
Null Pwner
@nullpwner
Turning random hashes into aha-moments. Coffee fueled. Views mine.
ID: 114604009
http://badbyte.io 16-02-2010 00:54:47
51 Tweet
124 Followers
679 Following


π¨ New Odyssey Stealer C2 Panel π― hxxp://5.199.166[.]102/login This is the third C2 spin-up in a matter of days. Favicon: 9108dde25ad958b27f6a97d644775dee #Threathunting #Odyssey #Stealer #ThreatIntel MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov
![Null Pwner (@nullpwner) on Twitter photo π¨ New Odyssey Stealer C2 Panel
π― hxxp://5.199.166[.]102/login
This is the third C2 spin-up in a matter of days.
Favicon: 9108dde25ad958b27f6a97d644775dee
#Threathunting #Odyssey #Stealer #ThreatIntel
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a> <a href="/500mk500/">Mikhail Kasimov</a> π¨ New Odyssey Stealer C2 Panel
π― hxxp://5.199.166[.]102/login
This is the third C2 spin-up in a matter of days.
Favicon: 9108dde25ad958b27f6a97d644775dee
#Threathunting #Odyssey #Stealer #ThreatIntel
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a> <a href="/500mk500/">Mikhail Kasimov</a>](https://pbs.twimg.com/media/Gp0KDNgWUAAdl2Q.jpg)

π¨ More VektorX C2 Panel π―hxxp://92.119.114[.]111:5173/auth/login - AS211381 π― 91.211.249[.]147 π― 62.233.53[.]22 π§¬Hash: e9c154045c3e12a1a16617e0eaede551 @onyphe.io PD for the dev: Work on your logo tracing skills bro, they are therrible π (/assets/fncVEJjF.png)
![Null Pwner (@nullpwner) on Twitter photo π¨ More VektorX C2 Panel
π―hxxp://92.119.114[.]111:5173/auth/login - AS211381
π― 91.211.249[.]147
π― 62.233.53[.]22
π§¬Hash: e9c154045c3e12a1a16617e0eaede551 <a href="/onyphe/">@onyphe.io</a>
PD for the dev: Work on your logo tracing skills bro, they are therrible π (/assets/fncVEJjF.png) π¨ More VektorX C2 Panel
π―hxxp://92.119.114[.]111:5173/auth/login - AS211381
π― 91.211.249[.]147
π― 62.233.53[.]22
π§¬Hash: e9c154045c3e12a1a16617e0eaede551 <a href="/onyphe/">@onyphe.io</a>
PD for the dev: Work on your logo tracing skills bro, they are therrible π (/assets/fncVEJjF.png)](https://pbs.twimg.com/media/Gp5FRaoXoAAznAb.jpg)

π¨ Fresh ClickFix Delivering Pentagon Stealer π― hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov DaveTheResearcher ANY.RUN #pentagonstealer #threatintel #threathunt #stealer
![Null Pwner (@nullpwner) on Twitter photo π¨ Fresh ClickFix Delivering Pentagon Stealer
π― hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
<a href="/anyrun_app/">ANY.RUN</a>
#pentagonstealer #threatintel #threathunt #stealer π¨ Fresh ClickFix Delivering Pentagon Stealer
π― hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
<a href="/anyrun_app/">ANY.RUN</a>
#pentagonstealer #threatintel #threathunt #stealer](https://pbs.twimg.com/media/GqGD1WiWoAASMSR.png)

π¨ ClickFix - Sennheiser CF Phishing π― hxxps://www.sennheiser[.]ad/ MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov DaveTheResearcher #threatintel #clickfix #threathunting #PhishingScam
![Null Pwner (@nullpwner) on Twitter photo π¨ ClickFix - Sennheiser CF Phishing
π― hxxps://www.sennheiser[.]ad/
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a>
<a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
#threatintel #clickfix #threathunting #PhishingScam π¨ ClickFix - Sennheiser CF Phishing
π― hxxps://www.sennheiser[.]ad/
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a>
<a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
#threatintel #clickfix #threathunting #PhishingScam](https://pbs.twimg.com/media/GqGMY08WsAAdPPG.jpg)

