Top Tweets for #Strrat
Unknown Java #RAT using Halkbank as a lure 🪝, targeting Turkish citizens 🇹🇷
Halkbank Ekstre.jar
\AppData\Roaming\strlogs\keylogs_4558.html
Botnet C2:
📡77.90.153.31:5590 (AS214943 RAILNET 🇺🇸)
Malware sample:
📄https://t.co/mu6BBP98E0
Anyone knows what kind of RAT this is?
"Nuovo Ordine"👇 #STRRAT
https://t.co/jPH18XCoRL
"Ordine n. 25/00019 del 20/01/2025"
+RogueKiller Antirootkit Driver
➡️https://t.co/ljpUckXW8q
AnyRun
https://t.co/447vOptelu
cc @SquiblydooBlog

@JAMESWT_MHT @c_APT_ure That's interesting. Does this mean that #STRRAT is using the new(?) "Believe@@123" C2 protocol alongside the more common "ping|STRRAT" one? Or is the "ping" version getting replaced with "Believe@123"?

@c_APT_ure #STRRAT java #ratty
Some Samples from related and crossrelation hunting
https://t.co/fj2W5YoWt1
Some C2 from related and crossrelation Samples
italimmuo.ddns].net
heavensgatepeace.duckdns.]org
sfadfadfaafaf.ddns.]net
![JAMESWT_WT's tweet photo. @c_APT_ure #STRRAT java #ratty
Some Samples from related and crossrelation hunting
https://t.co/fj2W5YoWt1
Some C2 from related and crossrelation Samples
italimmuo.ddns].net
heavensgatepeace.duckdns.]org
sfadfadfaafaf.ddns.]net https://t.co/RY5bm2d3Ln](https://pbs.twimg.com/media/GZ2rlsNW4BAR4R9.jpg)
🚨 Join us for a webinar on the latest updates in #ThreatDetection! https://t.co/zxi5tHsKzG
🔍 Unveiling #Stealc #infostealer, and #Latrodectus #downloader
🛡️ #YARA Rules targeting #Kematian stealer, #Socks5Systemz, #FakeBat, #STRRAT, and latest #Lumma variants.
and more.
#malware #phishing #malwareanalysis
https://t.co/zxi5tHsKzG

Mentioned #StrRat #Italy Sample
https://t.co/GDwBfcns3D
First Submission 2024-08-06 19:43
Url is
First Submission 2020-05-18 07:56🤯😶🌫️

🇮🇹 Nuova campagna italiana #StrRat: disponibile una ricetta #CyberChef per decodificare il malware
ℹ️ abbiamo creato una ricetta CyberChef che sfrutta funzioni avanzate per facilitare e accelerare il processo di decodifica
ℹ️ Ulteriori dettagli 👇
🔗 https://t.co/IOOaTaLGfS

#Cyberchef #StrRat
➡️ la ricetta prende un input codificato in Base64
➡️ lo decodifica in esadecimale
➡️ pulisce il testo rimuovendo spazi bianchi
➡️ estrae la chiave e IV
➡️ deriva una chiave utilizzando PBKDF2
➡️ utilizza AES per decrittare i dati rimanenti
👇
🇮🇹 Nuova campagna italiana #StrRat: disponibile una ricetta #CyberChef per decodificare il malware
ℹ️ abbiamo creato una ricetta CyberChef che sfrutta funzioni avanzate per facilitare e accelerare il processo di decodifica
ℹ️ Ulteriori dettagli 👇
🔗 https://t.co/IOOaTaLGfS

🇮🇹 Nuova campagna italiana #StrRat: disponibile una ricetta #CyberChef per decodificare il malware
ℹ️ abbiamo creato una ricetta CyberChef che sfrutta funzioni avanzate per facilitare e accelerare il processo di decodifica
ℹ️ Ulteriori dettagli 👇
🔗 https://t.co/IOOaTaLGfS

#ThreatProtection #APT group #BloodyWolf targets #Kazakhstan with phishing emails containing malicious #JAR files to spread #STRRAT malware, read more about Symantec's protection: https://t.co/O7PCC4AD8R
Mentioned #STRRAT and #QRAT and Python Stealer samples *update and tag *added
✳️https://t.co/zTy98keVB6

More payloads:
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/pcor.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/jab.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/py3.8.zip
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/remit.html
+ https://t.co/MZNcQQSXFl
![1ZRR4H's tweet photo. More payloads:
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/pcor.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/jab.bat
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/py3.8.zip
- https://mbycket45344.s3.eu-north-1.amazonaws[.]com/remit.html
+ https://t.co/MZNcQQSXFl](https://pbs.twimg.com/media/GP57t__WgAAnA2s.jpg)
⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar
![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP54pUFXUAAsgzt.png)
@cocaman Thanks a lot Corsin! 👍💪🙌
I have to admit I didn't know how to search for it on VT 🙄
But now I can continue...
EML: https://t.co/INDaJgpepZ
URL: https://t.co/E5h53uLF7l
File:
https://t.co/7LPWZZIhEk
#STRRAT
https://t.co/sd02vJD1Uy
Most likely #DESKTOPgroup related

Campagne #Malware #Italy Week 16
👻💣🔥☠️
#AgentTesla: Offerta
#Remcos: Fattura
#WikiLoader: Delivery
#Guloader: Ordine
#Irata: APK Bank
#DarkCloud: Preventivo
#Formbook: Quote
#StrRat: Pagamento
#mwitaly

Top 10 last week's threats by uploads 🌐
⬇️ #Phishing 1154 (1352)
⬇️ #Agenttesla 158 (165)
⬆️ #Njrat 129 (71)
⬇️ #Remcos 75 (92)
⬆️ #Dbatloader 73 (34)
⬇️ #Asyncrat 60 (95)
⬆️ #Orcus 60 (2)
⬇️ #Xworm 58 (62)
⬆️ #Strrat 53 (17)
⬆️ #Redline 50 (31)
Track them all at 👇
https://t.co/dPZCXQX0vn

