this is an old C2 that was also used in 2023-01-26 sample 34104f2ee58f629d7222cce339a24db5. However its still active and Bitter has been recently using other, even older C2's
Another #Spyder from #Sidewinder#APT
-
Md5 930f288c9f9ed516f7eaec8f1ccbfc02
hxxp[:]//libreofficeupdates[.]com/drive/files.php
hxxp[:]//libreofficeupdates[.]com/drive/includes.php
#Spyder malware looks to be an update of #WarHawk malware from #Sidewinder#APT
1f4b225813616fbb087ae211e9805baf
BAF Operations Report CamScannerDocument.exe
c2 hxxp[:]//plainboardssixty[.]com/drive/bottom.php
Are you Small? Medium? Are you a business? I wrote a thing about you! Using @Proofpoint_SME data @threatinsight found SMBs are hot targets for APT threat actors looking for key #espionage info, financial gain, or hoping to launch supply chain attacks
https://t.co/flh0UxLPeq
New variant of #Emotet Excel lure, slight variation where "Relaunch Required" instructions (to bypass Office macro security measures) are in green box instead of yellow. Example file:
W-9 form.xls
703d6f27c9b54b604f58d3d853c328f6cd51b8598af4dedb4ae0ddea3074ef38
Today Proofpoint observed the #Emotet E4 botnet delivering what seems to be a development build of a new #IcedID Loader. This module has the ID 2445 and directly downloads the IcedID bot.
A particularly interesting #Emotet email in #France is spoofing "Chambre des Notaires de Paris."
#Emotet emails are targeting many countries, including the United States, United Kingdom, Japan, Germany, Italy, France, Mexico, and Brazil.
@__0XYC__@StopMalvertisin +2
b82580cd92afe20e3a51ec92fb46053b3f78c93cf57811d94ac9fe14d3a5e21f
List of Officers and amount deducted for floods 2022.xlsm
9133388cf8754dc7bb98031dad59333868f441c303264b9218a900c8079cfafc
List of Officers and amount deducted for floods 2022.xlsm