9630
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
It has cap. I looked at at it but it seems that the scrambled js is the submission so the rest of the traffic does not include that
Читать полностью…
Hello @nulluser_404, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
If you go to the content tab, you could see obfuscated codes
Читать полностью…
Try this: https://web.archive.org/web/20240609152549/https://four.startperfectsolutions.com/scripts/sold.js
Читать полностью…
hxxps://four.startperfectsolutions.com/scripts/sold.js anyone can help me get this sample ?
Читать полностью…
You can use an app on your Android to scan for the camera once your device is connected to the same WiFi network
Читать полностью…
And then you can locate the IP address of the camera and log into it from a web browser
Читать полностью…
If I’m connected to the WiFi of that place can I get access to it
Читать полностью…
Please I’m not doing anything illegal I want to help my friend
Читать полностью…
Hi guys,
Does anyone know anything about dAn0n ransomware? TTP?
does the anyrun sample has a PCAP? you might be able to extract out the file from the PCAP
Читать полностью…
I didn't pivot off the communicating or referrer files/URLs, those may also yield something
Читать полностью…
I think VT only has the response body, not the actual file
Читать полностью…
They way back machine has a bunch of snapshots. Vt didn’t return any for some reason.
Читать полностью…
While I was on there I am getting server error fml
Читать полностью…
it is dead. only see a mention on anyrun but they dont offer a sample
Читать полностью…
User capekep has 1/3 warnings; be careful!
Reason:
stay on topic
You can only get access to the cameras if you have remote access to a Windows machine on the same network as the cameras
Читать полностью…
This ransomware is from the end of April of this year, it is relatively new and I can't find much information about it
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: MRshinba
User ID: 5027212289
Reason: scam
Only unique artefact is the link to session chat for connecting with their operator rest the extension is used as a "code" to initiate conversation with the operator for identifying the affected victim
Читать полностью…