_re_fox@_re_foxMay 27, 2022#malware #DOUBLEBACK c41e2c2cc5843cedd79162c73787d4de XOR key for config: 0x000001bf C2: https://greeklife242[.]com/admin8/client.php https://cdnprojects[.]net/admin8/client.php69
_re_fox@_re_foxMay 18, 2022#malware rtf template injection IDEAS 2022.doc - 35eadf808d958c01bd4b6b18a3ade34e Template -> http://log[.]bookservices[.]xyz/Ods9Z6420zj7Y9H3/OsVoOaari3CP2x4i.php215
_re_fox@_re_foxApr 21, 2022#malware template injection 17efa6a9b3547aaad4588c07f9773e6a - ( ගුවන් හමුදා සේවා පුද්ගලයින් අනුයුක්ත කර ගැනීම.doc) Template: http://records.hibiscus[.]live/NDnD7RdekyhSrhPE/KOighzucGWiCq6hR.php 146.70.29[.]2513719
_re_fox@_re_foxDec 4, 2021Linux .desktop entry #malware 09857e9e3676ee079de645e7dd4a65ec - Def_Coop_Mtg.odt.desktop Decoy: http://www.mea[.]gov[.]in/Portal/CountryNews/11790_Press_Statement_EAM_visit_5_September.docx DL and exec: http://178.18.249[.]42/mtg.sh -> http://178.18.249[.]42/calendar124
_re_fox@_re_foxApr 16, 2021#malware Call-for-Proposal-DGSP-COAS-Chair-Excellance[.]zip Containing #lnk 261fa3263efc672ed853c7b327b64d70 mshta -> iiieyehealth[.]com Drops winidr.exe (76f427732d65127b631822e84158fab3) C2 http://161.97.142[.]96/htt_p app.any.run/tasks/1e78d9b8…18