Top Tweets for #andeloader
🚨We continue to see new lines in #CryptersAndTools #Steganography
Fuzzed two possible URLs delivering the same malware
1013.txt and 1012.txt
#AndeLoader used to load Agent Tesla in RegAsm.exe
mail@detarcoopmedical[.]com
photos@detarcoopmedical[.]com
🇵🇹 used
#TA558 ?
SAMPLE BELOW
![ShadowOpCode's tweet photo. 🚨We continue to see new lines in #CryptersAndTools #Steganography
Fuzzed two possible URLs delivering the same malware
1013.txt and 1012.txt
#AndeLoader used to load Agent Tesla in RegAsm.exe
mail@detarcoopmedical[.]com
photos@detarcoopmedical[.]com
🇵🇹 used
#TA558 ?
SAMPLE BELOW https://t.co/NMbQtjDyJe](https://pbs.twimg.com/media/G3NjX51WkAAfnQS.png)
Next ACCE release is available. See the updates for #CVE20258088 #AndeLoader #INCRansomware #KitsuneRat #MythicAgentsPoseidon https://t.co/nDVLkx9rWp
@JAMESWT_WT @guelfoweb @AndreaDraghetti @VirITeXplorer @1ZRR4H @Max_Mal_ @fr0s7_ similar to what we saw few days ago #andeloader via stego image injects #purelogs into aspnet_compiler.exe
and it seems they like strozzapreti 🍝
https://t.co/ykyHlHYIcb

@anyrun_app @JAMESWT_WT @k3dg3 @500mk500 @skocherhan @VirITeXplorer @guelfoweb @DPesolo @AndreaDraghetti @Certego_Intel @1ZRR4H @c_APT_ure @0xToxin @pr0xylife final payload #purelogs
📡212.23.222[.56: 20341
#purerat injected into aspnet_compiler.exe, downloads #purelogs dubbed ClassLibrary4.dll from c2, which in turn sends stolen info back
malware version: 4.0.1 NEW DAY
@abuse_ch please adjust c2 tag accordly

@MalGamy12 @cod3nym Awesome work, thanks for sharing!
Just a little detail:
.net #loader seems related to #andeloader.
similar infection chain covered here: https://t.co/F68FpwNlJg
sample analyzed more deeply here: https://t.co/xDJqmpJBGR
Check out my recent writeup on #AndeLoader delivering #0bj3ctivityStealer. It's been some time since we last saw AndeLoader popping up ☺️
Link: https://t.co/i8TqvYDUT9

[1/3] multi stage #stego campaign vs #italy 🇮🇹 leads to #xworm rat via #andeloader (h/t @abuse tag: spam-ita @JAMESWT_WT )
mail > 7z > js > ps1 > ande loader from #stego image from archive[.org > b64 #xworm payload from paste[.ee > msbuild.exe
possible #BlindEagle apt-c-36 ? 🤔
![marsomx_'s tweet photo. [1/3] multi stage #stego campaign vs #italy 🇮🇹 leads to #xworm rat via #andeloader (h/t @abuse tag: spam-ita @JAMESWT_WT )
mail > 7z > js > ps1 > ande loader from #stego image from archive[.org > b64 #xworm payload from paste[.ee > msbuild.exe
possible #BlindEagle apt-c-36 ? 🤔 https://t.co/ZTcb3Nw8Z9](https://pbs.twimg.com/media/GpXMshnXIAAdzcj.png)
#BlindEagle APT-C-36 #DcRAT #Threat #Malware
📍🇨🇴
💥🇨🇴🇪🇨🇵🇦🌎
⛓️ #Phishing > UEE|ZIP > EXE > Fake DOC > #vbs > Task Persistence > Download dll + execution > dll download #AndeLoader + #DcRAT > Inject #RAT into RegSvcs > #C2
🔗360 Threat Intelligence: https://t.co/dWLBn3GBNQ

#ThreatProtection New #phishing attack deploys #0bj3ctivity Stealer via #Discord CDN and #AndeLoader. Read More about Symantec's protection: https://t.co/7YCg8gZQAP #InfoStealer
Check out my recent writeup on #AndeLoader delivering #0bj3ctivityStealer. It's been some time since we last saw AndeLoader popping up ☺️
Link: https://t.co/i8TqvYDUT9

Ande Loader Malware Targets Manufacturing Sector in North America https://t.co/TuGpXYtTfH
#Andeloader #loadermalware #malware #manufacturer #northamerica #CyberSecurity #cybersecurite #CybersecurityNews #CyberSecurityAwareness
Checkout my writeup on #PhantomControl delivering #AndeLoader and #SwaetRAT via ScreenConnect. And no, I didn’t misspell SwaetRAT 🤭
https://t.co/lMcyObSxQR
@esthreat

