You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This IP is hosting several domains that are being used to distribute MeduzaStealer. When the file is viewed on VirusTotal, the string {"C2 url": "79.137.197.154:15666"} is visible in the Decoded Text section of the behavior report. Viewing http://79.137.197.154/ shows the login screen for the C2 dashboard.
Wildcard domain records
32.28.115.81.185|malicious
Sub-Domain records
No response
Hosts (RFC:953) specific records, not used by DNS RPZ firewalls
Damned, this is teen records in one..., will solves this for you, as you are a big supplier of info
Sorry about that. I wasn't sure which approach would be best. It felt like it made sense to keep the group together to show the relation. What would be the best way to keep this sort of information organized here? A parent post with the host IP then reference the derived domains and C2?
Comments
This IP is hosting several domains that are being used to distribute MeduzaStealer. When the file is viewed on VirusTotal, the string
{"C2 url": "79.137.197.154:15666"}
is visible in the Decoded Text section of the behavior report. Viewinghttp://79.137.197.154/
shows the login screen for the C2 dashboard.Wildcard domain records
Sub-Domain records
No response
Hosts (RFC:953) specific records, not used by DNS RPZ firewalls
No response
SeafeSearch records
No response
Screenshots
Screenshot
Links to external sources
logs from uBlock Origin
N/A
The text was updated successfully, but these errors were encountered: