\_(ʘ_ʘ)_/
3.6K posts


#RMM_NAble
FolhadeOr-amentoPDF.exe
MD5: 4cec112404691e2fad7b323d467e15df
Subject: Folha Orçamento PDF
s://www.dropbox.com/scl/fi/rls1zkdy4fvzv9wr30kkz/FolhadeOr-amentoPDF.exe?rlkey=f57ygwk5v2cigwpsed47l7orw&st=yj64nrqk&dl=1
Nederlands

#RMM_NAble
Or-amento-Cota-o.exe
9dfe5f9974adc95a06c24d51715f1404
Subject: Cotação Rui Mendes
s://www.dropbox.com/scl/fi/jpzu8a4ivgrcp6ppop2l0/Or-amento-Cota-o.exe?rlkey=uiv0xjzb1t4lqdow9mt8nr4ue&st=5bpqr9yq&dl=1
Română

#RMM_NAble
Or-ameno2026.EXE
edb0db5837527ef456423327b98bc4d6
Subject: Orçamento
s://www.dropbox.com/scl/fi/mgeqq6x0mzko9w50qmrb3/Or-ameno2026.EXE?rlkey=3momtalpyqvspc2f2k55v4q7h&st=e6cgzhcr&dl=1
HT
\_(ʘ_ʘ)_/ retweetledi

Pleased to share my latest blog post for @TeamCymru all about identifying and tracking C2 infrastructure. 1/3 🧵
team-cymru.com/post/fingerpri…
English

#ShadowVector
FALLO_CON_CONCEPTO_FAVORABLE_PARA_EMBARGO_DE_ACTIVOS_Y_CUENTAS_A_DEUDORES_REPORTE_OFICINA_DE_HACIENDA_ALCALDIA_ARBOLEDAD_NORTE_DE_SANTANDER_PARA_EJECUTORIAR_MES_JULIO_DEL_2025pdf.rar
rar a4a4395d398c64ae932d109d362d64d2
js 9d7f7c692b68d5445f152901e80beece
Español
\_(ʘ_ʘ)_/ retweetledi

Pleased to share my first official Team Cymru blog that follows on from my webinar last month 🙌
“Uncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry” 🇰🇵 🔍
team-cymru.com/post/uncoverin…
English

@1ZRR4H @JAMESWT_MHT #Coyote malware ...
WhatsApp
- ZIP
-- LNK
--- PS1
---- EXE
----- PS1
------ EXE
------- Coyote
English

Malware targeting Brazil (geofenced) 🇧🇷 allegedly distributed via WhatsApp
All the LNKs I checked pointed to a different subdomain (Wildcard DNS type), which apparently works and allows them to evade certain network-level detections? 🤔
Two domains:
semrabo[.]com
pinkeosemrabo[.]com
Some LNK names:
ItauComprovante-30443-5410.pdf.lnk
ComprovanteSantander_2025-01-27_8492.pdf.lnk
H/T @malwrhunterteam
[+] 1st stage (ps1) bazaar.abuse.ch/sample/0fd542b…




English

#CarnavalHeist
Nota Eletronica - [0-9]{7}
s://is.gd/RFGZfq
s://notafiscal.relatorio-fiscais.store/nota-estadual/?notafiscal=00382006.240091
20.201.119.30@80
NotaFiscal.pdf.lnk
0afdf765713d2b2b522fcb2b59908871
\c\c.cmd
18a3702bb83631256dac200fba0d5489
Español







