Top Tweets for #quantloader
#Quantloader serving #zeus as part of the latest campaign. b590755cd6fa8ab3d6c5a8702fa41249d3361749b0a0609dc4c0383c76ad5358 #Malienist
![ViriBack's tweet photo. #Malware #quantloader C2 on
very.ruvmp[.]ru/admin/
185.212.130[.]15 https://t.co/5Kyn17r7YY](https://pbs.twimg.com/media/DodLA9QUcAA6myH.jpg)
![ViriBack's tweet photo. New #quantloader #malware instance on
gelmonterom[.]com/admin/
see: https://t.co/JnDdZYCccS https://t.co/Ud3oWCmEXs](https://pbs.twimg.com/media/DgkWnZDVQAAYHY7.jpg)
@Mesiagh @JAMESWT_MHT @avman1995 @NelsonSecurity @executemalware @HazMalware @pollo290987 @_ddoxer @malware_traffic @neonprimetime @Techhelplistcom @dvk01uk @baberpervez2 @malwrhunterteam #quantloader per @ViriBack
https://t.co/klJYxdctjY
different domain it seems.
New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV
![ViriBack's tweet photo. New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV https://t.co/KdBxjFrJrM](https://pbs.twimg.com/media/Dfh33KAXcAAdNv-.jpg)
New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV
![ViriBack's tweet photo. New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV https://t.co/KdBxjFrJrM](https://pbs.twimg.com/media/Dfh33KAXcAAdNv-.jpg)

#Malware #quantloader C2 first seen today...
heroskatopirango[.]com/391f4jda9s/a/admin/
see: https://t.co/ZZxdXEjsfG
![ViriBack's tweet photo. #Malware #quantloader C2 first seen today...
heroskatopirango[.]com/391f4jda9s/a/admin/
see: https://t.co/ZZxdXEjsfG https://t.co/oLP6tFyPz7](https://pbs.twimg.com/media/Dde0RDwVQAALZry.jpg)
New #quantLoader #malware C2 panel seen today:
dada.grantflaskparty[.]com/admin/
see: https://t.co/CzAj4TQQfd
![ViriBack's tweet photo. New #quantLoader #malware C2 panel seen today:
dada.grantflaskparty[.]com/admin/
see: https://t.co/CzAj4TQQfd https://t.co/yh8PcTYKzN](https://pbs.twimg.com/media/DdMhi09VMAAX9AX.jpg)
#Necurs spam botnet actors now using ARS VBS Loader instead of #QuantLoader for #FlawedAmmyy campaigns.
ARS C2: hxxp://untorsnot[.]in/voice/gate[.]php
FlawedAmmyy C2: 169.239.129[.]38:443
Same URL Zip email attachments, downloads ARS VBS via SMB.
![hexlax's tweet photo. #Necurs spam botnet actors now using ARS VBS Loader instead of #QuantLoader for #FlawedAmmyy campaigns.
ARS C2: hxxp://untorsnot[.]in/voice/gate[.]php
FlawedAmmyy C2: 169.239.129[.]38:443
Same URL Zip email attachments, downloads ARS VBS via SMB. https://t.co/gvAUDHB4qb](https://pbs.twimg.com/media/Dbk13c5W4AMGOxE.jpg)
4-20-2018: #QuantLoader #malware campaign
Spam Theme: “Reciba su Factura electrónica” 🇪🇸
Make Build: [84aec3]
Version: [1.53]
✅Block C2:
dackdack[.]online
krkr44[.]club
krkr55[.]club
MD5: cd1634599deef00174d1fa3ca74e9ffa
(h/t @pollo290987)
1.45 diary ->
https://t.co/8eRTmjomPg
![VK_Intel's tweet photo. 4-20-2018: #QuantLoader #malware campaign
Spam Theme: “Reciba su Factura electrónica” 🇪🇸
Make Build: [84aec3]
Version: [1.53]
✅Block C2:
dackdack[.]online
krkr44[.]club
krkr55[.]club
MD5: cd1634599deef00174d1fa3ca74e9ffa
(h/t @pollo290987)
1.45 diary ->
https://t.co/8eRTmjomPg https://t.co/E4FZgT3woY](https://pbs.twimg.com/media/DbNNJC3UQAACnYO.jpg)
Researchers warning of a new email #phishing campaign that downloads & launches #QuantLoader, capable of distributing #ransomware & stealing passwords; spread via @Microsoft url shortcut files that use a variation of CVE-2016-3353 @LindseyOD123 @threatpost https://t.co/LkYQcJQOxr

