Elektrine lite

โ† Feed

@anyrun_app@infosec.exchange

2026-07-22 14:32 UTC

๐ŸŽฏ IOCs and behavioral patterns: Python RAT (Stage 1): C2: live.rnsn[.]live โ†’ 69.169.111[.]81, TCP 8585 HTTP request markers: GET /International, X-Secret: 12345, Host: www.porsche[.]com, Referer: /|1.1.3 HTTP response decoy markers: Fullscreen Spinner + commands encoded in comment strings OVERLORD RAT (Stage 2): C2: lord.kirkdridebridge[.]com โ†’ 163.245.218[.]93, TCP 5173, mTLSv1.3 channel encryption Host artifacts: C:\Users\Public\Windows\win32\we.exe โ€ฆ\run.vbs โ€ฆ\win6\exo.exe .cmd C:\ProgramData\sysid.txt (we.exe bot UUID) C:\ProgramData\DeepSkyBlueIndianRed\* โ†’ FnHotkeyUtility.exe, spkvol.dll, ludp.dll, msvcp140.dll, vcruntime140*.dll dropped executables Registry: HKCU...\Run: SkypeUpd=โ€ฆ\win32\we.exe HKCU...\Run: Winrarservice=โ€ฆ\win32\run.vbs Mutexes: Global\Overlord-1_oVC9y33fSmT7DVUv0HJn9Y (ForestGreenLightSlateGray object) Inno Setup cmdline password: f1846950-ca2f-4f9b-bd08-4807e431faa9 SHA256: 38cec7299bcbcc334633c87de5ed0d8355df8c73fadd26a8b5ca3862c2ea4357 (we.exe) 6805a1cb9b26b629f94aa3cf062e78eb4a5d259f459c0d8ca5a43cc08b16154b (client1.1.3.pyc) 7f53b7a21ba1418f56afac2f5f9db18bcca48d0c9ab7c3bee15a01db57d5fe5c (exo.exe) 9ab2f85ab539cea0f868c0b2a5219c3a8ccfef5365d74cc2cd455cb06d243f65 (upd.exe) 31c97b6e93112cae7bfce17d5979ccd513111b74165fc6ef471a9f8c821ae879 (spkvol.dll) ๐Ÿ“ MITRE ATT&CK: T1059 โ€” Command and Scripting Interpreter T1105 โ€” Ingress Tool Transfer T1547.001 โ€” Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1027 โ€” Obfuscated Files or Information T1574.002 โ€” Hijack Execution Flow: DLL Side-Loading T1113 โ€” Screen Capture T1123 โ€” Audio Capture T1056.001 โ€” Input Capture: Keylogging T1041 โ€” Exfiltration Over C2 Channel

Replies (0)

No replies.