ULTRAFRAUD
@ultrafraud
Underground bon vivant hunting for #malware
ID: 1519011129896411136
26-04-2022 17:51:15
217 Tweet
1,1K Takipçi
30 Takip Edilen
Active #Doenerium stealer dressed up as AnyDesk Software 🏴☠️ /anydesks.co/en/downloads/AnyDesk.exe 229037ea33eb267cc08621c8967ab4022f811461f716592ae95be23a8191bfe6 C2 /doenerium.kqnfkpoccicxiudstqonfotuwsrhuxkwhqjjfsbjhonoubrccy.nl
Another great analysis from Bridewell BridewellCTI 💣 Thank you guys Joshua Penny Yashraj Solanki for credits. #EasyStealer
Interesting loader disguised as CreateStudio Pro, dropping an obfuscated Python payload via PythonAnywhere 🐳 /download-createstudioo.com /kingkh.pythonanywhere.com ↪️/kingkh.pythonanywhere.com/SRC/test.zip
#100DaysofYARA Day83: Suspicious files attempting to impersonate Google Update Utilities github.com/RustyNoob-619/… Thanks to ULTRAFRAUD for sharing the signed malware sample which allowed me to build this YARA