Top Tweets for #StrRat
Unknown Java #RAT using Halkbank as a lure 🪝, targeting Turkish citizens 🇹🇷
Halkbank Ekstre.jar
\AppData\Roaming\strlogs\keylogs_4558.html
Botnet C2:
📡77.90.153.31:5590 (AS214943 RAILNET 🇺🇸)
Malware sample:
📄https://t.co/mu6BBP98E0
Anyone knows what kind of RAT this is?
"Nuovo Ordine"👇 #STRRAT
https://t.co/jPH18XCoRL
"Ordine n. 25/00019 del 20/01/2025"
+RogueKiller Antirootkit Driver
➡️https://t.co/ljpUckXW8q
AnyRun
https://t.co/447vOptelu
cc @SquiblydooBlog

@JAMESWT_MHT @c_APT_ure That's interesting. Does this mean that #STRRAT is using the new(?) "Believe@@123" C2 protocol alongside the more common "ping|STRRAT" one? Or is the "ping" version getting replaced with "Believe@123"?

@c_APT_ure #STRRAT java #ratty
Some Samples from related and crossrelation hunting
https://t.co/fj2W5YoWt1
Some C2 from related and crossrelation Samples
italimmuo.ddns].net
heavensgatepeace.duckdns.]org
sfadfadfaafaf.ddns.]net
![JAMESWT_WT's tweet photo. @c_APT_ure #STRRAT java #ratty
Some Samples from related and crossrelation hunting
https://t.co/fj2W5YoWt1
Some C2 from related and crossrelation Samples
italimmuo.ddns].net
heavensgatepeace.duckdns.]org
sfadfadfaafaf.ddns.]net https://t.co/RY5bm2d3Ln](https://pbs.twimg.com/media/GZ2rlsNW4BAR4R9.jpg)
🚨 Join us for a webinar on the latest updates in #ThreatDetection! https://t.co/zxi5tHsKzG
🔍 Unveiling #Stealc #infostealer, and #Latrodectus #downloader
🛡️ #YARA Rules targeting #Kematian stealer, #Socks5Systemz, #FakeBat, #STRRAT, and latest #Lumma variants.
and more.
#malware #phishing #malwareanalysis
https://t.co/zxi5tHsKzG

Mentioned #StrRat #Italy Sample
https://t.co/GDwBfcns3D
First Submission 2024-08-06 19:43
Url is
First Submission 2020-05-18 07:56🤯😶🌫️

🇮🇹 Nuova campagna italiana #StrRat: disponibile una ricetta #CyberChef per decodificare il malware
ℹ️ abbiamo creato una ricetta CyberChef che sfrutta funzioni avanzate per facilitare e accelerare il processo di decodifica
ℹ️ Ulteriori dettagli 👇
🔗 https://t.co/IOOaTaLGfS

#Cyberchef #StrRat
➡️ la ricetta prende un input codificato in Base64
➡️ lo decodifica in esadecimale
➡️ pulisce il testo rimuovendo spazi bianchi
➡️ estrae la chiave e IV
➡️ deriva una chiave utilizzando PBKDF2
➡️ utilizza AES per decrittare i dati rimanenti
👇
🇮🇹 Nuova campagna italiana #StrRat: disponibile una ricetta #CyberChef per decodificare il malware
ℹ️ abbiamo creato una ricetta CyberChef che sfrutta funzioni avanzate per facilitare e accelerare il processo di decodifica
ℹ️ Ulteriori dettagli 👇
🔗 https://t.co/IOOaTaLGfS

🇮🇹 Nuova campagna italiana #StrRat: disponibile una ricetta #CyberChef per decodificare il malware
ℹ️ abbiamo creato una ricetta CyberChef che sfrutta funzioni avanzate per facilitare e accelerare il processo di decodifica
ℹ️ Ulteriori dettagli 👇
🔗 https://t.co/IOOaTaLGfS

#ThreatProtection #APT group #BloodyWolf targets #Kazakhstan with phishing emails containing malicious #JAR files to spread #STRRAT malware, read more about Symantec's protection: https://t.co/O7PCC4AD8R
Mentioned #STRRAT and #QRAT and Python Stealer samples *update and tag *added
✳️https://t.co/zTy98keVB6

More payloads:
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/pcor.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/jab.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/py3.8.zip
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/remit.html
+ https://t.co/MZNcQQSXFl
![1ZRR4H's tweet photo. More payloads:
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/pcor.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/jab.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/py3.8.zip
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/remit.html
+ https://t.co/MZNcQQSXFl](https://pbs.twimg.com/media/GP57t__WgAAnA2s.jpg)
⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar
![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP54pUFXUAAsgzt.png)
@cocaman Thanks a lot Corsin! 👍💪🙌
I have to admit I didn't know how to search for it on VT 🙄
But now I can continue...
EML: https://t.co/INDaJgpepZ
URL: https://t.co/E5h53uLF7l
File:
https://t.co/7LPWZZIhEk
#STRRAT
https://t.co/sd02vJD1Uy
Most likely #DESKTOPgroup related

Campagne #Malware #Italy Week 16
👻💣🔥☠️
#AgentTesla: Offerta
#Remcos: Fattura
#WikiLoader: Delivery
#Guloader: Ordine
#Irata: APK Bank
#DarkCloud: Preventivo
#Formbook: Quote
#StrRat: Pagamento
#mwitaly

Top 10 last week's threats by uploads 🌐
⬇️ #Phishing 1154 (1352)
⬇️ #Agenttesla 158 (165)
⬆️ #Njrat 129 (71)
⬇️ #Remcos 75 (92)
⬆️ #Dbatloader 73 (34)
⬇️ #Asyncrat 60 (95)
⬆️ #Orcus 60 (2)
⬇️ #Xworm 58 (62)
⬆️ #Strrat 53 (17)
⬆️ #Redline 50 (31)
Track them all at 👇
https://t.co/dPZCXQX0vn

#ThreatProtection #VCURMS and #STRRAT being delivered via links in spam messages, learn how Symantec protects its customers: https://t.co/53doqGIWL9
🎣#phishing con #RAT: campagna porta gli utenti a scaricare un downloader #Java malevolo che distribuisce #VCURMS e #STRRAT, #trojan ad accesso remoto con capacità di #infostealer/#keylogger👉🏽https://t.co/8aFMXlZXLj #Discord #Steam #cookie #browser #cybersecurity @wcs_cloud #WCS
Last Seen Hashtags on Sotwe
autolactation
Seen from Canada
สาวสอง
Seen from Thailand
femboys
Seen from Canada
dessertmastersau
Seen from Brazil
nolimit nolimit momson
Seen from Netherlands
splash
Seen from United States
DRTA
Seen from Japan
YahwehIsHisName
Seen from United Kingdom
Fouineuse
Seen from United States
payton preslee
Seen from United Kingdom
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.8M followers

Taylor Swift 
@taylorswift13
80.6M followers

Lady Gaga 
@ladygaga
72.2M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.6M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.1M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
59.9M followers














![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP54pUEXoAA7Mb4.png)
![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP53HsIXAAAfmep.jpg)
![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP53HrrXkAA5qrP.jpg)





