Top Tweets for #Cryptbot
📅 Read the full report here: https://t.co/blCnBLFody
#Cybersecurity #CTI #Cybercrime #ThreatIntel #CryptBot #Infostealer #Malware

PEAKLIGHT, a new memory-only dropper, is deploying #malware on Windows systems via pirated movie files. It uses #PowerShell scripts to install information stealers like Lumma Stealer and #CryptBot.
https://t.co/gw7YRfbRmS
#cybersecurity #infosec
With one cluster closely overlapping with what Talos tracks as #CoralRaider, we identified further Emmenhtal iterations leading to #CryptBot, #Lumma, #AsyncRAT, #Meduza, #Xworm, #SectopRAT and many others 👾, in multiple campaigns using fake PDF or video as lures.

🔍👩💻Our CTI analysts, @CERTCyberdef @Mar_Pich and A. Matousek just released a new article on a little-documented loader, dubbed #Emmenhtal.
👉📰Read here: https://t.co/BSOQy15M96
#lummastealer #cryptbot #cheesybunny #cyberthreatintelligence #threathunting

@malwrhunterteam Mentioned Samples
❇️https://t.co/e586ivEN8n
AnyRun #RemCosRat
💯https://t.co/PnfLL0EFjY
⛔️C2 81.19.139.]74
Samples from previus tweet
❇️https://t.co/Q0D4lQVux5
AnyRun #cryptbot
💯https://t.co/aPowSpqMyY
![JAMESWT_WT's tweet photo. @malwrhunterteam Mentioned Samples
❇️https://t.co/e586ivEN8n
AnyRun #RemCosRat
💯https://t.co/PnfLL0EFjY
⛔️C2 81.19.139.]74
Samples from previus tweet
❇️https://t.co/Q0D4lQVux5
AnyRun #cryptbot
💯https://t.co/aPowSpqMyY https://t.co/eoxqpAQc5q](https://pbs.twimg.com/media/GTbXhQiXsAAlm_c.jpg)
The #threatactor group #CoralRaider was recently observed distributing three #infostealers, #CryptBot, #LummaC2, and #Rhadamanthys. @TalosSecurity recently reported on this activity. Check out our blog for more info and PolySwarm’s related samples.
https://t.co/CoVMefm4RA
There is a new version of #CryptBot spreading around with VMProtect? The infrastructure belongs to CryptBot 🤔
🛜 C2: vdeight8vt[.]top (81.94.159[.]120)
🔥 @unpacme did a great job with unpacking
https://t.co/1rmFRI0bB4
📁 More related samples:
490625afa4de3eac3b03d1ca3e81afab07b5e748423319ee6e08f58c40d20250
4c75fb7bd0855e4d4623b1ac71a47c9e7f4fce743d15be28c644e32181a5d785
62340232fc4a9eb580f7153af5edc4c01cbd65bb698cad256edba9fa71c978cf
b3082e8f12436cc58855241b73a72d5d2cfa3a9cdfaffd0616e9e5820b6ad830
b3aad09df96b1e8491e0dfb2ca7e3addff573c034d6c7d384587977fc1d1d4a2
e4502b6a97614a12eb799262cd8c6e796f5b5b3fd2a9fac97f533b0c06b4a3a7
e5bf0b095b5b78d44a0664c9e5def6818db220d0646d0fecf1c3f86cdddc8ceb
fbdb00670f30534cd1847cd64d3f9c02af991dd922ee7e2b2c9a662f239fac11
fe320183b006be1b318bc889dc42ee4cf82d7d39ef5b188764dcee846b656b1f
https://t.co/FFhz0ntDMU sandbox analysis: https://t.co/RcnlDbuq4L
![RussianPanda9xx's tweet photo. There is a new version of #CryptBot spreading around with VMProtect? The infrastructure belongs to CryptBot 🤔
🛜 C2: vdeight8vt[.]top (81.94.159[.]120)
🔥 @unpacme did a great job with unpacking
https://t.co/1rmFRI0bB4
📁 More related samples:
490625afa4de3eac3b03d1ca3e81afab07b5e748423319ee6e08f58c40d20250
4c75fb7bd0855e4d4623b1ac71a47c9e7f4fce743d15be28c644e32181a5d785
62340232fc4a9eb580f7153af5edc4c01cbd65bb698cad256edba9fa71c978cf
b3082e8f12436cc58855241b73a72d5d2cfa3a9cdfaffd0616e9e5820b6ad830
b3aad09df96b1e8491e0dfb2ca7e3addff573c034d6c7d384587977fc1d1d4a2
e4502b6a97614a12eb799262cd8c6e796f5b5b3fd2a9fac97f533b0c06b4a3a7
e5bf0b095b5b78d44a0664c9e5def6818db220d0646d0fecf1c3f86cdddc8ceb
fbdb00670f30534cd1847cd64d3f9c02af991dd922ee7e2b2c9a662f239fac11
fe320183b006be1b318bc889dc42ee4cf82d7d39ef5b188764dcee846b656b1f
https://t.co/FFhz0ntDMU sandbox analysis: https://t.co/RcnlDbuq4L](https://pbs.twimg.com/media/GIKqsdBWwAAByTA.png)
#100DaysofYARA Day21:
this rule detects the unpacked version of #CryptBot Stealer
rule -> https://t.co/0CekmAtwmH

