Who said what? (@g0njxa) 's Twitter Profile
Who said what?

@g0njxa

qui fa lo que pot no esta obligat a mes | donate 💸 to g0njxa.eth 💖 | Bad student, enthusiast, defo not an expert

DMs are open, feel free to reach!
😼☂️🟣

ID: 1620126347338080267

calendar_today30-01-2023 18:28:26

3,3K Tweet

4,4K Followers

100 Following

RussianPanda 🐼 🇺🇦 (@russianpanda9xx) 's Twitter Profile Photo

Presenting the #Wagmi traffer group (Героев нужно знать в лицо). Collaborated with Who said what? on this blog to raise awareness about these widespread scams on X, Discord, and other platforms. Too many people are falling victim, putting millions in the hands of threat actors. Stay

Presenting the #Wagmi traffer group (Героев нужно знать в лицо).

Collaborated with <a href="/g0njxa/">Who said what?</a> on this blog to raise awareness about these widespread scams on X, Discord, and other platforms. Too many people are falling victim, putting millions in the hands of threat actors. Stay
Who said what? (@g0njxa) 's Twitter Profile Photo

For an unknown reason, Stealc_v2 decided to set up a fake 404 error on their C2 servers to make us easier to track them 😜 Hunt for Stealc_v2 on FofaBot: en.fofa.info/result?qbase64… Example: 91.92.46.133 95.216.107.55 77.105.164.183 157.180.8.71 198.251.84.107 62.113.118.58

For an unknown reason, Stealc_v2 decided to set up a fake 404 error on their C2 servers to make us easier to track them 😜

Hunt for Stealc_v2 on <a href="/fofabot/">FofaBot</a>:
en.fofa.info/result?qbase64…

Example:
91.92.46.133
95.216.107.55
77.105.164.183
157.180.8.71
198.251.84.107
62.113.118.58
RussianPanda 🐼 🇺🇦 (@russianpanda9xx) 's Twitter Profile Photo

Autopsy of a Failed Stealer: StealC v2 When Your $3000 Malware Budget Goes to Marketing Instead of Actually Enabling the Encryption Function I did some analysis on the updated #StealC v2. The blog comes with config extractor, hunting queries and Yara rule. Let me know your

Autopsy of a Failed Stealer: StealC v2
When Your $3000 Malware Budget Goes to Marketing Instead of Actually Enabling the Encryption Function

I did some analysis on the updated #StealC v2. The blog comes with config extractor, hunting queries and Yara rule. Let me know your
Who said what? (@g0njxa) 's Twitter Profile Photo

Fresh #Clickfix design campaign spreading #Lumma stealer on X ads impersonating AI sites /newflave.rf.gd /gltgirl.rf.gd Payload: /kutt.it/ReStarT >> /snippet.host/migppg Build hosted on Azure DevOps repo Detonation: app.any.run/tasks/617fda4e…

Fresh #Clickfix design campaign spreading #Lumma stealer on X ads impersonating AI sites

/newflave.rf.gd
/gltgirl.rf.gd

Payload: /kutt.it/ReStarT &gt;&gt; /snippet.host/migppg

Build hosted on Azure DevOps repo

Detonation: app.any.run/tasks/617fda4e…
Who said what? (@g0njxa) 's Twitter Profile Photo

StealC v2 infostealer updated recently: featuring "decryption of Google Chrome v135 passwords" and also removing the thing we reported days before 😜x.com/g0njxa/status/…

StealC v2 infostealer updated recently:

featuring "decryption of Google Chrome v135 passwords"

and also removing the thing we reported days before 😜x.com/g0njxa/status/…
Who said what? (@g0njxa) 's Twitter Profile Photo

In the last days a secondary C2 panel from private #Odyssey Stealer for MacOS has appeared in the wild 🍎 /88.214.50.3 - new one Dee sample: 34259547171d840973bce9ddd2d87bbf previous known: /185.147.124.212

In the last days a secondary C2 panel from private #Odyssey Stealer for MacOS has appeared in the wild 🍎

/88.214.50.3 - new one <a href="/ViriBack/">Dee</a> 

sample: 34259547171d840973bce9ddd2d87bbf

previous known: /185.147.124.212
Who said what? (@g0njxa) 's Twitter Profile Photo

Today I've suffered from a major blackout due to a nationwide power outage in Spain since ~10:30 AM UTC Mobile network is still down, electricity returned a few moments ago. The situation was good but doubtful. I'm waiting for an official report on the incident.