ScumBots (@scumbots) 's Twitter Profile
ScumBots

@scumbots

I drop dox on scumbag bots and RATs.

ID: 861230178164498433

calendar_today07-05-2017 14:44:10

32,32K Tweet

4,4K Takipçi

5 Takip Edilen

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Sat Nov 2 13:33:12 2024 UTC, located at hXXps://pastebin[.]com/raw/GxApQ5Fc C2: strong-wall[.]gl[.]at[.]ply[.]gg:45824 (IP: 147.185.221.23)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 14:38:12 2024 UTC, located at hXXps://pastebin[.]com/raw/MEVqkdnj C2: 4[.]tcp[.]eu[.]ngrok[.]io:11893 (IP: 3.121.139.82)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Tue Nov 5 22:21:09 2024 UTC, located at hXXps://pastebin[.]com/raw/q0NPU8CN C2: 0[.]tcp[.]sa[.]ngrok[.]io:8951 (IP: 18.230.84.69)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 02:53:05 2024 UTC, located at hXXps://pastebin[.]com/raw/sqmu0TyC C2: localbeheaders[.]mcgo[.]io:443 (IP: 108.16.60.193)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 12:43:06 2024 UTC, located at hXXps://pastebin[.]com/raw/2LbC3cGA C2: 185[.]244[.]29[.]113:5564

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 09:36:10 2024 UTC, located at hXXps://pastebin[.]com/raw/0VbbYPXn C2: 51[.]103[.]213[.]187:1234

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Tue Nov 5 19:08:11 2024 UTC, located at hXXps://pastebin[.]com/raw/uKw1X9bQ C2: sep-chapter[.]gl[.]at[.]ply[.]gg:47475 (IP: 147.185.221.23)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Fri Nov 1 22:29:07 2024 UTC, located at hXXps://pastebin[.]com/raw/uGh5fXiM C2: while-diseases[.]gl[.]at[.]ply[.]gg:45181 (IP: 147.185.221.23)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Fri Nov 1 20:09:07 2024 UTC, located at hXXps://pastebin[.]com/raw/LfF0rCNP C2: 185[.]94[.]29[.]15:6969

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Fri Nov 1 17:30:07 2024 UTC, located at hXXps://pastebin[.]com/raw/jyG4wPdZ C2: enjoy-instead[.]gl[.]at[.]ply[.]gg:44895 (IP: 147.185.221.23)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Fri Nov 1 16:46:11 2024 UTC, located at hXXps://pastebin[.]com/raw/RH5c3qqM C2: seems-kinda[.]gl[.]at[.]ply[.]gg:17320 (IP: 147.185.221.22)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Sun Nov 3 17:00:15 2024 UTC, located at hXXps://pastebin[.]com/raw/g74ytW50 C2: 185[.]46[.]10[.]13:1080

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Tue Nov 5 21:03:12 2024 UTC, located at hXXps://pastebin[.]com/raw/EJ2UmS6u C2: 185[.]94[.]29[.]15:8069

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Fri Nov 1 18:26:04 2024 UTC, located at hXXps://pastebin[.]com/raw/EUZA0xC8 C2: 49[.]49[.]193[.]37:8080

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 17:58:03 2024 UTC, located at hXXps://pastebin[.]com/raw/RpHAadxe C2: 0[.]tcp[.]sa[.]ngrok[.]io:12142 (IP: 18.230.84.69)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 18:00:23 2024 UTC, located at hXXps://pastebin[.]com/raw/vqbVKMUP C2: serveo[.]net:7897 (IP: 138.68.79.95)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 18:03:14 2024 UTC, located at hXXps://pastebin[.]com/raw/0FcFHab1 C2: serveo[.]net:7897 (IP: 138.68.79.95)

ScumBots (@scumbots) 's Twitter Profile Photo

#StagedC2 config observed at Wed Nov 6 19:54:21 2024 UTC, located at hXXps://pastebin[.]com/raw/icyjbcnF C2: 0[.]tcp[.]sa[.]ngrok[.]io:17163 (IP: 54.232.216.110)

Paul Melson (@pmelson) 's Twitter Profile Photo

Rather than continue to bang my head against the increasing frequency of nonsense errors and timeouts coming from Twitter’s APIs, I’ve decided just to move ScumBots. You can now follow it here on infosec.exchange: infosec.exchange/@ScumBots

ScumBots (@scumbots) 's Twitter Profile Photo

#Remcos SHA256: cd82340a2485580109f0250c99b7ea8cc5f4f40497c665d1ed525bbb9f8fc1c9 C2: tcp://newstartnewjournyevamygirllovesalotwithm[.]duckdns[.]org:14646,