@malwrhunterteam @0xDanielLopez @g0njxa @weareDMNTRs Importante lo que agrega @g0njxa, el malware podría ser realmente #CryptBot, más los dominios de distribución activos en este momento.
https://t.co/sVNXCuT1Uf

@1ZRR4H @malwrhunterteam @0xDanielLopez @weareDMNTRs La pagina desde donde descargo:
/oficial-kmspico.com/
aun activo sirviendo #Cryptbot
/rars-uploaded.com/KMSpico/
Detonacion https://t.co/KUvHLVn2Hk
Esta campaña es conocida y antigua, el resto es historia
@1ZRR4H @malwrhunterteam @0xDanielLopez @weareDMNTRs La pagina desde donde descargo:
/oficial-kmspico.com/
aun activo sirviendo #Cryptbot
/rars-uploaded.com/KMSpico/
Detonacion https://t.co/KUvHLVn2Hk
Esta campaña es conocida y antigua, el resto es historia
🤖New #Cryptbot activity detected.
Of course, the campaign is delivered through pirate sites with "cracked" software.
🔍Investigated website: mycrackfree.]com (with cloudflare protection)
↩️Redirects: freeinstallcpc.]xyz @namecheap -> etradistribuciones.]com -> href.]li -> somosobrasocial.]com
URL that downloads the malware: hxxps://somosobrasocial.]com/quuRcHYZdQu/d3/F5Y/gMCCVo3JhfGqrc
C2: hxxp://qdfourt14sr.]top/zip.php
212.]193.]57.]173
All stolen data is bundled into a zip-file that is uploaded to the c2.
IP address 🇷🇺 185.]112.]83.]145 is the same for etradistribuciones.]com and somosobrasocial.]com
[+] Sample in zip format:
https://t.co/9XOgUManWh
[+] https://t.co/IPn9rKYzul analysis
https://t.co/SRaUHiBgrk
![V3n0mStrike's tweet photo. 🤖New #Cryptbot activity detected.
Of course, the campaign is delivered through pirate sites with "cracked" software.
🔍Investigated website: mycrackfree.]com (with cloudflare protection)
↩️Redirects: freeinstallcpc.]xyz @namecheap -> etradistribuciones.]com -> href.]li -> somosobrasocial.]com
URL that downloads the malware: hxxps://somosobrasocial.]com/quuRcHYZdQu/d3/F5Y/gMCCVo3JhfGqrc
C2: hxxp://qdfourt14sr.]top/zip.php
212.]193.]57.]173
All stolen data is bundled into a zip-file that is uploaded to the c2.
IP address 🇷🇺 185.]112.]83.]145 is the same for etradistribuciones.]com and somosobrasocial.]com
[+] Sample in zip format:
https://t.co/9XOgUManWh
[+] https://t.co/IPn9rKYzul analysis
https://t.co/SRaUHiBgrk](https://pbs.twimg.com/media/GBw6RPGXsAAC6YV.png)
Welcome to the future! The Cryptybot collection represents an innovative vision for the years to come. This project, started in 2021, was carefully developed over an extensive period,
#NFT #CRYPTBOT #CRYPTO #CRYPTONFT
#NFTS @cryptocom
https://t.co/e3t1NzftsN
Igor is now helping you "activating" your unpaid Office products on hxxps://office-activator[.]com/.
What a gentleman, but don't forget to disable your antivirus if you want to see your credentials stolen in your browser also...
#cryptbot #infostealer
![H_Miser's tweet photo. Igor is now helping you "activating" your unpaid Office products on hxxps://office-activator[.]com/.
What a gentleman, but don't forget to disable your antivirus if you want to see your credentials stolen in your browser also...
#cryptbot #infostealer https://t.co/j4yl7et090](https://pbs.twimg.com/media/F9yBvtwWMAAInE3.png)
Last Seen Hashtags on Sotwe
Most Popular Users

