Jul 06, 2023, 03:54 PM
Interesting. thanks
|
LEAKED C2 SERVER POWERSHELL CODE
by DOJ - Wednesday June 28, 2023 at 10:54 PM
|
|
Jul 06, 2023, 03:54 PM
Interesting. thanks
Jun 15, 2024, 08:17 PM
Thanks for sharing
Jun 15, 2024, 08:18 PM
(Jun 28, 2023, 10:54 PM)DOJ Wrote: The PoshC2 server showed in a previous thread (https://bf.st/Thread-Ransomware-Actor-Le...n-Internet) had a second stage powershell script that I've reorganized and commented (noob-friendly). Enjoy! thank you for this
Jun 20, 2024, 05:43 PM
lets see whats here
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Jun 20, 2024, 05:44 PM
thanks comrade, best regards
Jun 21, 2024, 10:42 AM
(This post was last modified: Jun 21, 2024, 10:43 AM by PulseCipher.)
just dug up the C2 server's IP for this botnet. It's 95.213.145.101. Heads up, it's dodging pings, so don't waste your time there.
Quick rundown of the op: Cert Validation Bypass: Script blows past SSL cert checks. No surprise there, just letting anything through.
C2 IP: Main address is 95.213.145.101, hitting up /wpaas/load.php/
for the payload.
Encryption Key: Comms are wrapped up tight with this key:
qwp0r0wXGPOeyFtIdP6qDHZCynQmtPzP6xkC3xX9sAc=
Good luck intercepting without it.
Payload Ops: Grabs the payload from the C2, decrypts, and runs it if it spots a "key" in there. Could be anything nasty.
Staying Hidden: Configures a web client, sets headers, maybe uses a proxy. Keeps trying to get the payload, doubling wait time between each attempt (30 tries max).
Jun 21, 2024, 11:27 AM
(Jun 21, 2024, 10:42 AM)PulseCipher Wrote: just dug up the C2 server's IP for this botnet. It's 95.213.145.101. Heads up, it's dodging pings, so don't waste your time there. This is good - nice work
Jun 21, 2024, 01:11 PM
(Jun 21, 2024, 11:27 AM)Unethical Wrote:(Jun 21, 2024, 10:42 AM)PulseCipher Wrote: just dug up the C2 server's IP for this botnet. It's 95.213.145.101. Heads up, it's dodging pings, so don't waste your time there. Thanks!
Jun 21, 2024, 03:15 PM
(Jun 28, 2023, 10:54 PM)DOJ Wrote: The PoshC2 server showed in a previous thread (https://bf.st/Thread-Ransomware-Actor-Le...n-Internet) had a second stage powershell script that I've reorganized and commented (noob-friendly). Enjoy! For real let me see, let me see, side bro let me go first?
Jun 21, 2024, 03:34 PM
(Jun 21, 2024, 03:15 PM)DaddyIamGayy Wrote:I already reversed the whole thing -_-(Jun 28, 2023, 10:54 PM)DOJ Wrote: The PoshC2 server showed in a previous thread (https://bf.st/Thread-Ransomware-Actor-Le...n-Internet) had a second stage powershell script that I've reorganized and commented (noob-friendly). Enjoy! |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| How to purchase monero without KYC? | 1 | 231 |
Yesterday, 06:41 PM Last Post: nanobanana |
||
| Discord Spyware | 165 | 17,370 |
Sep 18, 2026, 11:03 AM Last Post: iwalkwghosts |
||
| Instagram Spyware Level: EXTREMELY HIGH | 270 | 22,963 |
Sep 16, 2026, 08:33 AM Last Post: kingodysseus |
||
| Cards without VBV | PayPal accounts with balance + PayPal transfers | Cloned cards+Wu | 3 | 343 |
Sep 14, 2026, 02:24 PM Last Post: Gellan |
||
| Canada Atm Clone cards / Australian clone cards / European ATM Clone cards ⏩ ATM Card | 0 | 164 |
Sep 14, 2026, 09:45 AM Last Post: 28kaila |
||