http://tweedge32j4ib2hrj57l676twj2rwedkkkbr57xcz5z73vpkolws6vid.onion/2022/evolution-of-vipersoftx-dga
In June 2022, the first samples will emerge which use a tiny dropper - which this operator will use for stealth, heavily limiting what code is deployed to a victim machine and making it harder for researchers to see the full picture of this activity. June 15th, 2022 Dropper: Load from file at offset, then base64 C2: One known domain, wmail-service.com , uses HTTP Payload: Not witnessed On June 15th, 2022, a topic on malwareremoval.com is started by a person who found a task running on...
1 similar result skipped