PROBABLY_PENTEST (1) campaign cataloged at 2024-09-16(2).
- Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2024-09-old-discself¶
Package suggests a code to build bots; however, the code just exfiltrates the token given by the user to the hardcoded Discord webhook. Looking at other activity on the account, it's either research or forgotten WIP/test.
Abuse categories¶
Campaign uses .
action-hidden-in-lib-usage
Campaign uses action-hidden-in-lib-usage.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
hxxps://discord.com/api/webhooks/912467064164323348/5wRkOV95qAwWdY4KBmbO9-3d2tf4FrSE4R2i7LWGyzfEevzi0xvKaJmLo-Z_AN0OFqGh