IP: 103.13.210.153 (AS41436)
URL: hxxp://103.13.210.153/bins/ (open dir)
C2 endpoint: 103.13.210.153:1312
Listener endpoint: 103.13.210.153:3912
Infos: It's a mirai which is vulnerable to "buffer overflow".
@redrabyt.es.bsky.social
Developer, threat reporter, OSINT, CNCs reverser.
IP: 103.13.210.153 (AS41436)
URL: hxxp://103.13.210.153/bins/ (open dir)
C2 endpoint: 103.13.210.153:1312
Listener endpoint: 103.13.210.153:3912
Infos: It's a mirai which is vulnerable to "buffer overflow".
IP: 194.180.48.105 (AS211252)
URL: hxxp://194.180.48.105/d
Listener endpoint: 194.180.48.105:6667
IP: 80.94.92.20 (AS47890)
URL: hxxp://80.94.92.20/ssh (already reported)
C2 endpoint: 80.94.92.20:59666
Listener endpoint: 80.94.92.20:24529
Infos: It's a mirai which is vulnerable to "buffer overflow".
MALWARE REPORT
06.10.2023 12:52 — 👍 0 🔁 0 💬 3 📌 0VBA sucks.
03.10.2023 14:50 — 👍 1 🔁 0 💬 0 📌 0Thank you for invite @securesh3ll.bsky.social 👀
youtu.be/1CurN2Fg-2E