http://tweedge32j4ib2hrj57l676twj2rwedkkkbr57xcz5z73vpkolws6vid.onion/2022/evolution-of-vipersoftx-dga
VT Links Sample 1 - Example dropper with DGA, using HTTP as the communication channel. Sample 2 - Example dropper with DGA, using DNS as the communication channel. (Note: it’s late, I’ll expand this later.) Appendix At least, that we know of so far ;) ↩ The browser extension component would later evolve into what is called VenomSoftX by Avast’s report. ↩ Avast also notes wmail-service.com as a ViperSoftX C2 domain, which is correct, but that domain specifically isn’t...