#ThreatProtection #VCURMS and #STRRAT being delivered via links in spam messages, learn how Symantec protects its customers: https://t.co/53doqGIWL9
🎣#phishing con #RAT: campagna porta gli utenti a scaricare un downloader #Java malevolo che distribuisce #VCURMS e #STRRAT, #trojan ad accesso remoto con capacità di #infostealer/#keylogger👉🏽https://t.co/8aFMXlZXLj #Discord #Steam #cookie #browser #cybersecurity @wcs_cloud #WCS
Last Seen Hashtags on Sotwe
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.9M followers

Taylor Swift 
@taylorswift13
80.7M followers

Lady Gaga 
@ladygaga
72.2M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.6M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.2M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60M followers














![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP54pUEXoAA7Mb4.png)
![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP53HsIXAAAfmep.jpg)
![1ZRR4H's tweet photo. ⚠️ Threat actors are using the services of drivehq[.]com to distribute malware (#STRRAT and #QRAT were seen).
In the latest campaign they were using names of banks and financial institutions from various parts of the world. Some links can be seen at URLhaus: https://t.co/y7UZC2fcRD.
Sample: "Redbanc-Bankdeposit.txt.jar" (🇨🇱): 993b27eb1194b953d2e9f83a19446241d75cadf11f11a126be273e4aba40e159
Next stages from:
mbycket45344.s3.eu-north-1.amazonaws[.]com
+ https://mbycket45344.s3.eu-north-1.amazonaws[.]com/bn.jar (https://t.co/y1aW5KdPlF)
Other file names:
Abkegypt-Bankdeposit.txt.jar
Accent-Bankdeposit.txt.jar
Acemoneytransfer-Bankdeposit.txt.jar
Alfransi-Bankdeposit.txt.jar
Alsalambahrain-Bankdeposit.txt.jar
Bancobpm-Bankdeposit.txt.jar
Bancolombia-Bankdeposit.txt.jar
Bancosantander-Bankdeposit.txt.jar
Bangkokbank-Bankdeposit.txt.jar
Bankdeposit.txt.jar
Bankofabyssinia-Bankdeposit.txt.jar
Bankofindia-Bankdeposit.txt.jar
Bcdc-Bankdeposit.txt.jar
Bgpb-Bankdeposit.txt.jar
Bmibank-Bankdeposit.txt.jar
Bnpparibas-Bankdeposit.txt.jar
Capgroup-Bankdeposit.txt.jar
Ceat-Bankdeposit.txt.jar
Cedge-Bankdeposit.txt.jar
Cibl-Bankdeposit.txt.jar
Cpm-Bankdeposit.txt.jar
Credit-agricole-Bankdeposit.txt.jar
Creditbank-Bankdeposit.txt.jar
Db-Bankdeposit.txt.jar
Dinarak-Bankdeposit.txt.jar
Donaris-Bankdeposit.txt.jar
Eastnets-Bankdeposit.txt.jar
Eblf-Bankdeposit.txt.jar
Eco-fin-Bankdeposit.txt.jar
Finca-Bankdeposit.txt.jar
Firstdata-Bankdeposit.txt.jar
Fiserv-Bankdeposit.txt.jar
Ftnfinancial-Bankdeposit.txt.jar
Halykbank-Bankdeposit.txt.jar
Hbl-Bankdeposit.txt.jar
Hk-Bankdeposit.txt.jar
Instantcashworldwide-Bankdeposit.txt.jar
Intesasanpaolobank-Bankdeposit.txt.jar
I-transfer-Bankdeposit.txt.jar
Jico-Bankdeposit.txt.jar
Jtrustroyal-Bankdeposit.txt.jar
Kanoo-Bankdeposit.txt.jar
Kaspibank-Bankdeposit.txt.jar
Kh-Bankdeposit.txt.jar
Korona-Bankdeposit.txt.jar
Kotak-Bankdeposit.txt.jar
Kursk-Bankdeposit.txt.jar
Labanquepostale-Bankdeposit.txt.jar
Lariexchange-Bankdeposit.txt.jar
Linkser-Bankdeposit.txt.jar
Madfooat-Bankdeposit.txt.jar
Manliftgroup-Bankdeposit.txt.jar
Mastercard-Bankdeposit.txt.jar
Meridiancu-Bankdeposit.txt.jar
Moneta-Bankdeposit.txt.jar
Nedbank-Bankdeposit.txt.jar
Oracle-Bankdeposit.txt.jar
Orange-Bankdeposit.txt.jar
Paritetbank-Bankdeposit.txt.jar
Pershing-Bankdeposit.txt.jar
Pumaenergy-Bankdeposit.txt.jar
Qsystems-Bankdeposit.txt.jar
Rawbank-Bankdeposit.txt.jar
Redbanc-Bankdeposit.txt.jar
Republicghana-Bankdeposit.txt.jar
Saraswatbank-Bankdeposit.txt.jar
Securitybank-Bankdeposit.txt.jar
Stc-Bankdeposit.txt.jar
Theglobalfund-Bankdeposit.txt.jar
Tinkoff-Bankdeposit.txt.jar
Universalbank-Bankdeposit.txt.jar
Upu-Bankdeposit.txt.jar
Utkarsh-Bankdeposit.txt.jar
Vistabank-Bankdeposit.txt.jar
Vodaclean-Bankdeposit.txt.jar
Warwyckprivatebank-Bankdeposit.txt.jar
Websterbank-Bankdeposit.txt.jar](https://pbs.twimg.com/media/GP53HrrXkAA5qrP.jpg)





