
Null Pwner
@nullpwner
Turning random hashes into aha-moments. Coffee fueled. Views mine.
ID: 114604009
http://badbyte.io 16-02-2010 00:54:47
51 Tweet
124 Takipçi
679 Takip Edilen


🚨 New Odyssey Stealer C2 Panel 🎯 hxxp://5.199.166[.]102/login This is the third C2 spin-up in a matter of days. Favicon: 9108dde25ad958b27f6a97d644775dee #Threathunting #Odyssey #Stealer #ThreatIntel MalwareHunterTeam Dee Who said what? RussianPanda 🐼 🇺🇦 Mikhail Kasimov
![Null Pwner (@nullpwner) on Twitter photo 🚨 New Odyssey Stealer C2 Panel
🎯 hxxp://5.199.166[.]102/login
This is the third C2 spin-up in a matter of days.
Favicon: 9108dde25ad958b27f6a97d644775dee
#Threathunting #Odyssey #Stealer #ThreatIntel
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> <a href="/500mk500/">Mikhail Kasimov</a> 🚨 New Odyssey Stealer C2 Panel
🎯 hxxp://5.199.166[.]102/login
This is the third C2 spin-up in a matter of days.
Favicon: 9108dde25ad958b27f6a97d644775dee
#Threathunting #Odyssey #Stealer #ThreatIntel
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> <a href="/500mk500/">Mikhail Kasimov</a>](https://pbs.twimg.com/media/Gp0KDNgWUAAdl2Q.jpg)

🚨 More VektorX C2 Panel 🎯hxxp://92.119.114[.]111:5173/auth/login - AS211381 🎯 91.211.249[.]147 🎯 62.233.53[.]22 🧬Hash: e9c154045c3e12a1a16617e0eaede551 @onyphe.io PD for the dev: Work on your logo tracing skills bro, they are therrible 😂 (/assets/fncVEJjF.png)
![Null Pwner (@nullpwner) on Twitter photo 🚨 More VektorX C2 Panel
🎯hxxp://92.119.114[.]111:5173/auth/login - AS211381
🎯 91.211.249[.]147
🎯 62.233.53[.]22
🧬Hash: e9c154045c3e12a1a16617e0eaede551 <a href="/onyphe/">@onyphe.io</a>
PD for the dev: Work on your logo tracing skills bro, they are therrible 😂 (/assets/fncVEJjF.png) 🚨 More VektorX C2 Panel
🎯hxxp://92.119.114[.]111:5173/auth/login - AS211381
🎯 91.211.249[.]147
🎯 62.233.53[.]22
🧬Hash: e9c154045c3e12a1a16617e0eaede551 <a href="/onyphe/">@onyphe.io</a>
PD for the dev: Work on your logo tracing skills bro, they are therrible 😂 (/assets/fncVEJjF.png)](https://pbs.twimg.com/media/Gp5FRaoXoAAznAb.jpg)

🚨 Fresh ClickFix Delivering Pentagon Stealer 🎯 hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev MalwareHunterTeam Dee Who said what? RussianPanda 🐼 🇺🇦 Mikhail Kasimov DaveTheResearcher ANY.RUN #pentagonstealer #threatintel #threathunt #stealer
![Null Pwner (@nullpwner) on Twitter photo 🚨 Fresh ClickFix Delivering Pentagon Stealer
🎯 hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
<a href="/anyrun_app/">ANY.RUN</a>
#pentagonstealer #threatintel #threathunt #stealer 🚨 Fresh ClickFix Delivering Pentagon Stealer
🎯 hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
<a href="/anyrun_app/">ANY.RUN</a>
#pentagonstealer #threatintel #threathunt #stealer](https://pbs.twimg.com/media/GqGD1WiWoAASMSR.png)

