Null Pwner
@nullpwner
Turning random hashes into aha-moments. Coffee fueled. Views mine.
ID: 114604009
http://badbyte.io 16-02-2010 00:54:47
51 Tweet
124 Followers
679 Following
π¨ New Odyssey Stealer C2 Panel π― hxxp://5.199.166[.]102/login This is the third C2 spin-up in a matter of days. Favicon: 9108dde25ad958b27f6a97d644775dee #Threathunting #Odyssey #Stealer #ThreatIntel MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov
π¨ More VektorX C2 Panel π―hxxp://92.119.114[.]111:5173/auth/login - AS211381 π― 91.211.249[.]147 π― 62.233.53[.]22 π§¬Hash: e9c154045c3e12a1a16617e0eaede551 @onyphe.io PD for the dev: Work on your logo tracing skills bro, they are therrible π (/assets/fncVEJjF.png)
π¨ Fresh ClickFix Delivering Pentagon Stealer π― hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov DaveTheResearcher ANY.RUN #pentagonstealer #threatintel #threathunt #stealer
π¨ ClickFix - Sennheiser CF Phishing π― hxxps://www.sennheiser[.]ad/ MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov DaveTheResearcher #threatintel #clickfix #threathunting #PhishingScam
π¨ ClickFix Delivering XWorm π― hxxps://lbkequityexchange[.]com/i.cmd π― hxxps://lbkequityexchange[.]com/EQTRN.exe π― Prob C2: winservicesconsole[.]duckdns.]org - 45.154.98[.]252 ASN 210558 π» Fake CAPTCHA β Runs PS script β Downloads i.cmd β Deploys XWorm while mimicking a
π¨ Clickfix - Binance Phishing delivering VIDAR π― 193.24.123[.]165 π― traderai[.]name C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title). VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1 MalwareHunterTeam
π¨ Odyssey Stealer C2 Panel π― odyssey-st[.]com π― 83.222.190[.]214 MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦ Mikhail Kasimov DaveTheResearcher
π¨ Introducing Mave Stealer C2 Panel: π― web.mavedashboard[.]lol π―31.57.156[.]135 (AS210538) π§¬ea8aebfaedd0d287ac10c39a5a3c4de6 @onyphe.io Mave Stealer appears to have been launched on Apr 25. [@]squ4tsπ<π :) Any samples? MalwareHunterTeam Dee Who said what? RussianPanda πΌ πΊπ¦
π¨ Odyssey Stealer C2 Panel π― http[:]//194.26.29[.]217 AS 206728 Rotating infostealer infra. MalwareHunterTeam Dee Who said what? Mikhail Kasimov DaveTheResearcher