@james_inthe_box@infosec.exchange
Post #3859116
2026-07-16 12:32 UTC
#remcos hta and payload in an #opendir at:
http://157.254.223\.141/25/
Replies (1)
-
@netresec@infosec.exchange 2026-07-16 13:05
@james_inthe_box@infosec.exchange C2 server seems to be on 141.98.10.150:14642 curl -s --data-binary @260716-pq5hpadv4p-behavioral1.pcapng https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]' ["141.98.10.150:14642","MALWARE protocol detected: TLS, Remcos"]