7ambola
@1nt3l_hunt
ID: 1911415630328123393
13-04-2025 13:46:29
4 Tweet
1 Followers
87 Following
#ZoomEye #ThreatHunting | #ClickFix Similar Cluster Query: google-privacy-policy-Cb0CGVRT.svg IoCs: pastebin.com/qZCEFSpU ref: x.com/1nt3l_hunt/sta… Michael Koczwara Mikhail Kasimov Ginkgo MalwareHunterTeam ZoomEye
Observed domains embedding PowerShell commands in their TXT records. DomainTools Fox_threatintel WatchingRac Squiblydoo ܛܔܔܔܛܔܛܔܛ Mikhail Kasimov Demon Szabolcs Schmidt
Elon Musk Elon Musk, you are lying and you know you are lying. After once being ‘relatively’ free in your speech, it seems fear has overtaken you, and you have started flattering and pandering to your masters in the Zionist lobby in a cheap manner, even by distorting the facts in a crude
Abdelghafour B. 🇵🇸 Fox_threatintel WatchingRac Squiblydoo MalwareHunterTeam ܛܔܔܔܛܔܛܔܛ Mikhail Kasimov Demon Szabolcs Schmidt the initial clipboard hijack downloads a .wav file. it will be downloaded renamed & executed here temp\c3b4\rmnaj7.ps1 The ps1 script is a dropper for the main payload base64 encoded decoded that and got main payload virus total scan of both files: (ps1 script)