@nickmedico94@SeeRacists They shouldn’t want to say it and they are not saying the same words. Make it make sense that is also a person of authority. The word was birthed out of oppression.
Zircuit Finance is now live.
Institutional-grade yield. Transparent structure. Security-first design.
Targeting 8–11% APR with no deposit minimums and 0% management fee.
Interesting NodeJS botnet malware campaign using C2s stored on ETH blockchain contracts , as a potential initial access tool🪙🔎
The malware is being spread via a fake GitHub repo impersonating a F5 Big IP VPN Client on /github.com/dhclnt/BIG-IP-Edge-Client (that I believe it has been already deleted, timing matters)
Detonation: https://t.co/GLbFZK1CRV
Inside the ZIP file shared on the releases page, a malicious installer downloads NodeJS and runs obfuscated javascript code
(MSI:eab5efb15861a85fc4f116b2da31e0eddbcb906892484c49a0be4862abc4e1f4)
An initial JS loader decrypts, launches, and creates persistence on another obfuscated JS script that manages the C2 communications.
(raw JS:610c67028da05a45cc2a9bf42511f9cd848eb2de945c522cb3b7fde625a75b60)
partially deobfuscated to read -> 646f6aa9c47087b351eba60a5ee400c399741ff7f4ea671639fc85ae94d3c226
This main JS payload interacts with a ETH contract on address 0xe26c57b7fa8de030238b0a71b3d063397ac127d3, making a RPC call to retrieve C2 -> hayesmed[.]com
The infected machines, bots, will constantly check for this C2 domain, connecting to the new one if the value on the contract is changed. (image 1)
Then, the JS payload retrieves and execute more code generated on the C2. In this case communicating with generated URLs that looks like:
{C2}/api/{rand1}/{BOT_ID}/{rand2}.{ext}?{param}={BUILD_ID}
Being rand1 and rand2 random hex 4-bytes values, ext = one of (png jpg gif css ico webp) , param = one of (id token key b q s v), BOT_ID as the unique infected machine ID generated previously and a hardcoded BUILD_ID -> 8c461b56-b9b2-4b23-b8de-214814060b01.
A working example is: hayesmed[.]com/api/9f3a1c2e/550e8400-e29b-41d4-a716-446655440000/7a1d4c9b.png?id=8c461b56-b9b2-4b23-b8de-214814060b01
The code generated can be found here: af075ba53d3931095094dfa0a98c65a57a0329738560ff316cffcfb4d9cb30ff (image 2)
This second stage payload checks for the OS of the infected machine (Windows, MacOS or Linux), fingerprints the host (grabbing information of the public IP, Username, Hostname, OS version, Kernel / release, Architecture, Node.js version, Uptime, CPU models, Core count, RAM, GPU model, MAC address, Machine GUID, Installed antivirus or AV processes, Domain membership, AD domain name, WORKGROUP vs domain-joined, Privileged execution) and sends all this data to the known C2 via hxxp://C2/<HWID>
Please note that this payload also checks for locales of the CIS countries on the machine to stop execution (in this case Russia, Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, Armenia, Azerbaijan and Georgia)
The infected machine maintains persistent communication with the C2 while operators can load tasks to execute unknown malware on the selected host, making this a potential initial access malware used in unknown further campaigns.
Today AI Video stops being slop.
Introducing Wondercraft Video, an AI video studio built for real work.
Create explainer videos, trainings, product launches, ads, and more by describing what you want.
RT and comment “WONDA” and I’ll DM you 1,000 free credits.