Temporary Advertisements:
Ad
Ad
Ad
LEAKED C2 SERVER POWERSHELL CODE
by DOJ - Wednesday June 28, 2023 at 10:54 PM
#11
Interesting. thanks
Reply
#12
Thanks for sharing
Reply
#13
(Jun 28, 2023, 10:54 PM)DOJ Wrote: The PoshC2 server showed in a previous thread (https://bf.st/Thread-Ransomware-Actor-Le...n-Internet) had a second stage powershell script that I've reorganized and commented (noob-friendly). Enjoy!

thank you for this
Reply
#14
lets see whats here

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#15
thanks comrade, best regards
Reply
#16
just dug up the C2 server's IP for this botnet. It's 95.213.145.101. Heads up, it's dodging pings, so don't waste your time there.
Quick rundown of the op:

Cert Validation Bypass: Script blows past SSL cert checks. No surprise there, just letting anything through.
C2 IP: Main address is 95.213.145.101, hitting up /wpaas/load.php/
for the payload.
Encryption Key: Comms are wrapped up tight with this key:
qwp0r0wXGPOeyFtIdP6qDHZCynQmtPzP6xkC3xX9sAc=
Good luck intercepting without it.
Payload Ops: Grabs the payload from the C2, decrypts, and runs it if it spots a "key" in there. Could be anything nasty.
Staying Hidden: Configures a web client, sets headers, maybe uses a proxy. Keeps trying to get the payload, doubling wait time between each attempt (30 tries max).
Reply
#17
(Jun 21, 2024, 10:42 AM)PulseCipher Wrote: just dug up the C2 server's IP for this botnet. It's 95.213.145.101. Heads up, it's dodging pings, so don't waste your time there.
Quick rundown of the op:

Cert Validation Bypass: Script blows past SSL cert checks. No surprise there, just letting anything through.
C2 IP: Main address is 95.213.145.101, hitting up /wpaas/load.php/
for the payload.
Encryption Key: Comms are wrapped up tight with this key:
qwp0r0wXGPOeyFtIdP6qDHZCynQmtPzP6xkC3xX9sAc=
Good luck intercepting without it.
Payload Ops: Grabs the payload from the C2, decrypts, and runs it if it spots a "key" in there. Could be anything nasty.
Staying Hidden: Configures a web client, sets headers, maybe uses a proxy. Keeps trying to get the payload, doubling wait time between each attempt (30 tries max).

This is good - nice work
Reply
#18
(Jun 21, 2024, 11:27 AM)Unethical Wrote:
(Jun 21, 2024, 10:42 AM)PulseCipher Wrote: just dug up the C2 server's IP for this botnet. It's 95.213.145.101. Heads up, it's dodging pings, so don't waste your time there.
Quick rundown of the op:

Cert Validation Bypass: Script blows past SSL cert checks. No surprise there, just letting anything through.
C2 IP: Main address is 95.213.145.101, hitting up /wpaas/load.php/
for the payload.
Encryption Key: Comms are wrapped up tight with this key:
qwp0r0wXGPOeyFtIdP6qDHZCynQmtPzP6xkC3xX9sAc=
Good luck intercepting without it.
Payload Ops: Grabs the payload from the C2, decrypts, and runs it if it spots a "key" in there. Could be anything nasty.
Staying Hidden: Configures a web client, sets headers, maybe uses a proxy. Keeps trying to get the payload, doubling wait time between each attempt (30 tries max).

This is good - nice work

Thanks!
Reply
#19
(Jun 28, 2023, 10:54 PM)DOJ Wrote: The PoshC2 server showed in a previous thread (https://bf.st/Thread-Ransomware-Actor-Le...n-Internet) had a second stage powershell script that I've reorganized and commented (noob-friendly). Enjoy!

For real let me see, let me see, side bro let me go first?
Reply
#20
(Jun 21, 2024, 03:15 PM)DaddyIamGayy Wrote:
(Jun 28, 2023, 10:54 PM)DOJ Wrote: The PoshC2 server showed in a previous thread (https://bf.st/Thread-Ransomware-Actor-Le...n-Internet) had a second stage powershell script that I've reorganized and commented (noob-friendly). Enjoy!

For real let me see, let me see, side bro let me go first?
I already reversed the whole thing  -_-
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  How to purchase monero without KYC? sakes 1 231 Yesterday, 06:41 PM
Last Post: nanobanana
  Discord Spyware 1926 165 17,370 Sep 18, 2026, 11:03 AM
Last Post: iwalkwghosts
  Instagram Spyware Level: EXTREMELY HIGH 1926 270 22,963 Sep 16, 2026, 08:33 AM
Last Post: kingodysseus
  Cards without VBV | PayPal accounts with balance + PayPal transfers | Cloned cards+Wu yelenatan 3 343 Sep 14, 2026, 02:24 PM
Last Post: Gellan
  Canada Atm Clone cards / Australian clone cards / European ATM Clone cards ⏩ ATM Card 28kaila 0 164 Sep 14, 2026, 09:45 AM
Last Post: 28kaila

Forum Jump:


 Users browsing this forum: