[bridged from https://infosec.exchange/@james_inthe_box on the fediverse by https://fed.brid.gy/ ]
https://app.any.run/tasks/98ee9a03-06d0-4c94-af52-53a84d3a3132
https://app.any.run/tasks/98ee9a03-06d0-4c94-af52-53a84d3a3132
https://app.any.run/tasks/5e815a05-a047-4010-aefc-9d6f95c1127b
https://app.any.run/tasks/5e815a05-a047-4010-aefc-9d6f95c1127b
https://app.any.run/tasks/399383f4-5ab6-4f53-ab93-09d36c891041
https://app.any.run/tasks/399383f4-5ab6-4f53-ab93-09d36c891041
https://app.any.run/tasks/a38ca435-f03f-4e77-aac0-f7446b6fe4df
https://app.any.run/tasks/a38ca435-f03f-4e77-aac0-f7446b6fe4df
https://gist.github.com/silence-is-best/720a513ff366780662870bc0dd080ce3
#retrohunt
https://gist.github.com/silence-is-best/720a513ff366780662870bc0dd080ce3
#retrohunt
https://app.any.run/tasks/5f8778b4-7a5a-42fc-b814-4951c356c274
https://app.any.run/tasks/5f8778b4-7a5a-42fc-b814-4951c356c274
https://app.any.run/tasks/776a8c9a-61f3-4593-b166-a60e3eb65f2f
https://app.any.run/tasks/776a8c9a-61f3-4593-b166-a60e3eb65f2f
https://app.any.run/tasks/489d6268-d719-4f6f-9de1-798d1c26467a
https://app.any.run/tasks/489d6268-d719-4f6f-9de1-798d1c26467a
https://ballotlinllc\\.top/kellymnb/ENCRYPTED.ps1
c2: http://91.92.243.\254/kelly/five/fre.php
65312b1b16f7928cbd0fa79bc12fe75dac2f610d13a54848a8b6f52d035f870d on the ps1
https://ballotlinllc\\.top/kellymnb/ENCRYPTED.ps1
c2: http://91.92.243.\254/kelly/five/fre.php
65312b1b16f7928cbd0fa79bc12fe75dac2f610d13a54848a8b6f52d035f870d on the ps1
https://gist.github.com/silence-is-best/b0eed8c8a6d6f6381a30d17047603726
#retrohunt
https://gist.github.com/silence-is-best/b0eed8c8a6d6f6381a30d17047603726
#retrohunt
https://gist.github.com/silence-is-best/65c9fe419f8b0551b5f1ce9356e9d13f
https://gist.github.com/silence-is-best/65c9fe419f8b0551b5f1ce9356e9d13f
https://intesmak\\.com/obitwo
c2: https://api.telegram\\.org/bot8099843793:AAGeYKMLti1IpyT9o6bz7OtgdXF9md25uXA
https://intesmak\\.com/obitwo
c2: https://api.telegram\\.org/bot8099843793:AAGeYKMLti1IpyT9o6bz7OtgdXF9md25uXA
https://app.any.run/tasks/67c44d06-c643-4998-af77-05fd6261168f
https://app.any.run/tasks/67c44d06-c643-4998-af77-05fd6261168f
https:// connectme-1ke.pages. dev/LogMeInResolve_Unattended.msi
e56e5f1f37b6c2ae9f4f1b2e7ab2f7aee9ca91c4c84334dd5bb49675de619736
Company ID: 8400521075231559185
https:// connectme-1ke.pages. dev/LogMeInResolve_Unattended.msi
e56e5f1f37b6c2ae9f4f1b2e7ab2f7aee9ca91c4c84334dd5bb49675de619736
Company ID: 8400521075231559185
http://31.57.147.77:6464/gethta
http://31.57.147.77:6464/getdll
hash 88feadbb2f9548d3c0cb9c6519bcea476acf9ac2a3eeccde5655457cbba29db4 on the dll
http://31.57.147.77:6464/gethta
http://31.57.147.77:6464/getdll
hash 88feadbb2f9548d3c0cb9c6519bcea476acf9ac2a3eeccde5655457cbba29db4 on the dll