Sign in

James_inthe_box

@james-inthe-box.infosec.exchange.ap.brid.gy
38 followers 0 following 267 posts

#malware [bridged from infosec.exchange/@james_inthe_box on the fediverse by fed.brid.gy ]

PostsRepliesMedia
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 06/10/2026
A new one on me.. #lxbaserat: app.any.run/tasks/a434d238-8a9a-4df… c2: 64.89.160\\.127:4561
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 06/10/2026
#xworm #opendir at: 107.173.143\\.44/60 c2: 151.241.154\\.23:7007
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 01/10/2026
A csv formatted list of #malspam campaigns that crossed my path in September to include subject, #malware type, c2, hash, and email efil addresses: gist.github.com/silence-is-best/8f9… #retohunt
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 30/09/2026
Fresh #unknown #stealer: app.any.run/tasks/c46c99a4-8b08-4b0… 1eb51e82267b2ea1d3216919dbac9d5297ca8565baf8e39ccfc07323136b1849 C:\Users\lakup\Documents\dev_tools\LARP HERE\Studio\client.pdb
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 28/09/2026
Fresh #salsastealer: app.any.run/tasks/fcd555b3-6b72-4c9…
app.any.run
Analysis client_build (4).exe (MD5: F18DB04DB93BE41A63BE4F643944CE08) Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
110
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 28/09/2026
#remcos #powershell (albeit broken) #opendir at: https:// delphiaonline\\.top c2 dmsi\\.duckdns\\.org:14642 9d9f149a0052999587be2078375bb4530b351f3cda1b343c7f81a5d13b02ac45
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 24/09/2026
#asyncrat #darkcrystal #opendir at: https:// interactions-according-reports-syndication\\.trycloudflare.com https:// periods-genetic-stones-government\\.trycloudflare.com
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 22/09/2026
A new one on me.. (apparently) something called #hydra_kl #stealer #clipper #hvnc app.any.run/tasks/7dfd881f-dc86-41a… 2c530f2e10db77881730e7a9ec4e72244d59149fc8981a4f49c6e0fadc5fecee
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 17/09/2026
To the threat actor that has found my personal email address and has started sending malicious office documents: THANK YOU!!! IT'S LIKE CHRISTMAS UP IN HERE 🤗
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 16/09/2026
"All large-scale AI's eventually go insane." Dungeon Crawler Carl, The Gate of the Feral Gods Apt.
031
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 16/09/2026
The usual suspects (only looked at the #dcrat one) at: https:// interactions-according-reports-syndication.trycloudflare\\.com https:// periods-genetic-stones-government.trycloudflare\\.com
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 09/09/2026
New one on me... #haze #stealer: app.any.run/tasks/efd789a0-24c2-4bf… c2: api\\.hazexd\\.lol
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 09/09/2026
Couple #screenconnect droppers at: https:// doc. papperldoculess\\.top/edocument/
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 08/09/2026
If you're running into malicious #meshagent in #malspams, keep an eye on the .msh file for details:
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 06/09/2026
f you're using any of those Monster A19 wifi lightbulbs (monsterilluminessence . com) be aware your data appears to be going to @splunk cloud.
115
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 04/09/2026
#purelogslealer at: https:// gaiadeqi\\.com/scrapbookpocketfordraf.exe Same tired old c2 of 2.27.62.123:4449
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 04/09/2026
While browser makers are edging out #ublockorigin , ublockorigin keeps getting better:
1415
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 03/09/2026
Heh.. #ChatGPT down...again
010
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 02/09/2026
#unknown panels at: 108.165.15\\.70/view/view.php 169.58.168\\.28:3847
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 02/09/2026
#originlogger payloads (encrypted) at: https:// munihuacho\\.gob\\.pe/documentos/
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 01/09/2026
Remember kids, companies that commit crimes, create LLM's that commit crimes: www.dwarkesh.com/p/openai-huggingfa…
dwarkesh.com
The Rise and Fall of Agent Civilizations
The whole OpenAI/Hugging Face story in plain English
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 01/09/2026
A csv formatted list of #malspam campaigns that crossed my path in August to include subject, #malware type, c2, hash, and email exfil addresses: gist.github.com/silence-is-best/df9… #retrohunt
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 01/09/2026
If you're not blocking workers . dev at the proxy/perimeter, it's long overdue.
001
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 28/08/2026
#Clickfix initial payloads at: https:// github. com/snowplow-byte/ #stealer still unknown sadly exe hash: 70bf0a8c0ffe5d1aa51358aba0ae365a1fab15cc356a02c07a36de6427e3ca7f
