Remote
#cybersecurity - Fighting #malware and #botnets
0
Followers
0
Following
6
Posts
Joined November 11, 2022
URL:
Twitter:
LinkedIn:
Posts
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰
📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download
Final payload is hosted on MediaFire 🔥 free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️
User-Agent: Embarcadero URI Client/1.0
🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀
📡 Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28
🌐 Payloads URLs:
https://urlhaus.abuse.ch/browse/tag/Grandoreiro/
📄 Malware samples:
https://bazaar.abuse.ch/browse/signature/Grandoreiro/
🦊 Relevant IOCs are available on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.grandoreiro/
Open post
📢 SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy.
To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. Accounts generating unusually high query volumes may be temporarily limited for up to 72 hours.
Repeated or persistent abuse may result in longer-term restrictions on API access.
0
1
0
1
Open post
It's here!! The @abuse_ch@ioc.exchange #CommunityHub is LIVE 🔥🔥🔥
Now you can access a LIVE view of:
➡️ Total community contributions
➡️ Top 10 Leaderboards
➡️ Monthly contribution trends
....and a place to track your own impact!
Our community is bigger than any one platform. It's a global network of researchers working together to disrupt malware, botnets, and cybercrime.
And every contributor deserves recognition 💛
Head to the Community and claim your profile 👉 abuse.ch/community
1
0
0
0
Open post
Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️
The malware sample:
1️⃣ Obtains the DNS A record of ns2.theendlessweb .com
2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site
3️⃣ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record
4️⃣ Malware executes the PS command and obtains second stage from global-research .space/adv13.php
global-research .space has been registered almost a year ago, which suggests that this campaign is already running since quite a while 📅 It also returns a fake HTTP 404, which indicates that the payload delivery is restricted to a handful targets 🎯
IOCs 📡
%ProgramData%\Microsoft\HTML Help\hhcolreg.dat
%APPDATA%\Microsoft\HTML Help\hh.dat
https://threatfox.abuse.ch/ioc/1855885/
https://threatfox.abuse.ch/ioc/1855883/
Malware sample 📄
https://bazaar.abuse.ch/sample/32a962439ec0fb5559e494fe1ea6be039815d3c4c1cceb95b16dc123e5abde61/
8
2
3
0
Open post
We’ve identified an interesting malware family 🔍, which we’ve named #GrokPy due to its use of a Grok LLM model 🤖 to solve and subsequently bypass CAPTCHAs 🔥
The malware gets dropped by #Amadey and:
🪝 collects information about the infected device, such as screen resolution, public IP & location, ram usage and CPU name
💻 attempts to escalate privileges by running as admin or as a scheduled task
7
1
6
0
Open post
We are happy to announce the integration of @kunai_project@infosec.exchange Linux Sandbox on MalwareBazaar 🥳
Sample ELF X86 report ⤵️
https://bazaar.abuse.ch/sample/0d2211b7e92fcc6a9f7c94d4adf8e47f6f97e31dacd3b2ffb6cce3c485fcef26/
13
1
11
0
Remote instance
ioc.exchange
Open on original server