#donutloader

5 posts · Last used 4d

Back to Timeline
ANY.RUN @anyrun_app@infosec.exchange · 4d ago
⚠️ Malware activity increased across nearly every major family last week. RATs like #Remcos and #AgentTesla, stealers like #Stealc and #Lumma, and loaders like #DonutLoader all gained momentum. 📌 Trend to watch: activity is accelerating across the threat landscape rather than around a single malware family, pointing to broader attacker activity rather than isolated campaigns. Monitor the malware driving today’s attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=100826&utm_content=linktomtt #cybersecurity #infosec
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Aug 03, 2026
⚠️ While most leading malware families declined last week, #DonutLoader and #AgentTesla continued to grow. 📌 Trend to watch: quieter weeks don't affect every threat equally. Tracking which malware families continue to gain momentum helps SOC teams spot changes in attacker activity early. Monitor the malware driving today’s attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=030826&utm_content=linktomtt #Top10Malware
0
0
0
bomccss @bomccss@infosec.exchange · Jul 31, 2026
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。 ■日時 2026/07/31(金) ■件名 破損した商品をご確認ください ■リンク hxxps://cloudflare.carriernetworks[.]top/?sharingcenterDelivery_Unboxing_Verification.MP4 ■ダウンロードファイル Delivery_Unboxing_Verification_Details[.]zip https://www.virustotal.com/gui/file/307594e042248ad7cc9627e8de385851bd92df452216b1b829077d3a93ac815b https://tria.ge/260731-j1982aywgw/behavioral1 https://app.any.run/tasks/4fbdb57d-0566-438b-9067-70a05a504f69 uxtheme.dll マルウェア #DonutLoader ■通信先 hxxps://bdp.edu[.]vn/pwn/new/pdf.exe https://www.virustotal.com/gui/file/719f689b34f47be8ca105ce8484948474dafde0e106bab599e4a89326070c3d0 hxxps://bdp.edu[.]vn/pwn/new/puredk.txt https://www.virustotal.com/gui/file/554ea9c12cd430c91bede296f437477629b2b26d89cdbe80784f44686696272c ■C2 hxxp[:]//pure26.myftp[.]org:56001 (151.241.154[.]227:56001) なお、以下ではtor-browserがValleyRATと判定されていますが誤判定の可能性があります。 https://tria.ge/260731-j1982aywgw/behavioral1 https://virustotal.com/gui/file/bc33f30d25db4ccf35aeef90d5ee0d7d556c4b8f8a04d13ccac50df89223b6dd/details 引用元: https://x.com/tdatwja/status/2083100203834568782
0
0
0
bomccss @bomccss@infosec.exchange · Jul 30, 2026
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。 ■日時 2026/07/30(木) ■件名 返金をご検討ください ■リンク hxxps[:]//customersrespondedpositively[.]com/Complete_Unboxing_And_Damage_Inspection[.]mp4/views/PqsTVwXyZatii ■ダウンロードファイル Full_Unboxing_Process_Inspection_Record_9862_2026[.]zip -> .exe, AppVIsvSubsystems64.dll, riched32.dat https://www.virustotal.com/gui/file/a50dcea028a1bfcea55f2aa612c3bc0ffe354fd6a938eb5f1df07f676723df26 https://tria.ge/260730-nn32eawgje/behavioral1 マルウェア #DonutLoader ■通信先 hxxp[:]//trump2.1368[.]lol:56001 (15.235.174[.]203:56001) 引用元: https://x.com/tdatwja/status/2082761360321200396
0
0
0
bomccss @bomccss@infosec.exchange · Jul 15, 2026
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。 ■日時 2026/07/15(水) ■件名 税務担当 ■リンク hxxps[:]//download.aces.cc[.]cd/webdav/Notice%20from%20Tax%20Department[.]zip ※既にファイルアクセス不可 ■ファイル Notice from Tax Department[.]zip -> .img -> .exe, netutils.dll https://www.virustotal.com/gui/file/af05c0b7aefa3554b15792bab2ed7460b011d62ae64841541ebc24a33dd103d6/detection https://tria.ge/260715-khdyjsbs41/behavioral1 https://app.any.run/tasks/a024fad2-0700-4bcf-a099-5eba13053e87 マルウェア #DonutLoader ■C2 154.82.93[.]206:8080 引用元: https://x.com/tdatwja/status/2077302997248545238
0
0
0

You've seen all posts