π¨ ClickFix Delivering XWorm π― hxxps://lbkequityexchange[.]com/i.cmd π― hxxps://lbkequityexchange[.]com/EQTRN.exe π― Prob C2: winservicesconsole[.]duckdns.]org - 45.154.98[.]252 ASN 210558 π» Fake CAPTCHA β Runs PS script β Downloads i.cmd β Deploys XWorm while mimicking a



π¨ Clickfix - Binance Phishing delivering VIDAR π― 193.24.123[.]165 π― traderai[.]name C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title). VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1 MalwareHunterTeam
![Null Pwner (@nullpwner) on Twitter photo π¨ Clickfix - Binance Phishing delivering VIDAR
π― 193.24.123[.]165
π― traderai[.]name
C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title).
VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1
<a href="/malwrhunterteam/">MalwareHunterTeam</a> π¨ Clickfix - Binance Phishing delivering VIDAR
π― 193.24.123[.]165
π― traderai[.]name
C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title).
VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1
<a href="/malwrhunterteam/">MalwareHunterTeam</a>](https://pbs.twimg.com/media/GqlQF4GXoAASOJ_.jpg)

π¨ Odyssey Stealer C2 Panel π― odyssey-st[.]com π― 83.222.190[.]214 MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov DaveTheResearcher
![Null Pwner (@nullpwner) on Twitter photo π¨ Odyssey Stealer C2 Panel
π― odyssey-st[.]com
π― 83.222.190[.]214
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a>
<a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a>
<a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a> π¨ Odyssey Stealer C2 Panel
π― odyssey-st[.]com
π― 83.222.190[.]214
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a>
<a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a>
<a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>](https://pbs.twimg.com/media/GqlSg2NXsAATZaR.png)

π¨ Introducing Mave Stealer C2 Panel: π― web.mavedashboard[.]lol π―31.57.156[.]135 (AS210538) π§¬ea8aebfaedd0d287ac10c39a5a3c4de6 @onyphe.io Mave Stealer appears to have been launched on Apr 25. [@]squ4tsπ<π :) Any samples? MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦
![Null Pwner (@nullpwner) on Twitter photo π¨ Introducing Mave Stealer C2 Panel:
π― web.mavedashboard[.]lol
π―31.57.156[.]135 (AS210538)
π§¬ea8aebfaedd0d287ac10c39a5a3c4de6 <a href="/onyphe/">@onyphe.io</a>
Mave Stealer appears to have been launched on Apr 25.
[@]squ4tsπ<π :)
Any samples?
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a> π¨ Introducing Mave Stealer C2 Panel:
π― web.mavedashboard[.]lol
π―31.57.156[.]135 (AS210538)
π§¬ea8aebfaedd0d287ac10c39a5a3c4de6 <a href="/onyphe/">@onyphe.io</a>
Mave Stealer appears to have been launched on Apr 25.
[@]squ4tsπ<π :)
Any samples?
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda πΌ πΊπ¦</a>](https://pbs.twimg.com/media/Gqsa5ggWcAAFDme.jpg)




π¨ Odyssey Stealer C2 Panel π― http[:]//194.26.29[.]217 AS 206728 Rotating infostealer infra. MalwareHunterTeam Dee Who said what? Mikhail Kasimov DaveTheResearcher
![Null Pwner (@nullpwner) on Twitter photo π¨ Odyssey Stealer C2 Panel
π― http[:]//194.26.29[.]217 AS 206728
Rotating infostealer infra.
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a> π¨ Odyssey Stealer C2 Panel
π― http[:]//194.26.29[.]217 AS 206728
Rotating infostealer infra.
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>](https://pbs.twimg.com/media/GryNI2GXUAAusyw.png)