Elektrine lite

← Feed

James_inthe_box

james_inthe_box@infosec.exchange

<p><a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="tag">#<span>malware</span></a></p>

Posts

  • Post #4395725

    In light of recent LLM&amp;#39;s breaking out of their guardrails and doing damage, I felt compelled to write this. https://gist.github.com/silence-is-best/e8fe274d219fc509ed950286deeae502

  • Post #4395724

    An interesting development with #PureLogStealer ....seen this twice now where the Edge flag is invalid: https://app.any.run/tasks/992252ed-c867-4ad9-8b3f-f53c9ca8451b

  • Post #4395723

    PSA: If you&amp;#39;re seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure. 1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  • Post #4395722

    Some 2 day old #valleyrat https://app.any.run/tasks/7a1480fa-e0fc-4e13-ae1a-535cf1077b6d

  • Post #4360847

    A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2&#39;s, hashes, and email exfil addresses: https://gist.github.com/silence-is-best/48b613e82bf64f1fd8b9a231ccdd590b #retrohunt

  • Post #4278147

    Handful of IOC&#39;s for those .js #purelogs #stealer #malspams: https://app.any.run/tasks/43e561e4-707a-4189-8b4c-d4795b2451a6 Exfil port is 4449 Calls hidden Edge Calls hidden Chrome

  • Post #4244341

    #xloader &#39;s (c6713b3c5ba4da5044d96463cae74227a6a898abb051a5f75ab7b508eb20f7e1) choice of which executable to inject into continues to fascinate me...

  • Post #3964188

    #clickfix to #vidar (among other things) via: http:// www\.apcconstruction\.com/ https://app.any.run/tasks/4599dbb0-1041-43f3-b127-a42cfc7ca60e

  • Post #3863642

    Got tired of mucking with these miserable #screenconnect msi&#39;s so here&#39;s a #suricata rule to catch the initial check via sni: https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144 https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294 cc @da_667@infosec.exchange

  • Post #3859116

    #remcos hta and payload in an #opendir at: http://157.254.223\.141/25/

  • Post #3673161

    Some fresh #raton https://app.any.run/tasks/d020658f-dbca-4a1c-bfec-557db23a332d C:\Users\Cristian\Desktop\NewRaton\DONOTDELETE\Commands.pdb

  • Post #3656827

    #medusahvnc in a js -&gt; autoit: https://app.any.run/tasks/86ddc895-ed72-4eae-8c9c-f1e7b81abaf9

  • Post #3538803

    Fresh #purerat : https://app.any.run/tasks/4bd07f35-3a29-477a-8e2b-7e4d31182cd7 cc @da_667@infosec.exchange

  • Post #3537611

    From #clickfix -&gt; #vidar https://app.any.run/tasks/dac83ca5-fa36-4478-8332-2dbce48c6dbc

  • Post #1851397

    This meets my expectations: https://www.thatprivacyguy.com/blog/anthropic-spyware/

  • Post #1851396

    #unknown panel associated with: bf777e4dee6918d2373ba83433b4a7530d6e69465a1b6107ef4fd43f4ea60ec4

  • Post #1851395

    #reverseloader payloads at: http://66.179.248\.120/img/ #remcos c2: 23.95.62\.25:7070

  • Post #1851394

    #Cyberchef down: https://downforeveryoneorjustme.com/cyberchef.gchq.gov.uk

  • Post #1851392

    Much hatred for the latest #Wireshark

  • Post #1851391

    #nanocore......#ransomware ..? https://app.any.run/tasks/0f06cf0b-8417-4e7d-83db-0fd384472772 No files actually encrypted though 🤔

  • Post #1851390

    An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses: https://gist.github.com/silence-is-best/bc95a949f272f8c5487d057bbd74d14f #retrohunt