Elon Musk 
@elonmusk
240.1M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
108.9M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.8M followers

Taylor Swift 
@taylorswift13
80.6M followers

Lady Gaga 
@ladygaga
72.2M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.5M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.1M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
59.9M followers












![suyog41's tweet photo. Cryptbot
Download LINK (ALTERNATIVE).url
06996bb69b5978d822b228766c4b44c0
URL=http://gg[.]gg/1b9jyb
password protected zip
Sеtup.exe
4de2056db3a3b39bee9d833d403091d4 #Cryptbot
C2
twex12ht[.]top
#IOC https://t.co/XWOt4LKG1Q](https://pbs.twimg.com/media/GT9MLfCXUAAfbSt.png)
![suyog41's tweet photo. Cryptbot
Download LINK (ALTERNATIVE).url
06996bb69b5978d822b228766c4b44c0
URL=http://gg[.]gg/1b9jyb
password protected zip
Sеtup.exe
4de2056db3a3b39bee9d833d403091d4 #Cryptbot
C2
twex12ht[.]top
#IOC https://t.co/XWOt4LKG1Q](https://pbs.twimg.com/media/GT9MLeKb0AUt6QY.png)

![JAMESWT_WT's tweet photo. @malwrhunterteam Mentioned Samples
❇️https://t.co/e586ivEN8n
AnyRun #RemCosRat
💯https://t.co/PnfLL0EFjY
⛔️C2 81.19.139.]74
Samples from previus tweet
❇️https://t.co/Q0D4lQVux5
AnyRun #cryptbot
💯https://t.co/aPowSpqMyY https://t.co/eoxqpAQc5q](https://pbs.twimg.com/media/GTbXgylW8AAkUY3.jpg)
![JAMESWT_WT's tweet photo. @malwrhunterteam Mentioned Samples
❇️https://t.co/e586ivEN8n
AnyRun #RemCosRat
💯https://t.co/PnfLL0EFjY
⛔️C2 81.19.139.]74
Samples from previus tweet
❇️https://t.co/Q0D4lQVux5
AnyRun #cryptbot
💯https://t.co/aPowSpqMyY https://t.co/eoxqpAQc5q](https://pbs.twimg.com/media/GTbXgTUXEAAL8bQ.jpg)


