
Null Pwner
@nullpwner
Turning random hashes into aha-moments. Coffee fueled. Views mine.
ID: 114604009
http://badbyte.io 16-02-2010 00:54:47
51 Tweet
124 Takipรงi
679 Takip Edilen


๐จ New Odyssey Stealer C2 Panel ๐ฏ hxxp://5.199.166[.]102/login This is the third C2 spin-up in a matter of days. Favicon: 9108dde25ad958b27f6a97d644775dee #Threathunting #Odyssey #Stealer #ThreatIntel MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov
![Null Pwner (@nullpwner) on Twitter photo ๐จ New Odyssey Stealer C2 Panel
๐ฏ hxxp://5.199.166[.]102/login
This is the third C2 spin-up in a matter of days.
Favicon: 9108dde25ad958b27f6a97d644775dee
#Threathunting #Odyssey #Stealer #ThreatIntel
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a> <a href="/500mk500/">Mikhail Kasimov</a> ๐จ New Odyssey Stealer C2 Panel
๐ฏ hxxp://5.199.166[.]102/login
This is the third C2 spin-up in a matter of days.
Favicon: 9108dde25ad958b27f6a97d644775dee
#Threathunting #Odyssey #Stealer #ThreatIntel
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a> <a href="/500mk500/">Mikhail Kasimov</a>](https://pbs.twimg.com/media/Gp0KDNgWUAAdl2Q.jpg)

๐จ More VektorX C2 Panel ๐ฏhxxp://92.119.114[.]111:5173/auth/login - AS211381 ๐ฏ 91.211.249[.]147 ๐ฏ 62.233.53[.]22 ๐งฌHash: e9c154045c3e12a1a16617e0eaede551 @onyphe.io PD for the dev: Work on your logo tracing skills bro, they are therrible ๐ (/assets/fncVEJjF.png)
![Null Pwner (@nullpwner) on Twitter photo ๐จ More VektorX C2 Panel
๐ฏhxxp://92.119.114[.]111:5173/auth/login - AS211381
๐ฏ 91.211.249[.]147
๐ฏ 62.233.53[.]22
๐งฌHash: e9c154045c3e12a1a16617e0eaede551 <a href="/onyphe/">@onyphe.io</a>
PD for the dev: Work on your logo tracing skills bro, they are therrible ๐ (/assets/fncVEJjF.png) ๐จ More VektorX C2 Panel
๐ฏhxxp://92.119.114[.]111:5173/auth/login - AS211381
๐ฏ 91.211.249[.]147
๐ฏ 62.233.53[.]22
๐งฌHash: e9c154045c3e12a1a16617e0eaede551 <a href="/onyphe/">@onyphe.io</a>
PD for the dev: Work on your logo tracing skills bro, they are therrible ๐ (/assets/fncVEJjF.png)](https://pbs.twimg.com/media/Gp5FRaoXoAAznAb.jpg)

๐จ Fresh ClickFix Delivering Pentagon Stealer ๐ฏ hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov DaveTheResearcher ANY.RUN #pentagonstealer #threatintel #threathunt #stealer
![Null Pwner (@nullpwner) on Twitter photo ๐จ Fresh ClickFix Delivering Pentagon Stealer
๐ฏ hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
<a href="/anyrun_app/">ANY.RUN</a>
#pentagonstealer #threatintel #threathunt #stealer ๐จ Fresh ClickFix Delivering Pentagon Stealer
๐ฏ hxxps://zfbezhefbzhbdfbzdufbuzbdf[.]pages[.]dev
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
<a href="/anyrun_app/">ANY.RUN</a>
#pentagonstealer #threatintel #threathunt #stealer](https://pbs.twimg.com/media/GqGD1WiWoAASMSR.png)

๐จ ClickFix - Sennheiser CF Phishing ๐ฏ hxxps://www.sennheiser[.]ad/ MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov DaveTheResearcher #threatintel #clickfix #threathunting #PhishingScam
![Null Pwner (@nullpwner) on Twitter photo ๐จ ClickFix - Sennheiser CF Phishing
๐ฏ hxxps://www.sennheiser[.]ad/
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a>
<a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
#threatintel #clickfix #threathunting #PhishingScam ๐จ ClickFix - Sennheiser CF Phishing
๐ฏ hxxps://www.sennheiser[.]ad/
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a>
<a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>
#threatintel #clickfix #threathunting #PhishingScam](https://pbs.twimg.com/media/GqGMY08WsAAdPPG.jpg)

