正在加载视频...
视频加载失败
Very intelligent #android #malware actor filming his #C2 and giving away the URL. Targeting #spain and #portugal it seems. C2: hxxps://190.211.255.218/YTFlMzViNjNiNWM3/OTI0NGRhMTFlMDNk/index.php Probably: #Octo / #Coper android banker. Germán Fernández LaurieWired Alexander Leslie James @0xToxin Ankit Anubhav Tom.K vx-underground
10 条评论

Mikhail Kasimov3 年前
@1ZRR4H Aha, and all domains: biribizidurdursunn[.]com biribizidurdursunn1[.]com biribizidurdursunn2[.]com yamacbank22[.]xyz youtubeadvan3242[.]xyz youtubeadvanced[.]pro Last two ones could be related to youtubeadvanced[.]net youtubevanvedadw[.]net as #SOVA --

Daniel Stirnimann3 年前
@1ZRR4H Indeed, it is #Coper (tag NSGPlaystore). Config

Gi7w0rm3 年前
@1ZRR4H Thanks for sharing this :)

Brute Bee3 年前
@1ZRR4H The IP is also leaked on the video, he doing RDP into a host: 77[.]91[.]77[.]211 He is also using Winrar, 😅

Gi7w0rm3 年前
@1ZRR4H Yeah, the same observation was made here: Also some ip in the 91.... but that's a huge space to check ^^

Igal Lytzki🇮🇱3 年前
@1ZRR4H Lol 😂😂😂

Who said what?3 年前
@1ZRR4H RDPing 77.91.77.211 🇩🇪

Gi7w0rm3 年前
@1ZRR4H True I did oversee that :)

Bread3 年前
@1ZRR4H @Soy @232 lmfao

Ali Aqeel3 年前
@JAMESWT_MHT @1ZRR4H 🤣🤣🤣