Last Seen Hashtags on Sotwe
momson nolimit filter:videos
Seen from Turkey
Cuckold #cumkiss
Seen from Spain
Teenage nolimit _
Seen from Netherlands
turkifşa
Seen from Turkey
Yüsra Geyik
Seen from Turkey
semlimites
Seen from United States
disabledsex
nolimit #nolimit #momson
Seen from Turkey
thanggom
Seen from United States
exny nolimit nolimit () filter:native_video
Seen from Turkey
Most Popular Users

Elon Musk 
@elonmusk
240.3M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109.6M followers

Narendra Modi 
@narendramodi
106.9M followers

Rihanna 
@rihanna
97.4M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.7M followers

KATY PERRY 
@katyperry
87.2M followers

Taylor Swift 
@taylorswift13
81M followers

Lady Gaga 
@ladygaga
72.6M followers

Kim Kardashian 
@kimkardashian
69.6M followers

Virat Kohli 
@imvkohli
69.1M followers

YouTube 
@youtube
68.6M followers

Bill Gates 
@billgates
63.6M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.8M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60.3M followers

![ShadowOpCode's tweet photo. 🚨We continue to see new lines in #CryptersAndTools #Steganography
Fuzzed two possible URLs delivering the same malware
1013.txt and 1012.txt
#AndeLoader used to load Agent Tesla in RegAsm.exe
mail@detarcoopmedical[.]com
photos@detarcoopmedical[.]com
🇵🇹 used
#TA558 ?
SAMPLE BELOW https://t.co/NMbQtjDyJe](https://pbs.twimg.com/media/G3NjX3ZWkAELKPp.png)
![ShadowOpCode's tweet photo. 🚨We continue to see new lines in #CryptersAndTools #Steganography
Fuzzed two possible URLs delivering the same malware
1013.txt and 1012.txt
#AndeLoader used to load Agent Tesla in RegAsm.exe
mail@detarcoopmedical[.]com
photos@detarcoopmedical[.]com
🇵🇹 used
#TA558 ?
SAMPLE BELOW https://t.co/NMbQtjDyJe](https://pbs.twimg.com/media/G3NjX2-WEAEWOHg.png)
![ShadowOpCode's tweet photo. 🚨We continue to see new lines in #CryptersAndTools #Steganography
Fuzzed two possible URLs delivering the same malware
1013.txt and 1012.txt
#AndeLoader used to load Agent Tesla in RegAsm.exe
mail@detarcoopmedical[.]com
photos@detarcoopmedical[.]com
🇵🇹 used
#TA558 ?
SAMPLE BELOW https://t.co/NMbQtjDyJe](https://pbs.twimg.com/media/G3NjX1nXcAAnZiM.png)






![marsomx_'s tweet photo. [1/3] multi stage #stego campaign vs #italy 🇮🇹 leads to #xworm rat via #andeloader (h/t @abuse tag: spam-ita @JAMESWT_WT )
mail > 7z > js > ps1 > ande loader from #stego image from archive[.org > b64 #xworm payload from paste[.ee > msbuild.exe
possible #BlindEagle apt-c-36 ? 🤔 https://t.co/ZTcb3Nw8Z9](https://pbs.twimg.com/media/GpXMsgjWMAAmWZW.png)
![marsomx_'s tweet photo. [1/3] multi stage #stego campaign vs #italy 🇮🇹 leads to #xworm rat via #andeloader (h/t @abuse tag: spam-ita @JAMESWT_WT )
mail > 7z > js > ps1 > ande loader from #stego image from archive[.org > b64 #xworm payload from paste[.ee > msbuild.exe
possible #BlindEagle apt-c-36 ? 🤔 https://t.co/ZTcb3Nw8Z9](https://pbs.twimg.com/media/GpXMseAWoAAq_lY.png)
![marsomx_'s tweet photo. [1/3] multi stage #stego campaign vs #italy 🇮🇹 leads to #xworm rat via #andeloader (h/t @abuse tag: spam-ita @JAMESWT_WT )
mail > 7z > js > ps1 > ande loader from #stego image from archive[.org > b64 #xworm payload from paste[.ee > msbuild.exe
possible #BlindEagle apt-c-36 ? 🤔 https://t.co/ZTcb3Nw8Z9](https://pbs.twimg.com/media/GpXKvM7XYAAQKw6.jpg)


