Top Tweets for #quantLoader
#Quantloader serving #zeus as part of the latest campaign. b590755cd6fa8ab3d6c5a8702fa41249d3361749b0a0609dc4c0383c76ad5358 #Malienist
![ViriBack's tweet photo. #Malware #quantloader C2 on
very.ruvmp[.]ru/admin/
185.212.130[.]15 https://t.co/5Kyn17r7YY](https://pbs.twimg.com/media/DodLA9QUcAA6myH.jpg)
![ViriBack's tweet photo. New #quantloader #malware instance on
gelmonterom[.]com/admin/
see: https://t.co/JnDdZYCccS https://t.co/Ud3oWCmEXs](https://pbs.twimg.com/media/DgkWnZDVQAAYHY7.jpg)
@Mesiagh @JAMESWT_MHT @avman1995 @NelsonSecurity @executemalware @HazMalware @pollo290987 @_ddoxer @malware_traffic @neonprimetime @Techhelplistcom @dvk01uk @baberpervez2 @malwrhunterteam #quantloader per @ViriBack
https://t.co/klJYxdctjY
different domain it seems.
New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV
![ViriBack's tweet photo. New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV https://t.co/KdBxjFrJrM](https://pbs.twimg.com/media/Dfh33KAXcAAdNv-.jpg)
New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV
![ViriBack's tweet photo. New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV https://t.co/KdBxjFrJrM](https://pbs.twimg.com/media/Dfh33KAXcAAdNv-.jpg)

#Malware #quantloader C2 first seen today...
heroskatopirango[.]com/391f4jda9s/a/admin/
see: https://t.co/ZZxdXEjsfG
![ViriBack's tweet photo. #Malware #quantloader C2 first seen today...
heroskatopirango[.]com/391f4jda9s/a/admin/
see: https://t.co/ZZxdXEjsfG https://t.co/oLP6tFyPz7](https://pbs.twimg.com/media/Dde0RDwVQAALZry.jpg)
New #quantLoader #malware C2 panel seen today:
dada.grantflaskparty[.]com/admin/
see: https://t.co/CzAj4TQQfd
![ViriBack's tweet photo. New #quantLoader #malware C2 panel seen today:
dada.grantflaskparty[.]com/admin/
see: https://t.co/CzAj4TQQfd https://t.co/yh8PcTYKzN](https://pbs.twimg.com/media/DdMhi09VMAAX9AX.jpg)
#Necurs spam botnet actors now using ARS VBS Loader instead of #QuantLoader for #FlawedAmmyy campaigns.
ARS C2: hxxp://untorsnot[.]in/voice/gate[.]php
FlawedAmmyy C2: 169.239.129[.]38:443
Same URL Zip email attachments, downloads ARS VBS via SMB.
![hexlax's tweet photo. #Necurs spam botnet actors now using ARS VBS Loader instead of #QuantLoader for #FlawedAmmyy campaigns.
ARS C2: hxxp://untorsnot[.]in/voice/gate[.]php
FlawedAmmyy C2: 169.239.129[.]38:443
Same URL Zip email attachments, downloads ARS VBS via SMB. https://t.co/gvAUDHB4qb](https://pbs.twimg.com/media/Dbk13c5W4AMGOxE.jpg)
4-20-2018: #QuantLoader #malware campaign
Spam Theme: “Reciba su Factura electrónica” 🇪🇸
Make Build: [84aec3]
Version: [1.53]
✅Block C2:
dackdack[.]online
krkr44[.]club
krkr55[.]club
MD5: cd1634599deef00174d1fa3ca74e9ffa
(h/t @pollo290987)
1.45 diary ->
https://t.co/8eRTmjomPg
![VK_Intel's tweet photo. 4-20-2018: #QuantLoader #malware campaign
Spam Theme: “Reciba su Factura electrónica” 🇪🇸
Make Build: [84aec3]
Version: [1.53]
✅Block C2:
dackdack[.]online
krkr44[.]club
krkr55[.]club
MD5: cd1634599deef00174d1fa3ca74e9ffa
(h/t @pollo290987)
1.45 diary ->
https://t.co/8eRTmjomPg https://t.co/E4FZgT3woY](https://pbs.twimg.com/media/DbNNJC3UQAACnYO.jpg)
Researchers warning of a new email #phishing campaign that downloads & launches #QuantLoader, capable of distributing #ransomware & stealing passwords; spread via @Microsoft url shortcut files that use a variation of CVE-2016-3353 @LindseyOD123 @threatpost https://t.co/LkYQcJQOxr