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 28/08/2026
Yet another cheesy #RMM at: https:// github\\.com/Drealplug #heartbeatRM c2: controllers-us-west-2.heartbeatrm\\.com
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 24/08/2026
From #clickfix to #vidar app.any.run/tasks/8c61ec50-7b6d-419… app.any.run/tasks/14657cfb-4f8b-4b8… c2 on the #vidar https:// www.figma\\.com
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 21/08/2026
Since people trust LLM's known to hallucinate, does that mean I can drop acid at work?
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 19/08/2026
A new one on me: #SheetRAT : app.any.run/tasks/e84e434d-5d60-486…
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 18/08/2026
A debloated (from 989 megs) #remus #stealer app.any.run/tasks/54216fca-8c55-4c4… c2 of spirkex\\.click is 5 days old.
app.any.run
Analysis Bооtsехеc64_patched.exe (MD5: 37B764D102B3726D28131BA8B9068926) Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 13/08/2026
New one on me: #pentagon #stealer app.any.run/tasks/f8db9ea6-b48a-4f6…
000
Reposted by James_inthe_box
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 10/08/2026
I've published part one of a two-part blog series: Locking down Windows Part 1: Harden System Security Consider this the warm-up round. Part two will cover the way to truly lock down Windows: App Control (WDAC)
tharros.com
Locking down Windows Part 1: Harden System Security
225
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 10/08/2026
A 4 day old #diamotrox #stealc app.any.run/tasks/11ed2038-8f36-49d…
app.any.run
Analysis CC Gen & Checker.exe (MD5: 121531CB07077F91DEFEEA5BBE43F436) Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 07/08/2026
#faronics (yet another rmm by the look of it) at: https:// aerrixon .com/filee.html -> https:// mustafacorp .com/ref/2026Statement.exe
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 05/08/2026
Some 2 day old #valleyrat app.any.run/tasks/7a1480fa-e0fc-4e1…
app.any.run
Analysis https://app.box.com/index.php?rm=box_download_shared_file&shared_name=bvbw2k6rxrhqpkto4dxowmrwygjw0u2m&file_id=f_2388383773736 Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 05/08/2026
PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure. 1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 05/08/2026
An interesting development with #PureLogStealer ....seen this twice now where the Edge flag is invalid: app.any.run/tasks/992252ed-c867-4ad…
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 03/08/2026
A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses: gist.github.com/silence-is-best/48b… #retrohunt
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 01/08/2026
In light of recent LLM's breaking out of their guardrails and doing damage, I felt compelled to write this. gist.github.com/silence-is-best/e8f…
010
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 31/07/2026
Handful of IOC's for those .js #purelogs #stealer #malspams: app.any.run/tasks/43e561e4-707a-418… Exfil port is 4449 Calls hidden Edge Calls hidden Chrome
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 27/07/2026
#xloader 's (c6713b3c5ba4da5044d96463cae74227a6a898abb051a5f75ab7b508eb20f7e1) choice of which executable to inject into continues to fascinate me...
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 20/07/2026
#clickfix to #vidar (among other things) via: http:// www\\.apcconstruction\\.com/ app.any.run/tasks/4599dbb0-1041-43f…
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 17/07/2026
#phantomstealer dropping #chomelevator app.any.run/tasks/65f964b6-9585-4ec… exfils to mail.trimnt\\.com
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 16/07/2026
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni: gist.github.com/silence-is-best/29a… app.any.run/tasks/73887f39-a8ac-470… cc @da_667
110
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 16/07/2026
#remcos hta and payload in an #opendir at: 157.254.223\\.141/25
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 08/07/2026
Some fresh #raton app.any.run/tasks/d020658f-dbca-4a1… C:\Users\Cristian\Desktop\NewRaton\DONOTDELETE\Commands.pdb
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 07/07/2026
#medusahvnc in a js -> autoit: app.any.run/tasks/86ddc895-ed72-4ea…
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 02/07/2026
From #clickfix -> #vidar app.any.run/tasks/dac83ca5-fa36-447…
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 02/07/2026
Fresh #purerat : app.any.run/tasks/4bd07f35-3a29-477… cc @da_667
100
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 01/07/2026
A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses: gist.github.com/silence-is-best/247… #retrohunt
000
James_inthe_box @james-inthe-box.infosec.exchange.ap.brid.gy · 17/06/2026
Yet another shady #RMM; this time @Automox at: https:// ecdp.ronaldegesa\\.com/Automox_Installer-2.5.70.msi threat actor access key is c9af8abb-3be8-432d-b651-6da4df3e35a6
000