Watch out for this new #phishing campaign pushing a #trojan capable of distributing #ransomware and stealing passwords. https://t.co/TzMDjBfFcg #QuantLoader
Watch out for this new #phishing campaign pushing a #trojan capable of distributing #ransomware and stealing passwords. https://t.co/TzMDjBxgAQ #QuantLoader
#Malware C2 Panel seen for the first time Today:
#QuantLoader #Pony #AgentTesla #Azorult #ISRStealer
https://t.co/Tmp3GYAraT
cc: @benkow_ @Xylit0l @FourOctets

@IsraSource @virusbay_io This is #quantloader -> #evilammyy:
https://t.co/YgMO77FYLY
you can also just http to the same site.
So, todays "URL" malspam is "Photos from <girl's name>", .url -> .vbs from 169.239.129.25/content or 169.239.129.25/stream. Ibet it will be followed by QuantLoader :-D
#Malicious IP 169.239.128.129 serving #Quantloader and is wierd. Yesterday it had /upload which is down and currently is with /media_source with multiple wsf files

#Necurs #BotNet #MalSpam Pushes #QuantLoader And Follow-Up #Malware - https://t.co/rjlUXYddQY @malware_traffic
➡️
#CyberCrime
#InfoSec
#CyberAttacks
#MalwareAnalysis
#Ransomware
#CyberSecurity
#Pliskal (aka #QuantLoader) is a known family of trojan downloaders. Our analysis of related domains shows that the malware can download a wide range of payloads, including #ransomware, #coinminer, #infostealers, and other threats.
The #spam campaign that delivers .url files in .zip archives is still very active. Today attackers are using “Voice Message” in subject & email body. Yesterday "discount","sale","coupon","offer","promo" were used. But it's the same campaign that leads to #Pliskal (#QuantLoader).

#QuantLoader
VM_04-03-2018_02465.zip
521f052dc581261cb1eef7df1c62f08b
Subject: Voice Message from Outside Caller (1m 51s)
Payload
pfm-traduction,com GET /iUyfemds7??NtmaDOcTl=NtmaDOcTl

Last Seen Hashtags on Sotwe
19minutes
Seen from United Kingdom
public sục cặc
Seen from Vietnam
минет
ivetpetcare
Seen from Netherlands
بدويات
Seen from France
Diyarbakirtravesti
Seen from Turkey
boahancock
Seen from Thailand
bops
Seen from United States
desahancewek #moancewek
Seen from Indonesia
horny
Seen from United States
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109.5M followers

Narendra Modi 
@narendramodi
106.9M followers

Rihanna 
@rihanna
97.4M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.7M followers

KATY PERRY 
@katyperry
87.1M followers

Taylor Swift 
@taylorswift13
80.9M followers

Lady Gaga 
@ladygaga
72.5M followers

Kim Kardashian 
@kimkardashian
69.5M followers

Virat Kohli 
@imvkohli
69M followers

YouTube 
@youtube
68.6M followers

Bill Gates 
@billgates
63.5M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.6M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60.2M followers



![ViriBack's tweet photo. New #quantloader first seen today. #Malware #opendir on same domain.
usuf[.]top/q/admin/
see: https://t.co/Z9cmByE9CV https://t.co/KdBxjFrJrM](https://pbs.twimg.com/media/Dfh3WyxXUAEaLFM.jpg)


![VK_Intel's tweet photo. 4-20-2018: #QuantLoader #malware campaign
Spam Theme: “Reciba su Factura electrónica” 🇪🇸
Make Build: [84aec3]
Version: [1.53]
✅Block C2:
dackdack[.]online
krkr44[.]club
krkr55[.]club
MD5: cd1634599deef00174d1fa3ca74e9ffa
(h/t @pollo290987)
1.45 diary ->
https://t.co/8eRTmjomPg https://t.co/E4FZgT3woY](https://pbs.twimg.com/media/DbNNHdzUwAASUS2.jpg)










