Recently got infected with a really bad malware info stealer. Been combing back looking for the source. I think I may have found it.
PM if you want more info than provided here.
Sanitized Threat Intelligence & IOC Brief: Repackaged Fileless .NET Backdoor
1. File Indicators (Cryptographic Hashes)
Variant A (ZIP Archive Stage)
- File Type: ZIP archive data, deflate compression
- MD5:
c36b33a5370864decda5b0db97972191 - SHA256:
1019517268a2edb2d89729661539233396b3aa524279377ca8228085957d598b
Variant B (RAR Archive Stage)
- File Type: RAR archive data, v4, os: Win32
- MD5:
488cc1a8f44af73bc7f7baa1fafd8fdr - SHA256:
de5d21396908ab452059a3361f76dcb489fb705e44ac55983624a7e5d7bca1d
2. Network Indicators of Compromise (IoCs)
- Inbound Bind Shell / P2P Node: Starts a local server listening for inbound connections on
↗ Original-Artikel auf reddit.com lesenVollständiger Original-BerichtAusführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf reddit.com.
SOCIAL SHARE CARD GENERATOR