#iocs

3 posts · Last used 14d

Replying to
🚨 #Wazza phishkit routing flow: 1️⃣ *[.]boegl-krysl[.]eu — unique wildcard landing. 2️⃣ /api/wazza-config — checks whether the hostname belongs to an active campaign. 3️⃣ beacon-surge-sync[...]workers[.]dev — issues a client marker to correlate the visit. 4️⃣ /api/mint-token — creates a short-lived signed session token. 5️⃣ check[.]boegl-krysl[.]eu — validates the token and browser telemetry, filters unwanted traffic. 6️⃣ boegl-krysl[.]eu/r ➡️️ /meline — after the anti-bot check, the victim is sent through two intermediate redirect endpoints to the final Adobe-themed Device Code phishing landing page. 🔍 Pivot from #IOCs and subscribe to query updates to proactively track evolving activity: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=wazza_phishkit&utm_content=linktotilookup&utm_term=230926#%7B%22query%22:%22threatName:%5C%22wazza%5C%22%22,%22dateRange%22:90%7D
0
0
0
0
🚨 𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿 𝗖𝟮 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝗖𝗮𝘂𝗴𝗵𝘁 𝗼𝗻 𝗮 𝗟𝗶𝘃𝗲 𝗦𝘆𝘀𝘁𝗲𝗺. Interactive analysis let us capture what static detonation misses ⚠️ 𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱 𝘁𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴: 𝗚𝗲𝗿𝗺𝗮𝗻𝘆 𝗮𝗻𝗱 𝗨𝗞 ❗️ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT ➡️ exo.exe dropper ➡️ Lenovo FnHotkeyUtility.exe ➡️ spkvol.dll sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT. 🔥 The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory execution, encrypted C2, and active data exfiltration. 1️⃣ we.exe connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands hidden in HTML comments and a spoofed porsche[.]com Host header. 2️⃣ exo.exe unpacks to C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo binary, sideloads spkvol.dll, and delivers a fileless overlord-client Go agent. 📌 OVERLORD connects to lord[.]kirkdridebridge[.]com:5173 over mTLS-encrypted C2. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration. Observed capabilities include remote access, HVNC, keylogging, audio recording, SOCKS proxying, file management, browser/messenger/wallet data theft, and Solana drainer activity. 👨‍💻 See the full execution chain and collect #IOCs: https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoservice&utm_term=220726 ⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoenterpriselanding&utm_term=220726#cybersecurity #infosec
1
1
0
0
You've seen all posts