
ExecuteMalware
@executemalware
#malware hunter & analyst.
Opinions are my own.
ID: 743883460587167744
17-06-2016 19:10:12
16,16K Tweet
26,26K Takipçi
191 Takip Edilen


Related Pdf👇 "Comprovante-Mercado-Pago-26-05-2025-.pdf" ❇️Related #XWorm V5.2 ⛔️C2 158.69.41.]120:8000 Samples bazaar.abuse.ch/browse/tag/158… ✅AnyRun app.any.run/tasks/29f57a2f… 1/2 cc Dodo on Security 🇵🇸 🇺🇦 Germán Fernández ܛܔܔܔܛܔܛܔܛ Mikhail Kasimov Kelsey
![JAMESWT (@jameswt_wt) on Twitter photo Related Pdf👇
"Comprovante-Mercado-Pago-26-05-2025-.pdf"
❇️Related #XWorm V5.2
⛔️C2 158.69.41.]120:8000 Samples
bazaar.abuse.ch/browse/tag/158…
✅AnyRun
app.any.run/tasks/29f57a2f…
1/2
cc <a href="/dodo_sec/">Dodo on Security 🇵🇸 🇺🇦</a> <a href="/1ZRR4H/">Germán Fernández</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/k3dg3/">Kelsey</a> Related Pdf👇
"Comprovante-Mercado-Pago-26-05-2025-.pdf"
❇️Related #XWorm V5.2
⛔️C2 158.69.41.]120:8000 Samples
bazaar.abuse.ch/browse/tag/158…
✅AnyRun
app.any.run/tasks/29f57a2f…
1/2
cc <a href="/dodo_sec/">Dodo on Security 🇵🇸 🇺🇦</a> <a href="/1ZRR4H/">Germán Fernández</a> <a href="/skocherhan/">ܛܔܔܔܛܔܛܔܛ</a> <a href="/500mk500/">Mikhail Kasimov</a> <a href="/k3dg3/">Kelsey</a>](https://pbs.twimg.com/media/GsGusf8W4AEEdDF.jpg)


#Bumblebee from nir-soft[.]org (x.com/1ZRR4H/status/…). Botnet: grp0005 C2: 188.40.187.152 (although not flagged by any AV, the IP has been linked to Bumblebee campaigns since approximately April 2024). Bumblebee has been used in ransomware attacks. MalwareHunterTeam
![Germán Fernández (@1zrr4h) on Twitter photo #Bumblebee from nir-soft[.]org (x.com/1ZRR4H/status/…).
Botnet: grp0005
C2: 188.40.187.152 (although not flagged by any AV, the IP has been linked to Bumblebee campaigns since approximately April 2024).
Bumblebee has been used in ransomware attacks.
<a href="/malwrhunterteam/">MalwareHunterTeam</a> #Bumblebee from nir-soft[.]org (x.com/1ZRR4H/status/…).
Botnet: grp0005
C2: 188.40.187.152 (although not flagged by any AV, the IP has been linked to Bumblebee campaigns since approximately April 2024).
Bumblebee has been used in ransomware attacks.
<a href="/malwrhunterteam/">MalwareHunterTeam</a>](https://pbs.twimg.com/media/GsI_CctWUAAZaDV.jpg)






Germany doxxes Conti ransomware and TrickBot ring leader - Sergiu Gatlan bleepingcomputer.com/news/security/… bleepingcomputer.com/news/security/…









