Null Pwner
@nullpwner
Turning random hashes into aha-moments. Coffee fueled. Views mine.
ID: 114604009
http://badbyte.io 16-02-2010 00:54:47
51 Tweet
124 Takipรงi
679 Takip Edilen
๐จ New Odyssey Stealer C2 Panel ๐ฏ hxxp://5.199.166[.]102/login This is the third C2 spin-up in a matter of days. Favicon: 9108dde25ad958b27f6a97d644775dee #Threathunting #Odyssey #Stealer #ThreatIntel MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov
๐จ More VektorX C2 Panel ๐ฏhxxp://92.119.114[.]111:5173/auth/login - AS211381 ๐ฏ 91.211.249[.]147 ๐ฏ 62.233.53[.]22 ๐งฌHash: e9c154045c3e12a1a16617e0eaede551 @onyphe.io PD for the dev: Work on your logo tracing skills bro, they are therrible ๐ (/assets/fncVEJjF.png)
๐จ Fresh ClickFix Delivering Pentagon Stealer ๐ฏ hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov DaveTheResearcher ANY.RUN #pentagonstealer #threatintel #threathunt #stealer
๐จ ClickFix - Sennheiser CF Phishing ๐ฏ hxxps://www.sennheiser[.]ad/ MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov DaveTheResearcher #threatintel #clickfix #threathunting #PhishingScam
๐จ ClickFix Delivering XWorm ๐ฏ hxxps://lbkequityexchange[.]com/i.cmd ๐ฏ hxxps://lbkequityexchange[.]com/EQTRN.exe ๐ฏ Prob C2: winservicesconsole[.]duckdns.]org - 45.154.98[.]252 ASN 210558 ๐ป Fake CAPTCHA โ Runs PS script โ Downloads i.cmd โ Deploys XWorm while mimicking a
๐จ Clickfix - Binance Phishing delivering VIDAR ๐ฏ 193.24.123[.]165 ๐ฏ traderai[.]name C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title). VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1 MalwareHunterTeam
๐จ Odyssey Stealer C2 Panel ๐ฏ odyssey-st[.]com ๐ฏ 83.222.190[.]214 MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov DaveTheResearcher
๐จ Introducing Mave Stealer C2 Panel: ๐ฏ web.mavedashboard[.]lol ๐ฏ31.57.156[.]135 (AS210538) ๐งฌea8aebfaedd0d287ac10c39a5a3c4de6 @onyphe.io Mave Stealer appears to have been launched on Apr 25. [@]squ4ts๐<๐ :) Any samples? MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ
๐จ Odyssey Stealer C2 Panel ๐ฏ http[:]//194.26.29[.]217 AS 206728 Rotating infostealer infra. MalwareHunterTeam Dee Who said what? Mikhail Kasimov DaveTheResearcher