 
                                Kelsey
@k3dg3
@proofpoint | Friendly NEIGHborhood Threat Researcher | Reverse Engineer
ID: 1060893385978978308
09-11-2018 13:54:28
654 Tweet
3,3K Takipçi
307 Takip Edilen
 
         
         
         
        I don’t repost much, but Greg Lesnewich is kind of awesome!
 
         
         
         
         
         
         
         
        Related Pdf👇 "Comprovante-Mercado-Pago-26-05-2025-.pdf" ❇️Related #XWorm V5.2 ⛔️C2 158.69.41.]120:8000 Samples bazaar.abuse.ch/browse/tag/158… ✅AnyRun app.any.run/tasks/29f57a2f… 1/2 cc Dodo on Security 🇵🇸 🇺🇦 Germán Fernández ܛܔܔܔܛܔܛܔܛ Mikhail Kasimov Kelsey
![JAMESWT (@jameswt_wt) on Twitter photo Related Pdf👇
"Comprovante-Mercado-Pago-26-05-2025-.pdf"
❇️Related  #XWorm V5.2
⛔️C2 158.69.41.]120:8000 Samples 
bazaar.abuse.ch/browse/tag/158…
✅AnyRun
app.any.run/tasks/29f57a2f…
1/2
cc <a href="/dodo_sec/">Dodo on Security 🇵🇸 🇺🇦</a> <a href="/1ZRR4H/">Germán Fernández</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/k3dg3/">Kelsey</a> Related Pdf👇
"Comprovante-Mercado-Pago-26-05-2025-.pdf"
❇️Related  #XWorm V5.2
⛔️C2 158.69.41.]120:8000 Samples 
bazaar.abuse.ch/browse/tag/158…
✅AnyRun
app.any.run/tasks/29f57a2f…
1/2
cc <a href="/dodo_sec/">Dodo on Security 🇵🇸 🇺🇦</a> <a href="/1ZRR4H/">Germán Fernández</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/k3dg3/">Kelsey</a>](https://pbs.twimg.com/media/GsGusf8W4AEEdDF.jpg) 
                        
                    
                    
                    
                 
         
        #NetSupport #Rat from Squiblydoo submission Samples bazaar.abuse.ch/browse/tag/45-… Client32.ini MD5 17c5e53b00782ded1b35e7caae4db226 First Submission 2025-07-09 cc ܛܔܔܔܛܔܛܔܛ Mikhail Kasimov Kelsey
 
                        
                    
                    
                    
                 
         
         
        We're hiring on our Threat Research team at Proofpoint! If you enjoy making threat actor's lives more difficult (and you want to work with me and lots of other smart people) apply below! 🤓 proofpoint.wd5.myworkdayjobs.com/en-US/Proofpoi…
 
         
         
                         
                         
                        ![JAMESWT (@jameswt_wt) on Twitter photo Update
#booking  #clickfix #asyncrat
from
https://grupo-positivo.]com/GUP.zip
https://pastebin.]com/raw/XuBRH7G6
Samples
bazaar.abuse.ch/browse/tag/gru…
Ip Related
bazaar.abuse.ch/browse/tag/185…
AnyRun
app.any.run/tasks/d5a7b492…
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/k3dg3/">Kelsey</a> Update
#booking  #clickfix #asyncrat
from
https://grupo-positivo.]com/GUP.zip
https://pastebin.]com/raw/XuBRH7G6
Samples
bazaar.abuse.ch/browse/tag/gru…
Ip Related
bazaar.abuse.ch/browse/tag/185…
AnyRun
app.any.run/tasks/d5a7b492…
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/k3dg3/">Kelsey</a>](https://pbs.twimg.com/media/Gps9UNQXoAACLAL.jpg) 
                        ![JAMESWT (@jameswt_wt) on Twitter photo #booking #clickfix #fakecaptcha
👇
booking.partner-id897123.]com/sign-in?op_token=zXj81EgVvYXV0aCKyAQoUNlo
👇
⛔️80.64.18.]173/nhf7/knfl.exe
Sample
bazaar.abuse.ch/browse/tag/80-…
AnyRun
app.any.run/tasks/5972a8c5…
app.any.run/tasks/d9ba419a…
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/k3dg3/">Kelsey</a> #booking #clickfix #fakecaptcha
👇
booking.partner-id897123.]com/sign-in?op_token=zXj81EgVvYXV0aCKyAQoUNlo
👇
⛔️80.64.18.]173/nhf7/knfl.exe
Sample
bazaar.abuse.ch/browse/tag/80-…
AnyRun
app.any.run/tasks/5972a8c5…
app.any.run/tasks/d9ba419a…
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/k3dg3/">Kelsey</a>](https://pbs.twimg.com/media/Gp4KGhLWwAABhBT.jpg) 
                        ![JAMESWT (@jameswt_wt) on Twitter photo #booking #clickfix #fakecaptcha 
👇
1nspiricity.]com
pather-cancels.]com
room-id039054.]com
👇
ggetsvverif.]com
👇
80.64.18.]173/nhf7/555.exe
Sample bazaar.abuse.ch/browse/tag/80-…
AnyRun 
app.any.run/tasks/c5de5d98…
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/k3dg3/">Kelsey</a> #booking #clickfix #fakecaptcha 
👇
1nspiricity.]com
pather-cancels.]com
room-id039054.]com
👇
ggetsvverif.]com
👇
80.64.18.]173/nhf7/555.exe
Sample bazaar.abuse.ch/browse/tag/80-…
AnyRun 
app.any.run/tasks/c5de5d98…
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/k3dg3/">Kelsey</a>](https://pbs.twimg.com/media/GqTxyWdW8AAY1fv.jpg) 
                        ![JAMESWT (@jameswt_wt) on Twitter photo #netsupport #rat 
GatewayAddress=summer25hot.]org:443
88.218.93[.]71
Main Sample from <a href="/abuse_ch/">abuse.ch</a> 
👇👇👇
bazaar.abuse.ch/browse/tag/sum…
Client32.ini
dabe4273412d4d8ae67e8bc1786b3eac
⚠️First Sub 2025-07-07
LIC
7215675bdba98bd30c8e89aafba519de
⚠️First Sub 2025-06-19
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/k3dg3/">Kelsey</a> #netsupport #rat 
GatewayAddress=summer25hot.]org:443
88.218.93[.]71
Main Sample from <a href="/abuse_ch/">abuse.ch</a> 
👇👇👇
bazaar.abuse.ch/browse/tag/sum…
Client32.ini
dabe4273412d4d8ae67e8bc1786b3eac
⚠️First Sub 2025-07-07
LIC
7215675bdba98bd30c8e89aafba519de
⚠️First Sub 2025-06-19
cc <a href="/500mk500/">Mikhail Kasimov</a> <a href="/k3dg3/">Kelsey</a>](https://pbs.twimg.com/media/GvQGZ2WXgAAC3cA.jpg)