🚨 ClickFix - Sennheiser CF Phishing 🎯 hxxps://www.sennheiser[.]ad/ MalwareHunterTeam Dee Who said what? RussianPanda 🐼 🇺🇦 Mikhail Kasimov DaveTheResearcher #threatintel #clickfix #threathunting #PhishingScam
![Null Pwner (@nullpwner) on Twitter photo 🚨 ClickFix - Sennheiser CF Phishing
🎯 hxxps://www.sennheiser[.]ad/
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a>
<a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
#threatintel #clickfix #threathunting #PhishingScam 🚨 ClickFix - Sennheiser CF Phishing
🎯 hxxps://www.sennheiser[.]ad/
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a>
<a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
#threatintel #clickfix #threathunting #PhishingScam](https://pbs.twimg.com/media/GqGMY08WsAAdPPG.jpg)




🚨 Clickfix - Binance Phishing delivering VIDAR 🎯 193.24.123[.]165 🎯 traderai[.]name C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title). VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1 MalwareHunterTeam
![Null Pwner (@nullpwner) on Twitter photo 🚨 Clickfix - Binance Phishing delivering VIDAR
🎯 193.24.123[.]165
🎯 traderai[.]name
C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title).
VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1
<a href="/malwrhunterteam/">MalwareHunterTeam</a> 🚨 Clickfix - Binance Phishing delivering VIDAR
🎯 193.24.123[.]165
🎯 traderai[.]name
C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title).
VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1
<a href="/malwrhunterteam/">MalwareHunterTeam</a>](https://pbs.twimg.com/media/GqlQF4GXoAASOJ_.jpg)

🚨 Odyssey Stealer C2 Panel 🎯 odyssey-st[.]com 🎯 83.222.190[.]214 MalwareHunterTeam Dee Who said what? RussianPanda 🐼 🇺🇦 Mikhail Kasimov DaveTheResearcher
![Null Pwner (@nullpwner) on Twitter photo 🚨 Odyssey Stealer C2 Panel
🎯 odyssey-st[.]com
🎯 83.222.190[.]214
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a>
<a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a>
<a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a> 🚨 Odyssey Stealer C2 Panel
🎯 odyssey-st[.]com
🎯 83.222.190[.]214
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a>
<a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a>
<a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>](https://pbs.twimg.com/media/GqlSg2NXsAATZaR.png)

🚨 Introducing Mave Stealer C2 Panel: 🎯 web.mavedashboard[.]lol 🎯31.57.156[.]135 (AS210538) 🧬ea8aebfaedd0d287ac10c39a5a3c4de6 @onyphe.io Mave Stealer appears to have been launched on Apr 25. [@]squ4ts🐀<🐈 :) Any samples? MalwareHunterTeam Dee Who said what? RussianPanda 🐼 🇺🇦
![Null Pwner (@nullpwner) on Twitter photo 🚨 Introducing Mave Stealer C2 Panel:
🎯 web.mavedashboard[.]lol
🎯31.57.156[.]135 (AS210538)
🧬ea8aebfaedd0d287ac10c39a5a3c4de6 <a href="/onyphe/">@onyphe.io</a>
Mave Stealer appears to have been launched on Apr 25.
[@]squ4ts🐀<🐈 :)
Any samples?
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a> 🚨 Introducing Mave Stealer C2 Panel:
🎯 web.mavedashboard[.]lol
🎯31.57.156[.]135 (AS210538)
🧬ea8aebfaedd0d287ac10c39a5a3c4de6 <a href="/onyphe/">@onyphe.io</a>
Mave Stealer appears to have been launched on Apr 25.
[@]squ4ts🐀<🐈 :)
Any samples?
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda 🐼 🇺🇦</a>](https://pbs.twimg.com/media/Gqsa5ggWcAAFDme.jpg)




🚨 Odyssey Stealer C2 Panel 🎯 http[:]//194.26.29[.]217 AS 206728 Rotating infostealer infra. MalwareHunterTeam Dee Who said what? Mikhail Kasimov DaveTheResearcher
![Null Pwner (@nullpwner) on Twitter photo 🚨 Odyssey Stealer C2 Panel
🎯 http[:]//194.26.29[.]217 AS 206728
Rotating infostealer infra.
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a> 🚨 Odyssey Stealer C2 Panel
🎯 http[:]//194.26.29[.]217 AS 206728
Rotating infostealer infra.
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>](https://pbs.twimg.com/media/GryNI2GXUAAusyw.png)