tobersotski
@tobersotski
Malware Analyst and Reverse Engineer
ID: 1933443834551119872
13-06-2025 08:39:03
7 Tweet
13 Followers
23 Following
HTA file deobfuscation from the "fake DMCA report" phishing campaign. Key features shown in the screenshots John Hammond vx-underground ShadowOpCode x.com/_JohnHammond/s…
⚠️ALERT⚠️ there is an OPEN webshell on hxxps://boldcleaningsolutionsatl[.]com/ NEW domains: boldcompanions[.]com boldinnovationspetcare[.]com Cert AgID Gianni Amato JAMESWT vx-underground a lot of malwere inside 😋 cc: tobersotski x.com/AgidCert/statu…
Caminho Loader Malware Analysis #CaminhoLoader #malware #ThreatIntel Szabolcs Schmidt ShadowOpCode x.com/smica83/status…
Phishing "Pedaggio non pagato" autostde[.]com domain created today (2025-11-19) Cert AgID JAMESWT illegalFawn Gianni Amato Andrea (Drego) Draghetti 👨🏻💻 🎣 Simplicio Sam L.
🚨ALERT🚨 Malspam campaign against Sistema Sanitario Regionale Liguria Regione Liguria 📤Sender likely spoofed (🇺🇿 based server) 📥Receiver: Institutional PEC mail > rar > jse > powershell with AES encrypted ps1 > aspnet_compiler.exe (BLACKHAWK > Agent Tesla) IoC and sample below👇