James_inthe_box
james_inthe_box@infosec.exchange
<p><a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="tag">#<span>malware</span></a></p>
Posts
-
Post #4395725
In light of recent LLM&#39;s breaking out of their guardrails and doing damage, I felt compelled to write this. https://gist.github.com/silence-is-best/e8fe274d219fc509ed950286deeae502
-
Post #4395724
An interesting development with #PureLogStealer ....seen this twice now where the Edge flag is invalid: https://app.any.run/tasks/992252ed-c867-4ad9-8b3f-f53c9ca8451b
-
Post #4395723
PSA: If you&#39;re seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure. 1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b
-
Post #4395722
Some 2 day old #valleyrat https://app.any.run/tasks/7a1480fa-e0fc-4e13-ae1a-535cf1077b6d
-
Post #4360847
A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses: https://gist.github.com/silence-is-best/48b613e82bf64f1fd8b9a231ccdd590b #retrohunt
-
Post #4278147
Handful of IOC's for those .js #purelogs #stealer #malspams: https://app.any.run/tasks/43e561e4-707a-4189-8b4c-d4795b2451a6 Exfil port is 4449 Calls hidden Edge Calls hidden Chrome
-
Post #4244341
#xloader 's (c6713b3c5ba4da5044d96463cae74227a6a898abb051a5f75ab7b508eb20f7e1) choice of which executable to inject into continues to fascinate me...
-
Post #3964188
#clickfix to #vidar (among other things) via: http:// www\.apcconstruction\.com/ https://app.any.run/tasks/4599dbb0-1041-43f3-b127-a42cfc7ca60e
-
Post #3863642
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni: https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144 https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294 cc @da_667@infosec.exchange
-
Post #3859116
#remcos hta and payload in an #opendir at: http://157.254.223\.141/25/
-
Post #3673161
Some fresh #raton https://app.any.run/tasks/d020658f-dbca-4a1c-bfec-557db23a332d C:\Users\Cristian\Desktop\NewRaton\DONOTDELETE\Commands.pdb
-
Post #3656827
#medusahvnc in a js -> autoit: https://app.any.run/tasks/86ddc895-ed72-4eae-8c9c-f1e7b81abaf9
-
Post #3538803
Fresh #purerat : https://app.any.run/tasks/4bd07f35-3a29-477a-8e2b-7e4d31182cd7 cc @da_667@infosec.exchange
-
Post #3537611
From #clickfix -> #vidar https://app.any.run/tasks/dac83ca5-fa36-4478-8332-2dbce48c6dbc
-
Post #1851397
This meets my expectations: https://www.thatprivacyguy.com/blog/anthropic-spyware/
-
Post #1851396
#unknown panel associated with: bf777e4dee6918d2373ba83433b4a7530d6e69465a1b6107ef4fd43f4ea60ec4
-
Post #1851395
#reverseloader payloads at: http://66.179.248\.120/img/ #remcos c2: 23.95.62\.25:7070
-
Post #1851394
#Cyberchef down: https://downforeveryoneorjustme.com/cyberchef.gchq.gov.uk
-
Post #1851392
Much hatred for the latest #Wireshark
-
Post #1851391
#nanocore......#ransomware ..? https://app.any.run/tasks/0f06cf0b-8417-4e7d-83db-0fd384472772 No files actually encrypted though 🤔
-
Post #1851390
An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses: https://gist.github.com/silence-is-best/bc95a949f272f8c5487d057bbd74d14f #retrohunt