Brad · @malware_traffic
2104 followers · 87 posts · Server infosec.exchange

2023-01-12 (Thursday) - Google Ad --> Fake Notepad++ site textedit-notepad[.]com --> ()

I carved the inflated 777 MB EXE to remove all the padding. Sample available at:

- bazaar.abuse.ch/sample/2a4637e

- tria.ge/230113-eqwwfahg9v

- app.any.run/tasks/3d9a4477-305

C2 traffic:

- hxxp://164.90.172[.]224/blob/oo6nbv.a50a

#rhadamanthys #rhadamanthysstealer

Last updated 3 years ago

Brad · @malware_traffic
2019 followers · 74 posts · Server infosec.exchange

2023-01-03 (Tuesday) - Blog for malware from Google ad --> fake Notepad++ page updated to show this as malware.

Thanks to @500mk500, @ex_raritas, and @da_667 for identifying this sample!

malware-traffic-analysis.net/2

To see the changes, you might have to refresh the page, if you've already visited it.

#rhadamanthysstealer

Last updated 3 years ago