Watch out for this new #phishing campaign pushing a #trojan capable of distributing #ransomware and stealing passwords. https://t.co/TzMDjBfFcg #QuantLoader
Watch out for this new #phishing campaign pushing a #trojan capable of distributing #ransomware and stealing passwords. https://t.co/TzMDjBxgAQ #QuantLoader
#Malware C2 Panel seen for the first time Today:
#QuantLoader #Pony #AgentTesla #Azorult #ISRStealer
https://t.co/Tmp3GYAraT
cc: @benkow_ @Xylit0l @FourOctets

@IsraSource @virusbay_io This is #quantloader -> #evilammyy:
https://t.co/YgMO77FYLY
you can also just http to the same site.
So, todays "URL" malspam is "Photos from <girl's name>", .url -> .vbs from 169.239.129.25/content or 169.239.129.25/stream. Ibet it will be followed by QuantLoader :-D
#Malicious IP 169.239.128.129 serving #Quantloader and is wierd. Yesterday it had /upload which is down and currently is with /media_source with multiple wsf files

#Necurs #BotNet #MalSpam Pushes #QuantLoader And Follow-Up #Malware - https://t.co/rjlUXYddQY @malware_traffic
➡️
#CyberCrime
#InfoSec
#CyberAttacks
#MalwareAnalysis
#Ransomware
#CyberSecurity
#Pliskal (aka #QuantLoader) is a known family of trojan downloaders. Our analysis of related domains shows that the malware can download a wide range of payloads, including #ransomware, #coinminer, #infostealers, and other threats.
The #spam campaign that delivers .url files in .zip archives is still very active. Today attackers are using “Voice Message” in subject & email body. Yesterday "discount","sale","coupon","offer","promo" were used. But it's the same campaign that leads to #Pliskal (#QuantLoader).

#QuantLoader
VM_04-03-2018_02465.zip
521f052dc581261cb1eef7df1c62f08b
Subject: Voice Message from Outside Caller (1m 51s)
Payload
pfm-traduction,com GET /iUyfemds7??NtmaDOcTl=NtmaDOcTl

Last Seen Hashtags on Sotwe
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109.4M followers

Narendra Modi 
@narendramodi
106.9M followers

Rihanna 
@rihanna
97.4M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.7M followers

KATY PERRY 
@katyperry
87.1M followers

Taylor Swift 
@taylorswift13
80.9M followers

Lady Gaga 
@ladygaga
72.5M followers

Kim Kardashian 
@kimkardashian
69.5M followers

Virat Kohli 
@imvkohli
69M followers

YouTube 
@youtube
68.6M followers

Bill Gates 
@billgates
63.5M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.6M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60.2M followers



![ViriBack's tweet photo. New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV https://t.co/KdBxjFrJrM](https://pbs.twimg.com/media/Dfh3WyxXUAEaLFM.jpg)


![VK_Intel's tweet photo. 4-20-2018: #QuantLoader #malware campaign
Spam Theme: “Reciba su Factura electrónica” 🇪🇸
Make Build: [84aec3]
Version: [1.53]
✅Block C2:
dackdack[.]online
krkr44[.]club
krkr55[.]club
MD5: cd1634599deef00174d1fa3ca74e9ffa
(h/t @pollo290987)
1.45 diary ->
https://t.co/8eRTmjomPg https://t.co/E4FZgT3woY](https://pbs.twimg.com/media/DbNNHdzUwAASUS2.jpg)










