ShadowOpCode's profile picture. Malware analyst & reverse engineer 🧠
Threat intel on stealers, RATs, live campaigns 🕵️
Technical analysis. No buzzwords.
📍DM open for research collabs

ShadowOpCode

@ShadowOpCode

Malware analyst & reverse engineer 🧠 Threat intel on stealers, RATs, live campaigns 🕵️ Technical analysis. No buzzwords. 📍DM open for research collabs

고정된 트윗

🚨 New #JavaStealer “MaksStealer” uncovered! Fully in-memory, FUD, DES–Blowfish runtime decryption, WebSockets on 4025/4028/6662. Author “Max, 17yo” left his signature in the payload 🤯 Full report & IoCs 👉 github.com/ShadowOpCode/M… #infosec #malware #ThreatIntel @malwrhunterteam

ShadowOpCode's tweet image. 🚨 New #JavaStealer “MaksStealer” uncovered!
Fully in-memory, FUD, DES–Blowfish runtime decryption, WebSockets on 4025/4028/6662.
Author “Max, 17yo” left his signature in the payload 🤯
Full report & IoCs 👉 github.com/ShadowOpCode/M…
#infosec #malware #ThreatIntel @malwrhunterteam

#phishing @NetflixIT Sender: t.eam.2s.upport@yandex[.]ru hxxps://fuviya.techbazaar101[.]com/xisawife/fa/nabobo/minogi/index.php?rpclk= hxxps://theenchantedtreasurehunter[.]io/c/bXqCkBejK25w? hxxps://casafuze[.]com/l/Gd02TpQQvj2JT0YzB5R2mP4Uvzlz/payment?token= #ThreatIntelligence

ShadowOpCode's tweet image. #phishing @NetflixIT 
Sender: t.eam.2s.upport@yandex[.]ru
hxxps://fuviya.techbazaar101[.]com/xisawife/fa/nabobo/minogi/index.php?rpclk=
hxxps://theenchantedtreasurehunter[.]io/c/bXqCkBejK25w?
hxxps://casafuze[.]com/l/Gd02TpQQvj2JT0YzB5R2mP4Uvzlz/payment?token=
#ThreatIntelligence
ShadowOpCode's tweet image. #phishing @NetflixIT 
Sender: t.eam.2s.upport@yandex[.]ru
hxxps://fuviya.techbazaar101[.]com/xisawife/fa/nabobo/minogi/index.php?rpclk=
hxxps://theenchantedtreasurehunter[.]io/c/bXqCkBejK25w?
hxxps://casafuze[.]com/l/Gd02TpQQvj2JT0YzB5R2mP4Uvzlz/payment?token=
#ThreatIntelligence
ShadowOpCode's tweet image. #phishing @NetflixIT 
Sender: t.eam.2s.upport@yandex[.]ru
hxxps://fuviya.techbazaar101[.]com/xisawife/fa/nabobo/minogi/index.php?rpclk=
hxxps://theenchantedtreasurehunter[.]io/c/bXqCkBejK25w?
hxxps://casafuze[.]com/l/Gd02TpQQvj2JT0YzB5R2mP4Uvzlz/payment?token=
#ThreatIntelligence
ShadowOpCode's tweet image. #phishing @NetflixIT 
Sender: t.eam.2s.upport@yandex[.]ru
hxxps://fuviya.techbazaar101[.]com/xisawife/fa/nabobo/minogi/index.php?rpclk=
hxxps://theenchantedtreasurehunter[.]io/c/bXqCkBejK25w?
hxxps://casafuze[.]com/l/Gd02TpQQvj2JT0YzB5R2mP4Uvzlz/payment?token=
#ThreatIntelligence

Thanks everyone for the 600 followers! We're pushing together the boundaries of malware analysis 🔥

ShadowOpCode's tweet image. Thanks everyone for the 600 followers!
We're pushing together the boundaries of malware analysis 🔥

Threat Actors are delivering NetSupportManager RAT packed with "ChatGPT Installer.exe" as a decoy Dropper > (ChanGPT Install.exe, Setup.exe > msiexec.exe > NetSupport) @anyrun_app analysis here: app.any.run/tasks/d4a4a29e… Bazaar: bazaar.abuse.ch/sample/d86f647… Thanks @JAMESWT_WT for upload

ShadowOpCode's tweet image. Threat Actors are delivering NetSupportManager RAT packed with "ChatGPT Installer.exe" as a decoy
Dropper > (ChanGPT Install.exe, Setup.exe > msiexec.exe > NetSupport)
@anyrun_app analysis here: app.any.run/tasks/d4a4a29e…
Bazaar: bazaar.abuse.ch/sample/d86f647…
Thanks @JAMESWT_WT for upload
ShadowOpCode's tweet image. Threat Actors are delivering NetSupportManager RAT packed with "ChatGPT Installer.exe" as a decoy
Dropper > (ChanGPT Install.exe, Setup.exe > msiexec.exe > NetSupport)
@anyrun_app analysis here: app.any.run/tasks/d4a4a29e…
Bazaar: bazaar.abuse.ch/sample/d86f647…
Thanks @JAMESWT_WT for upload
ShadowOpCode's tweet image. Threat Actors are delivering NetSupportManager RAT packed with "ChatGPT Installer.exe" as a decoy
Dropper > (ChanGPT Install.exe, Setup.exe > msiexec.exe > NetSupport)
@anyrun_app analysis here: app.any.run/tasks/d4a4a29e…
Bazaar: bazaar.abuse.ch/sample/d86f647…
Thanks @JAMESWT_WT for upload

📧"Re : Request for Quotation-PO NO 151001896902" 📦Delivery #PhantomStealer 📤exfil via SMTP mail[.]novochrom[.]us:587 phamton@novochrom[.]us phamton2@novochrom[.]us sample: bazaar.abuse.ch/browse/tag/nov…

ShadowOpCode's tweet image. 📧"Re : Request for Quotation-PO NO 151001896902"
📦Delivery #PhantomStealer
📤exfil via SMTP
mail[.]novochrom[.]us:587
phamton@novochrom[.]us
phamton2@novochrom[.]us
sample: bazaar.abuse.ch/browse/tag/nov…
ShadowOpCode's tweet image. 📧"Re : Request for Quotation-PO NO 151001896902"
📦Delivery #PhantomStealer
📤exfil via SMTP
mail[.]novochrom[.]us:587
phamton@novochrom[.]us
phamton2@novochrom[.]us
sample: bazaar.abuse.ch/browse/tag/nov…
ShadowOpCode's tweet image. 📧"Re : Request for Quotation-PO NO 151001896902"
📦Delivery #PhantomStealer
📤exfil via SMTP
mail[.]novochrom[.]us:587
phamton@novochrom[.]us
phamton2@novochrom[.]us
sample: bazaar.abuse.ch/browse/tag/nov…
ShadowOpCode's tweet image. 📧"Re : Request for Quotation-PO NO 151001896902"
📦Delivery #PhantomStealer
📤exfil via SMTP
mail[.]novochrom[.]us:587
phamton@novochrom[.]us
phamton2@novochrom[.]us
sample: bazaar.abuse.ch/browse/tag/nov…

United States 트렌드

Loading...

Something went wrong.


Something went wrong.