๐จ ClickFix Delivering XWorm ๐ฏ hxxps://lbkequityexchange[.]com/i.cmd ๐ฏ hxxps://lbkequityexchange[.]com/EQTRN.exe ๐ฏ Prob C2: winservicesconsole[.]duckdns.]org - 45.154.98[.]252 ASN 210558 ๐ป Fake CAPTCHA โ Runs PS script โ Downloads i.cmd โ Deploys XWorm while mimicking a



๐จ Clickfix - Binance Phishing delivering VIDAR ๐ฏ 193.24.123[.]165 ๐ฏ traderai[.]name C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title). VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1 MalwareHunterTeam
![Null Pwner (@nullpwner) on Twitter photo ๐จ Clickfix - Binance Phishing delivering VIDAR
๐ฏ 193.24.123[.]165
๐ฏ traderai[.]name
C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title).
VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1
<a href="/malwrhunterteam/">MalwareHunterTeam</a> ๐จ Clickfix - Binance Phishing delivering VIDAR
๐ฏ 193.24.123[.]165
๐ฏ traderai[.]name
C2: t[.]me/m00f3r, steamcommunity[.]com/profiles/76561199851454339 (couple more IPs in the title).
VT: c3ac276122e6af6459eda55251a70ebf8bb091a620314f18ada33a6259fe10b1
<a href="/malwrhunterteam/">MalwareHunterTeam</a>](https://pbs.twimg.com/media/GqlQF4GXoAASOJ_.jpg)

๐จ Odyssey Stealer C2 Panel ๐ฏ odyssey-st[.]com ๐ฏ 83.222.190[.]214 MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ Mikhail Kasimov DaveTheResearcher
![Null Pwner (@nullpwner) on Twitter photo ๐จ Odyssey Stealer C2 Panel
๐ฏ odyssey-st[.]com
๐ฏ 83.222.190[.]214
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a>
<a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a>
<a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a> ๐จ Odyssey Stealer C2 Panel
๐ฏ odyssey-st[.]com
๐ฏ 83.222.190[.]214
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a>
<a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a>
<a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>](https://pbs.twimg.com/media/GqlSg2NXsAATZaR.png)

๐จ Introducing Mave Stealer C2 Panel: ๐ฏ web.mavedashboard[.]lol ๐ฏ31.57.156[.]135 (AS210538) ๐งฌea8aebfaedd0d287ac10c39a5a3c4de6 @onyphe.io Mave Stealer appears to have been launched on Apr 25. [@]squ4ts๐<๐ :) Any samples? MalwareHunterTeam Dee Who said what? RussianPanda ๐ผ ๐บ๐ฆ
![Null Pwner (@nullpwner) on Twitter photo ๐จ Introducing Mave Stealer C2 Panel:
๐ฏ web.mavedashboard[.]lol
๐ฏ31.57.156[.]135 (AS210538)
๐งฌea8aebfaedd0d287ac10c39a5a3c4de6 <a href="/onyphe/">@onyphe.io</a>
Mave Stealer appears to have been launched on Apr 25.
[@]squ4ts๐<๐ :)
Any samples?
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a> ๐จ Introducing Mave Stealer C2 Panel:
๐ฏ web.mavedashboard[.]lol
๐ฏ31.57.156[.]135 (AS210538)
๐งฌea8aebfaedd0d287ac10c39a5a3c4de6 <a href="/onyphe/">@onyphe.io</a>
Mave Stealer appears to have been launched on Apr 25.
[@]squ4ts๐<๐ :)
Any samples?
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/RussianPanda9xx/">RussianPanda ๐ผ ๐บ๐ฆ</a>](https://pbs.twimg.com/media/Gqsa5ggWcAAFDme.jpg)




๐จ Odyssey Stealer C2 Panel ๐ฏ http[:]//194.26.29[.]217 AS 206728 Rotating infostealer infra. MalwareHunterTeam Dee Who said what? Mikhail Kasimov DaveTheResearcher
![Null Pwner (@nullpwner) on Twitter photo ๐จ Odyssey Stealer C2 Panel
๐ฏ http[:]//194.26.29[.]217 AS 206728
Rotating infostealer infra.
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a> ๐จ Odyssey Stealer C2 Panel
๐ฏ http[:]//194.26.29[.]217 AS 206728
Rotating infostealer infra.
<a href="/malwrhunterteam/">MalwareHunterTeam</a> <a href="/ViriBack/">Dee</a> <a href="/g0njxa/">Who said what?</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/DaveLikesMalwre/">DaveTheResearcher</a>](https://pbs.twimg.com/media/GryNI2GXUAAusyw.png)