PULSE NAME
Stealer Malware (Hash / C2)
WHITE IndoOpenThreatXchange 2024-07-24 Modified: 2025-01-15
802
IOCs
HIGH VOLUME
Malware that stealing capabilities like Vidar, Raccoon, Mars, and Redline (will update in the future). any detection from internal network from this otx pulse indicates data leak. please fullscan your endpoint using antivirus and make sure change your all password. Family : Steal C Malware; Redline Stealer; Flame Stealer; Lumma Stealer; Cheana Stealer; Gomorra Stealer; Meduza Stealer; Hawkeye Malware; Node Stealer; Amatera Stealer ; Last Update : 16/12/2024 (Update Lumma Stealer, Add Amatera Stealer, Telegram Stealer and other)
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (9 / 802 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname URL
TYPEINDICATORDESCRIPTIONCREATED
URL https://secure.biiclick.com/webpanel/Panel/login.php 2024-09-23
URL http://customer.sellauth.com/nelsy/login 2024-12-13
URL http://covery-mover.biz/api 2024-12-16
URL http://dare-curbys.biz/api 2024-12-16
URL http://formy-spill.biz/api 2024-12-16
URL http://impend-differ.biz/api 2024-12-16
URL http://print-vexer.biz/api 2024-12-16
URL http://mega.nz/file/TNYwhRzb#XXGrmz1Cq8Tv_lQUDGlmPhwlxvnQudOZ2x1Noul-_bI 2024-12-16
URL http://mega.nz/file/SYh1XRDS#4kLOAEiNWwzgcbxtSXAGMZpSzd_3UM04VigOdf10a8Q 2024-12-16