's Avatar

@jamesinthebox

malware

155
Followers
30
Following
30
Posts
17.06.2023
Joined
Posts Following

Latest posts by @jamesinthebox

Preview
Analysis OperaGXSetup.exe (MD5: 331950DC665052789DC9FCB607CC10AF) Malicious activity - Interactive analysis ANY.RUN Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

Malicious @github repo at:

github/.com/charlie...

seen dropped via #xworm on a hijacked @operagxofficial installer

app.any.run/tasks/4be36a...

06.03.2025 17:37 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image Post image

If you'be been dealing with these janky downloaders ("pdfs" if MiTM the TLS), these have been #darkcloud #stealer so far:

app.any.run/tasks/925ce6...

Look for:
vbs file
showip\.net
LoginData
WebData
keyDBPath.db
in the run and

StrFtpServer
DCS V

in the dmp file

05.03.2025 22:34 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Analysis Payment receipt PO 1437 1_ Payment receipt PO #1437 2.exe (MD5: 5A4FC3780CFC0527D12D8BB5134A81F5) Malicious activity - Interactive analysis ANY.RUN Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

Some fresh (and I can't believe I'm typing this) #lokibot:

app.any.run/tasks/054d7a...

c2: http:// touxzw\.ir/fix/five/fre.php

05.03.2025 14:20 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

A csv formatted list of #malspam campaigns that crossed my path in February to include #malware name, c2, hash, subject, and email exfil addresses:

gist.github.com/silence-is-b...

#retrohunt

03.03.2025 20:31 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Hrmm....thinking a whitehat has taken control ;)

26.02.2025 15:19 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

Huh...first time I've seen threat actor's using @ThinkstCanary :

https:// assistance-newton-adam-indiana.trycloudflare\.com

26.02.2025 15:17 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image Post image

Badness at:

144.91.79.54/10022025/

app.any.run/tasks/70b515...

Ultimately #darkcloud (the txt file); c2 juguly\.shop

26.02.2025 15:03 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Ultimately #asyncrat and #hvnc:

mathewhvnc.twilightparadox\.com
kjhvnc.duckdns\.org
rtasyn.duckdns\.org
asyncyam.twilightparadox\.com

20.02.2025 16:13 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

If you're not blocking trycloudflare\.com at the perimeter, now's the time: #opendir 's:

https:// em-ash-announcements-alpha.trycloudflare\.com/1DSAHJKSA/ ->
https:// did-efficiency-than-lenses.trycloudflare\.com ->
https:// reached-theoretical-regular-impact\.trycloudflare.com

20.02.2025 14:34 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

#phishing #opendir:

dmc.otarvesq/.com/POST/

17.02.2025 17:51 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

http:// account\.empireaccelerate.com:9200/empire_account/account/account.do ๐Ÿคจ

12.02.2025 22:10 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

When the threat actor REALLY wants it to run... #venomrat c2:

176.65.142.172:4449

07.02.2025 14:23 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image Post image

A csv formatted list of #malspam campaigns that crossed my path in January to include subjects, hashes, c2's, #malware type, and email exfil addresses:

gist.github.com/silence-is-b...

#retrohunt

03.02.2025 16:36 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

When #windows decides it's had enough of you blocking it's update/telemetry processes (going to wd-prod-cp-us-west-2-fe\.westus.cloudapp.azure.com) and just yeats out the lookup over #netbios ๐Ÿคท

02.02.2025 12:50 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

A fairly sizable distributed port scan (all source port 19000) about 30 minutes ago; raw logs and sources here:

gist.github.com/silence-is-b...

24.01.2025 17:16 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

If you're....you know...bored...

app.any.run/tasks/365f89...

23.01.2025 20:30 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

#webshell #opendir #netsupport #rat at:

https:// appointedtimeagriculture\.com/wp-includes/blocks/post-content/

GatewayAddress=95.179.158.213:443
RADIUSSecret=dgAAAPpMkI7ke494fKEQRUoablcA

22.01.2025 22:20 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

As much as I was excited about #telegram cooperating with LE...I haven't noticed much of a change:

app.any.run/tasks/694cb9...

16.01.2025 14:34 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Big zips appear to be a #python #stealer

09.01.2025 15:03 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

#opendir at:

https:// superior-somalia-bs-leisure.trycloudflare\.com ->
http:// jsnybsafva\.biz:8030

09.01.2025 14:52 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Same

08.01.2025 21:11 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

A late (due to holiday vacation) and sparse csv formatted list of #malspam campaigns that crossed my path in December to include subjects, #malware, hashes, c2's, and email exfil addresses:

gist.github.com/silence-is-b...

#retrohunt

06.01.2025 17:25 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Additional details:

10.12.2024 17:11 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Analysis MA-DS-2024-03 URGENT.exe (MD5: B5C0BC1CA5223C4B18328235497A2EF6) Malicious activity - Interactive analysis ANY.RUN Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

An #expiro (believe it or not) dropping #xloader

app.any.run/tasks/43f807...

fake c2 and campaign:
http ://www.sunnyz.store/px6j

10.12.2024 17:08 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

But it's not though. Not really.

05.12.2024 20:33 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

Interesting use of @Formstack as an interactive landing page for a #ms365 #phish:

https:// bilykfilms .com/m/

is the site.

05.12.2024 18:03 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

An unsurprisingly light csv formatted list of #malspam campaigns that crossed my path in November to included subjects, #malware type, hashes, c2's and email exfil addresses:

gist.github.com/silence-is-b...

#retrohunt #infosec #cybersecurity

02.12.2024 16:23 ๐Ÿ‘ 9 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Excellent...thanks!

28.11.2024 14:11 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

A curious js file...
app.any.run/tasks/112848...

27.11.2024 22:48 ๐Ÿ‘ 7 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

...nice place you got here...

14.11.2024 20:48 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0