 
                                JAMESWT
@jameswt_wt
#Independent #Malware #Hunter
#CyberSecurity #InfoSec
virustotal.com/gui/user/james…
ID: 3433210978
20-08-2015 19:05:01
52,52K Tweet
36,36K Followers
487 Following
 
         
        🔍New Blog: JustAskJacky -- AI brings back classical trojan horse malware 🔗gdatasoftware.com/blog/2025/08/3… #GDATA G DATA Global #GDATATechblog
 
         
         
         
        𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 JAMESWT Andrea (Drego) Draghetti 👨🏻💻 🎣 Claudia Gianni Amato TG Soft Germán Fernández Ne0ne | Igal proxylife ShadowOpCode Simplicio Sam L. ANY.RUN Thanks for sharing Erik! I think there are some more C2 IPs connected to this TA: (via pDNS & SMB NetBIOS) virustotal.com/gui/domain/esp… 2025-08-08 - 94.26.90[.245 2025-07-02 - 45.74.10[.38 2025-06-22 - 74.208.226[.175 2025-03-26 - 176.65.144[.162 #AsyncRAT #ResolverRAT #server60929
 
                        
                    
                    
                    
                 
         
         
         
         
         
         
        Amazing reflection on trojans from Karsten Hahn . JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too: AskBettyHow, DailyChefly, GoCookMate, etc. JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com
![Squiblydoo (@squiblydooblog) on Twitter photo Amazing reflection on trojans from <a href="/struppigel/">Karsten Hahn</a> .
JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too:
AskBettyHow, DailyChefly, GoCookMate, etc.
JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com Amazing reflection on trojans from <a href="/struppigel/">Karsten Hahn</a> .
JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too:
AskBettyHow, DailyChefly, GoCookMate, etc.
JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com](https://pbs.twimg.com/media/GyYySH_bgAAooN_.png) 
                        
                    
                    
                    
                 
         
         
         
         
         
         
         
         
                         
                         
                         
                        ![JAMESWT (@jameswt_wt) on Twitter photo #compromised #italy
mtecommerce.]it
#Phishing pdf #fakecaptcha 
ASN AS39729 REGISTER-AS REGISTER S.P.A., IT (registered Apr 18, 2006)<a href="/registerit/">Register</a> #compromised #italy
mtecommerce.]it
#Phishing pdf #fakecaptcha 
ASN AS39729 REGISTER-AS REGISTER S.P.A., IT (registered Apr 18, 2006)<a href="/registerit/">Register</a>](https://pbs.twimg.com/media/GyX0gdBWAAMVOlo.jpg) 
                         
                         
                         
                         
                         
                         
                         
                        ![JAMESWT (@jameswt_wt) on Twitter photo #spam #Italy #RemcosRAT
"CONFERMA DELL'ESECUZIONE DELLA TRANSAZIONE.docx"
👇
bazaar.abuse.ch/browse/tag/car…
⛔️172.96.172.]174
⛔️carljas.duckdns.]org #spam #Italy #RemcosRAT
"CONFERMA DELL'ESECUZIONE DELLA TRANSAZIONE.docx"
👇
bazaar.abuse.ch/browse/tag/car…
⛔️172.96.172.]174
⛔️carljas.duckdns.]org](https://pbs.twimg.com/media/Gyd8RbEWMAAFppf.jpg) 
                        