Skip to content

PROBABLY_PENTEST (1) campaign cataloged at 2024-09-16(2).

  1. Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2024-09-old-discself

Package suggests a code to build bots; however, the code just exfiltrates the token given by the user to the hardcoded Discord webhook. Looking at other activity on the account, it's either research or forgotten WIP/test.

Abuse categories

Campaign uses .

action-hidden-in-lib-usage

Campaign uses action-hidden-in-lib-usage.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • hxxps://discord.com/api/webhooks/912467064164323348/5wRkOV95qAwWdY4KBmbO9-3d2tf4FrSE4R2i7LWGyzfEevzi0xvKaJmLo-Z_AN0OFqGh

Packages in the campaign

campaign:2024-09-old-discself