
JAMESWT
@jameswt_wt
#Independent #Malware #Hunter
#CyberSecurity #InfoSec
virustotal.com/gui/user/james…
ID: 3433210978
20-08-2015 19:05:01
52,52K Tweet
36,36K Followers
487 Following


🔍New Blog: JustAskJacky -- AI brings back classical trojan horse malware 🔗gdatasoftware.com/blog/2025/08/3… #GDATA G DATA Global #GDATATechblog




𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 JAMESWT Andrea (Drego) Draghetti 👨🏻💻 🎣 Claudia Gianni Amato TG Soft Germán Fernández Ne0ne | Igal proxylife ShadowOpCode Simplicio Sam L. ANY.RUN Thanks for sharing Erik! I think there are some more C2 IPs connected to this TA: (via pDNS & SMB NetBIOS) virustotal.com/gui/domain/esp… 2025-08-08 - 94.26.90[.245 2025-07-02 - 45.74.10[.38 2025-06-22 - 74.208.226[.175 2025-03-26 - 176.65.144[.162 #AsyncRAT #ResolverRAT #server60929








Amazing reflection on trojans from Karsten Hahn . JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too: AskBettyHow, DailyChefly, GoCookMate, etc. JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com
![Squiblydoo (@squiblydooblog) on Twitter photo Amazing reflection on trojans from <a href="/struppigel/">Karsten Hahn</a> .
JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too:
AskBettyHow, DailyChefly, GoCookMate, etc.
JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com Amazing reflection on trojans from <a href="/struppigel/">Karsten Hahn</a> .
JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too:
AskBettyHow, DailyChefly, GoCookMate, etc.
JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com](https://pbs.twimg.com/media/GyYySH_bgAAooN_.png)






