admin-will-be-extradited-to-the-us-charged-for-computer-crimes

#raccoonstealer #hacking #malwareasaservice

Last updated 2 years ago

bencrypted@localhost:~$| · @bencrypted
147 followers · 60 posts · Server infosec.exchange

Sophos has observed some / activity following a search for cracked software.
🔎 Google Search: fences download crack
Cracked Software Site:
➡️ hxxps[://]pesktop[.]com/en/windows/stardock_fences_setup
Download Button + Instructions:
➡️ hxxps[://]adainstaller[.]com/aofiler/<>-pesktop[.]php

Redirection Chain:
↪️ hxxps[://]xdrt656y[.]cfd/?i=Also-Download-its-Full-Activator&u=<>&site=hxxps[://]tinyurl[.]com
↪️ hxxps[://]href[.]li/?hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]href[.]li/?hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]href[.]li/?hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file
⬇️ hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file

Sample: virustotal.com/gui/file/b01c45
PE: a44b78a4cf37bf69a8b750d0a057c228f6bf80362911911950044638c2a2f462

Communicates via port 80 to C2:
hxxp://79.137.197[.]190/45c8e6f57dca0fdb5db9c679b502e12b

#recordbreaker #raccoonstealer #threatintel #infostealer

Last updated 2 years ago

bencrypted@localhost:~$| · @bencrypted
147 followers · 60 posts · Server infosec.exchange

Sophos has observed some / activity following a search for cracked software.
🔎 Google Search: fences download crack
Cracked Software Site:
➡️ hxxps[://]pesktop[.]com/en/windows/stardock_fences_setup
Download Button + Instructions:
➡️ hxxps[://]adainstaller[.]com/aofiler/<>-pesktop[.]php

Redirection Chain:
↪️ hxxps[://]xdrt656y[.]cfd/?i=Also-Download-its-Full-Activator&u=<>&site=hxxps[://]tinyurl[.]com
↪️ hxxps[://]href[.]li/?hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]href[.]li/?hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]href[.]li/?hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file
⬇️ hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file

Sample: virustotal.com/gui/file/b01c45
PE: a44b78a4cf37bf69a8b750d0a057c228f6bf80362911911950044638c2a2f462

Communicates via port 80 to C2:
hxxp://79.137.197[.]190/45c8e6f57dca0fdb5db9c679b502e12b

#recordbreaker #raccoonstealer #threatintel #infostealer

Last updated 2 years ago

bencrypted@localhost:~$| · @bencrypted
147 followers · 60 posts · Server infosec.exchange

Sophos has observed some / activity following a search for cracked software.
🔎 Google Search: fences download crack
Cracked Software Site:
➡️ hxxps[://]pesktop[.]com/en/windows/stardock_fences_setup
Download Button + Instructions:
➡️ hxxps[://]adainstaller[.]com/aofiler/<>-pesktop[.]php

Redirection Chain:
↪️ hxxps[://]xdrt656y[.]cfd/?i=Also-Download-its-Full-Activator&u=<>&site=hxxps[://]tinyurl[.]com
↪️ hxxps[://]href[.]li/?hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]href[.]li/?hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]href[.]li/?hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file
⬇️ hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file

Sample: virustotal.com/gui/file/b01c45
PE: a44b78a4cf37bf69a8b750d0a057c228f6bf80362911911950044638c2a2f462

Communicates via port 80 to C2:
hxxp://79.137.197[.]190/45c8e6f57dca0fdb5db9c679b502e12b

#recordbreaker #raccoonstealer #threatintel #infostealer

Last updated 2 years ago

bencrypted@localhost:~$| · @bencrypted
147 followers · 60 posts · Server infosec.exchange

Sophos has observed some / activity following a search for cracked software.
🔎 Google Search: fences download crack
Cracked Software Site:
➡️ hxxps[://]pesktop[.]com/en/windows/stardock_fences_setup
Download + Instructions:
➡️ hxxps[://]adainstaller[.]com/aofiler/<>-pesktop[.]php
Redirection Chain:
↪️ hxxps[://]xdrt656y[.]cfd/?i=Also-Download-its-Full-Activator&u=<>&site=hxxps[://]tinyurl[.]com
↪️ hxxps[://]href[.]li/?hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]href[.]li/?hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]href[.]li/?hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file
⬇️hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file

Sample: virustotal.com/gui/file/b01c45
PE: a44b78a4cf37bf69a8b750d0a057c228f6bf80362911911950044638c2a2f462

Communicates via port 80 to C2:
hxxp://79.137.197[.]190/45c8e6f57dca0fdb5db9c679b502e12b

#recordbreaker #raccoonstealer #threatintel #infostealer

Last updated 2 years ago

bencrypted@localhost:~$| · @bencrypted
147 followers · 60 posts · Server infosec.exchange

Sophos has observed some / activity following a search for cracked software.
🔎 Google Search: fences download crack
Cracked Software Site:
➡️ hxxps[://]pesktop[.]com/en/windows/stardock_fences_setup
Download + Instructions:
➡️ hxxps[://]adainstaller[.]com/aofiler/<>-pesktop[.]php
↪️ Redirection Chain:
- hxxps[://]xdrt656y[.]cfd/?i=Also-Download-its-Full-Activator&u=<>&site=hxxps[://]tinyurl[.]com
- hxxps[://]href[.]li/?hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
- hxxps[://]vghu896yh[.]cfd/?56_56=<>&file=Also-Download-its-Full-Activator&h={pubid}
- hxxps[://]href[.]li/?hxxps[://]bit[.]ly/New_FullLatestFile--Here
- hxxps[://]bit[.]ly/New_FullLatestFile--Here
- hxxps[://]href[.]li/?hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file

