Analyzed a PowerShell malware loader that hides its second stage inside a seemingly legitimate MP3 file.
Key observations:
• Downloads result.mp3
• Extracts bytes from a fixed offset (12345)
• Decrypts the blob using an RC4-like stream cipher with key "ZHOPA"
• Attempts in-memory execution via VirtualAlloc + NtCreateThreadEx
This is a nice example of payload smuggling using non-executable media files.
https://lincdiiin[.]com/homework.txt
https://lincdiiin[.]com/Program.exe
https://lincdiiin[.]com/loader.hta
https://lincdiiin[.]com/result.mp3
I have been recently investigating #Vidar samples, found this one that fakes captcha and ask user to loads a code via terminal.
URL: https://loadingsession-pagefrwrd[.]pages[.]dev/?vc=f2b44f1b&ts=1780356164198&rn=491567
File sha256sum
9d4117dfce10abaa6d4dd425b0018a0ff0eab56ec2ff2640f508fcd094d49f02 chlw[.]gz
Full IOCs list
https://t.co/1rRA5vgWOJ
#threathunting #cyberthreat #stealer #malware
Brazil is a Linux kernel rootkit factory.
Diamorphine, Brokepkg, KoviD, Reptile and now Singularity. Some of the most well-known Linux kernel rootkits came from Brazilian researchers.
Brazil has a crazy strong scene in linux rootkit development
Interesting how all of URLs of Routerhosting was suddenly taken down after a lot of pressure 2 days long.
More interestingly, this one URL just popped back online again on the same IP!
https://t.co/xsmLdtANPl
@Hannan_Nozari could you possibly take this one down?
dude, your shit is like a free candy store for APTs from literally every corner of the world, you win the diversity award for the highest amount of TAs from distinct geographical location hosted on same ranges.
people are so tired of you and your lack of response that anytime something pops on your range everybody treats it as high confidence signal of maliciousness lol.
its mind boggling you still need people to report it to you as nobody even gives a fuck anymore on your ranges to cloak their activity lol.
https://t.co/cEf6Ei0H6W
To all my @abuse_ch reporting homies. Keep the pressure up on routerhosting!
I see tons of malware urls online, but I know for a fact that there is even more to be found!
@YassReveal@khamenei_ir Religion as made to control people, and give power to a small circle. And this post and replyes shows exactly that still work flawlessly.
Poucas pessoas estão falando disso, mas na semana passada rolou um ataque aos servidores da JD Consultores, a maior provedora de PSTI do mercado brasileiro, que tem clientes como Nubank, CitiBank, XP e outros. E não foi um caso isolado. Em 2025, a C&M sofreu um ataque também. 🧵👇
Large phishing campaign aimed at Brazil, impersonating jusbrasil @Jusbrasil , using legitimate Microsoft @MsftSecIntel
C2
tocadistribuidora./net
translogvinece./net
telefonesapple./com
smartdistburstcn./net
speedroutenetrixwb./net