Filter
Exclude
Time range
-
Near
5 Oct 2023
#xkeybot #malware Email Swift Payment delivering #originbotnet Attachment: Swift.gz (c079296024238f82b1a019c712f5b8a6) -> Swift.exe (ce79ff49e2442108fb4eb3654d23dbad) veit-intl.]com/gate c2: veit-intl.]com (199.188.200.]87) @namecheap see: tria.ge/231005-3vdgnaaa62/be…
1
2
12
1,982
In September 2023, we collected Command and Control (C2) panels associated with diverse malwares . Over this timeframe, we identified 222 indicators of compromise, with Supershell leading the list, followed by Lokibot, Risepro, Unam, and Xkeybot. Additionally, our observations revealed the emergence of novel malware families, including Gotham Stealer, Bunny Loader, Xkeybot, and LOTO.
2
7
3,317
24 Sep 2023
#malware #opendir on zzlsteel[.]cc serving malwares, notably #OriginBotnet / #XKeyBot which calls out to C2: nitrosoftwares[.]shop Both Domains registered @namecheap Other C2 registered via @namecheap : ltm-canada.]com/login/ turinapparrels.]com/login/
5
11
60
8,144
Looks it's a newer build of XKeyBot. Anyway, XKeyBot name is still better to use I think, as there is already an Origin named malware (previously Agent Tesla), which as you know some idiots calls a botnet too, so OriginBotnet name for XKeyBot would make confusion for some...
2
352
17 Sep 2023
Seems #XKeyBot = #OriginBotnet #malware unpacked sample with string OriginBotnet here: unpac.me/results/33878a26-4a… Got me on google, to find a 6 days old article by @Fortinet : fortinet.com/blog/threat-res… Third Payload named after namespace. SAme C2 panel.

28 Jul 2023
For those that want to name/reverse a malware: Unknown #malware to me Unknown C2 Panel to me evensayers.]com[.au/gate evensayers.]com[.au/login/ MD5: ecfb74b93750609b906f519809d45556 tria.ge/230728-zryfwaac8y/be… cc: @Gi7w0rm @executemalware @malwrhunterteam
1
8
24
10,718
17 Sep 2023
More #XKeyBot #malware C2 panels 1oxcv1.duckdns.]org/login/ 198.98.54.]161/login/ wjjiutia.]com/login/ ISO-> XLS-> s://motioncontorlshop.]com/mydoc/champ/champ[.exe tria.ge/230917-n84hnscg53

28 Jul 2023
For those that want to name/reverse a malware: Unknown #malware to me Unknown C2 Panel to me evensayers.]com[.au/gate evensayers.]com[.au/login/ MD5: ecfb74b93750609b906f519809d45556 tria.ge/230728-zryfwaac8y/be… cc: @Gi7w0rm @executemalware @malwrhunterteam
8
26
6,526
7 Aug 2023
Thanks to @ViriBack (with additional chime-in by @James_inthe_box and @Jane_0sint) here for the hash and sandbox run for 2047004 - alerting on a XKeyBot C2 checkin/POST!

28 Jul 2023
For those that want to name/reverse a malware: Unknown #malware to me Unknown C2 Panel to me evensayers.]com[.au/gate evensayers.]com[.au/login/ MD5: ecfb74b93750609b906f519809d45556 tria.ge/230728-zryfwaac8y/be… cc: @Gi7w0rm @executemalware @malwrhunterteam
1
2
100
31 Jul 2023
Let's go with XKeyBot for now. Can always update/rename rules and change Metadata when we have more info. Expect coverage for this today in ETOPEN. Thank you all for sharing this!
1
7
267
31 Jul 2023
Well, I am fine with that, XKeyLoader or XKeyBot?
1
5
556
If that x-key header is so special/unique, then if still nothing better, what about just calling it XKeyBot? 😂
2
5
573