![RussianPanda9xx's tweet photo. There is a new version of #CryptBot spreading around with VMProtect? The infrastructure belongs to CryptBot 🤔
🛜 C2: vdeight8vt[.]top (81.94.159[.]120)
🔥 @unpacme did a great job with unpacking
https://t.co/1rmFRI0bB4
📁 More related samples:
490625afa4de3eac3b03d1ca3e81afab07b5e748423319ee6e08f58c40d20250
4c75fb7bd0855e4d4623b1ac71a47c9e7f4fce743d15be28c644e32181a5d785
62340232fc4a9eb580f7153af5edc4c01cbd65bb698cad256edba9fa71c978cf
b3082e8f12436cc58855241b73a72d5d2cfa3a9cdfaffd0616e9e5820b6ad830
b3aad09df96b1e8491e0dfb2ca7e3addff573c034d6c7d384587977fc1d1d4a2
e4502b6a97614a12eb799262cd8c6e796f5b5b3fd2a9fac97f533b0c06b4a3a7
e5bf0b095b5b78d44a0664c9e5def6818db220d0646d0fecf1c3f86cdddc8ceb
fbdb00670f30534cd1847cd64d3f9c02af991dd922ee7e2b2c9a662f239fac11
fe320183b006be1b318bc889dc42ee4cf82d7d39ef5b188764dcee846b656b1f
https://t.co/FFhz0ntDMU sandbox analysis: https://t.co/RcnlDbuq4L](https://pbs.twimg.com/media/GIKqqCHXUAAuK15.png)




![V3n0mStrike's tweet photo. 🤖New #Cryptbot activity detected.
Of course, the campaign is delivered through pirate sites with "cracked" software.
🔍Investigated website: mycrackfree.]com (with cloudflare protection)
↩️Redirects: freeinstallcpc.]xyz @namecheap -> etradistribuciones.]com -> href.]li -> somosobrasocial.]com
URL that downloads the malware: hxxps://somosobrasocial.]com/quuRcHYZdQu/d3/F5Y/gMCCVo3JhfGqrc
C2: hxxp://qdfourt14sr.]top/zip.php
212.]193.]57.]173
All stolen data is bundled into a zip-file that is uploaded to the c2.
IP address 🇷🇺 185.]112.]83.]145 is the same for etradistribuciones.]com and somosobrasocial.]com
[+] Sample in zip format:
https://t.co/9XOgUManWh
[+] https://t.co/IPn9rKYzul analysis
https://t.co/SRaUHiBgrk](https://pbs.twimg.com/media/GBw3_tUWoAAa_ZV.jpg)
![V3n0mStrike's tweet photo. 🤖New #Cryptbot activity detected.
Of course, the campaign is delivered through pirate sites with "cracked" software.
🔍Investigated website: mycrackfree.]com (with cloudflare protection)
↩️Redirects: freeinstallcpc.]xyz @namecheap -> etradistribuciones.]com -> href.]li -> somosobrasocial.]com
URL that downloads the malware: hxxps://somosobrasocial.]com/quuRcHYZdQu/d3/F5Y/gMCCVo3JhfGqrc
C2: hxxp://qdfourt14sr.]top/zip.php
212.]193.]57.]173
All stolen data is bundled into a zip-file that is uploaded to the c2.
IP address 🇷🇺 185.]112.]83.]145 is the same for etradistribuciones.]com and somosobrasocial.]com
[+] Sample in zip format:
https://t.co/9XOgUManWh
[+] https://t.co/IPn9rKYzul analysis
https://t.co/SRaUHiBgrk](https://pbs.twimg.com/media/GBw3whHXkAAHo3f.jpg)
![V3n0mStrike's tweet photo. 🤖New #Cryptbot activity detected.
Of course, the campaign is delivered through pirate sites with "cracked" software.
🔍Investigated website: mycrackfree.]com (with cloudflare protection)
↩️Redirects: freeinstallcpc.]xyz @namecheap -> etradistribuciones.]com -> href.]li -> somosobrasocial.]com
URL that downloads the malware: hxxps://somosobrasocial.]com/quuRcHYZdQu/d3/F5Y/gMCCVo3JhfGqrc
C2: hxxp://qdfourt14sr.]top/zip.php
212.]193.]57.]173
All stolen data is bundled into a zip-file that is uploaded to the c2.
IP address 🇷🇺 185.]112.]83.]145 is the same for etradistribuciones.]com and somosobrasocial.]com
[+] Sample in zip format:
https://t.co/9XOgUManWh
[+] https://t.co/IPn9rKYzul analysis
https://t.co/SRaUHiBgrk](https://pbs.twimg.com/media/GBw3iPcWIAA7ACN.png)