Sample: virustotal.com/gui/file/b01c45
PE: a44b78a4cf37bf69a8b750d0a057c228f6bf80362911911950044638c2a2f462

Communicates via port 80 to C2:
hxxp://79.137.197[.]190/45c8e6f57dca0fdb5db9c679b502e12b

#recordbreaker #raccoonstealer #threatintel #infostealer

Last updated 2 years ago

bencrypted@localhost:~$| · @bencrypted
147 followers · 60 posts · Server infosec.exchange

Sophos has observed some / activity following a search for cracked software.

🔎 Google Search: fences download crack
Cracked Software Site
➡️ hxxps[://]pesktop[.]com/en/windows/stardock_fences_setup
Instructions + Redirection
➡️ hxxps[://]adainstaller[.]com/aofiler/hjksdgfd4657i687iyouhkjgfrctxy5uerytukj-pesktop[.]php
Redirection Chain
↪️ hxxps[://]xdrt656y[.]cfd/?i=Also-Download-its-Full-Activator&u=1675670242&t=82&site=hxxps[://]tinyurl[.]com
↪️ hxxps[://]href[.]li/?hxxps[://]vghu896yh[.]cfd/?56_56=vjxRHYBnsOtTEqDMNa6VWzb4Ki2LowImSklQyAp&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]vghu896yh[.]cfd/?56_56=vjxRHYBnsOtTEqDMNa6VWzb4Ki2LowImSklQyAp&file=Also-Download-its-Full-Activator&h={pubid}
↪️ hxxps[://]href[.]li/?hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]bit[.]ly/New_FullLatestFile--Here
↪️ hxxps[://]href[.]li/?hxxps[://]www[.]mediafire[.]com/file/xkv5ulf2kwf7roo/Use-2022_As_PasW0rD-LatestFile-L4[.]rar/file

Sample: virustotal.com/gui/file/b01c45
PE: a44b78a4cf37bf69a8b750d0a057c228f6bf80362911911950044638c2a2f462

Communicates via port 80 to C2:
hxxp://79.137.197[.]190/45c8e6f57dca0fdb5db9c679b502e12b

#recordbreaker #raccoonstealer #threatintel #infostealer

Last updated 2 years ago

John F · @Abjuri5t
7 followers · 3 posts · Server infosec.exchange

Cluster of servers hosted by on 77.73.133[.]0/24 ☢️

Includes:
- bot 🤖
- 🕵️‍♂️​
- - especially active at 77.73.133[.]20, 77.73.133[.]93, 77.73.133[.]120
- 🕵️

I’m working to rebuild my automated C2 tracking over on abjuri5t.github.io/SarlackLab/. Figured I’d start sharing some of the data I have gathered with the community.

As per @pixelnull‘s suggestion, I’m tagging this with for threat intel visibility

#c2 #partnerllc #lilith #raccoonstealer #cobaltstrike #RedLineStealer #ioc

Last updated 2 years ago

John F · @Abjuri5t
57 followers · 11 posts · Server infosec.exchange

Cluster of servers hosted by on 77.73.133[.]0/24 ☢️

Includes:
- bot 🤖
- 🕵️‍♂️​
- - especially active at 77.73.133[.]20, 77.73.133[.]93, 77.73.133[.]120
- 🕵️

I’m working to rebuild my automated C2 tracking over on abjuri5t.github.io/SarlackLab/. Figured I’d start sharing some of the data I have gathered with the community.

As per @pixelnull‘s suggestion, I’m tagging this with for threat intel visibility

#c2 #partnerllc #lilith #raccoonstealer #cobaltstrike #RedLineStealer #ioc

Last updated 2 years ago

Stephan Simon :verified_paw: · @FirehaK
348 followers · 171 posts · Server infosec.exchange

Just created a bot account for updates. It isn't active yet, but meant to be a project for me. The bot will live at @RaccoonStealerBot! 🦝​

Side note, I used DALL·E to generate the images and I love them.

#raccoonstealer

Last updated 2 years ago

dispatch · @dispatch
472 followers · 2723 posts · Server ioc.exchange
ITSEC News · @itsecbot
856 followers · 32559 posts · Server schleuss.online

Accused ‘Raccoon’ Malware Developer Fled Ukraine After Russian Invasion - A 26-year-old Ukrainian man is awaiting extradition from The Netherlands to the Un... krebsonsecurity.com/2022/10/ac -do-wellnews .andinoreynal

#alexjones #raccoonstealer #marksokolovsky #f #alittlesunshine #neer #raccooninfostealer

Last updated 2 years ago

Stephan Simon :verified_paw: · @FirehaK
348 followers · 171 posts · Server infosec.exchange

My latest rule is for v2 which I've been following since June!

github.com/FirehaK/YARA/blob/m

#raccoonstealer

Last updated 2 years ago

Parliamo di news! · @parliamodinews
15 followers · 87553 posts · Server masthead.social