Can you host a copy somewhere?
-
-
Copy of the whole response as it is now or the older ones?
1 reply 0 retweets 1 like -
The news.js with the malware link please
1 reply 0 retweets 0 likes -
Early August variant: https://pastebin.com/PxbWQAHb & early July variant:https://pastebin.com/HGYKkmv1
1 reply 0 retweets 4 likes -
Thank you very much!
1 reply 0 retweets 2 likes -
No problem! Currently checking our data to see if I can pull up the payload from the powershell script. This does feel targeted/custom.
1 reply 0 retweets 2 likes -
Replying to @ydklijnsma @Voulnet and
Two stager samples (includes the one linked by MHT): https://virustotal.com/en/file/ac03023a50e48f5d7758f32681302433bfa8c65509530a11f3e70def7e540150/analysis/1502173404/ … & https://www.virustotal.com/en/file/a46bf4eda3ebb28351f780eeb3bcad65eff82e27d64ec45d4ee6c1cfdd6468f8/analysis/1502258572/ …
1 reply 0 retweets 2 likes -
Replying to @ydklijnsma @Voulnet and
Hash rotates every time, but is in essence the same binary. Definitely seems targeted. Anyone has a copy of the ELF sample perchance?
1 reply 0 retweets 2 likes -
Replying to @bartblaze @ydklijnsma and
Yes, here it is: https://www.virustotal.com/en/file/4f7afdf26384cb8ecd6965ce1bd2acb87e1492a42d25625cd22c1f579609260d/analysis/1502277395/ …
2 replies 0 retweets 2 likes -
Replying to @malwrhunterteam @bartblaze and
Besides the "Your flash plugin has been updated to version 26.0.0.131" and a different fake session ID its essentially the same thing.pic.twitter.com/Ds5ZYggEzp
1 reply 0 retweets 2 likes
Exactly! Thanks Yonathan!
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.