Top Tweets for #JSOutProx
#Visa #warns of #new #JSOutProx #malware #variant #targeting #financial #orgs
https://t.co/Z6Rfwk4F9l
#New #Wave of #JSOutProx #Malware #Targeting #Financial #Firms in #APAC and #MENA
https://t.co/yD4WJgup5g
Visa、金融機関を標的とした新たな JSOutProx マルウェア亜種について警告
Visa warns of new JSOutProx malware variant targeting financial orgs #BleepingComputer (Apr 4)
#JSOutProx #マルウェア #金融機関 #フィッシング #Visa
https://t.co/OUEesHJ3iE
#ThreatProtection New #JsOutProx #malware variant observed in campaigns targeted at financial sector, read more about Symantec's protection: https://t.co/9wVrXwZQdo
Les cibles sont des entreprises de la finance et leurs clients. Les ZIP attachés aux mails de phishing contiennent des .js qui téléchargent JSOutProx à partir d'un dépôt GitLab. #JSOutProx est un framework qui utilise Javascript et .NET.
https://t.co/MGqXfZCSyz
The New Version of #JsOutProx #Malware is Attacking Financial Institutions in APAC and MENA via @Gitlab and @Github Abuse.
https://t.co/Zd6anPSsll

hxxps[://]github[.]com/vectorvector11/transaction/blob/main/MoneyGram_AML_Compliance_review[.]pdf[.]zip-> bf0e1f2347bae5346c48d2a18fd82977af4f71b906da0bd1d74ed6d847624a4b -> https://t.co/2Ft9cAxQPN @anyrun_app #malware #jsoutprox #backdoor #infosec https://t.co/UeRyCmq6ku
And another #JSOutProx RAT sample (https://t.co/RUkRL78W0h). C2 URL is http[:]//desantrytoreh[.]servegame[.]com:9054/ .
Another #JSOutProx RAT sample (https://t.co/QIUNfUAsmy). C2 URL is http[:]//zitduxcidamehtyn[.]ddns[.]net:6870/ .
Likely #JSOutProx RAT
Downloaded via GitHub, utilizing a DDNS C2 domain.
C2: zitduxcidamehtyn[.]ddns[.]net:6870 >> 91.192.100[.]18
Triage URL: https://t.co/iyNeWxHyEI
![nahamike01's tweet photo. Likely #JSOutProx RAT
Downloaded via GitHub, utilizing a DDNS C2 domain.
C2: zitduxcidamehtyn[.]ddns[.]net:6870 >> 91.192.100[.]18
Triage URL: https://t.co/iyNeWxHyEI https://t.co/LDPa43206j](https://pbs.twimg.com/media/FxcCMb4akAE3n5s.png)
New #JSOutProx RAT sample: https://t.co/vDXCmEnjsF . C2 URL is http[:]//desantrytoreh[.]servegame[.]com[:]9054/
Here're some #JsOutProx RAT IOCs from ITW samples from the last few months. JS sample hashes + C2 URLs are at https://t.co/nK9QLiy3UJ
#JSOUTPROX
hantopetrigd[.]ddns[.]net
https://t.co/DqkFjzQpy4
#jsoutprox targeting banks in India 🇮🇳.
Links to several domains on 95.142.46.31 @Hostinger > Fake 404 > zip on @onedrive > js
https://t.co/w34FjAbXyw
https://t.co/ExBKSf9TSW
C2 /apatee40rm.gotdns.ch:9897 79.134.225.79 @kiwi66 (Taken down already?)
Sample https://t.co/tJCYNS5JO1

#jsoutprox
https://t.co/T5vtu3wYuS
https://t.co/zQypI5KES4
#jsoutprox
https://t.co/T5vtu3wYuS
https://t.co/zQypI5KES4
#jsoutprox
https://t.co/I2aRSWjA9b
#jsoutprox
https://t.co/yFYa01TkWW
https://t.co/j3GouTLUMn
#jsoutprox ITW ZIP c1efbf6bdfac93351be862cad6c40da59099500d3855e85cd43efb72b9ca58fa
#ThreatProtection New variant of #JsOutProx RAT spotted, read more about Symantec's protection: https://t.co/jw2a6URXr4

#cybercrime, #JsOutProx is evolving and started targeting western financial organizations. @yoroisecurity #CyberSecurity experts: The #Malware (aka TH-264) has improved protection mechanisms and can operate as a silent info stealer or run offensive plugins.https://t.co/02lYmbIIMt
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
240.1M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
108.9M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.8M followers

Taylor Swift 
@taylorswift13
80.6M followers

Lady Gaga 
@ladygaga
72.1M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.5M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61M followers

X 
@x
60.9M followers

CNN Breaking News 
@cnnbrk
59.9M followers








![nahamike01's tweet photo. Likely #JSOutProx RAT
Downloaded via GitHub, utilizing a DDNS C2 domain.
C2: zitduxcidamehtyn[.]ddns[.]net:6870 >> 91.192.100[.]18
Triage URL: https://t.co/iyNeWxHyEI https://t.co/LDPa43206j](https://pbs.twimg.com/media/FxcCJ9qagAUP03Q.jpg)
![nahamike01's tweet photo. Likely #JSOutProx RAT
Downloaded via GitHub, utilizing a DDNS C2 domain.
C2: zitduxcidamehtyn[.]ddns[.]net:6870 >> 91.192.100[.]18
Triage URL: https://t.co/iyNeWxHyEI https://t.co/LDPa43206j](https://pbs.twimg.com/media/FxcCHPuaIAEQ90d.jpg)
![nahamike01's tweet photo. Likely #JSOutProx RAT
Downloaded via GitHub, utilizing a DDNS C2 domain.
C2: zitduxcidamehtyn[.]ddns[.]net:6870 >> 91.192.100[.]18
Triage URL: https://t.co/iyNeWxHyEI https://t.co/LDPa43206j](https://pbs.twimg.com/media/FxcCFO2aUAAXxbL.jpg)






