Skip to content

MALICIOUS (1) campaign cataloged at 2024-10-27(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2024-10-kekiktaban

Obfuscated package containing multiple techniques detecting sandboxing and exfiltrating basic data to a telegram webhook, with a little other functionality

Abuse categories

basic_exfiltration

The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

obfuscation

Campaign uses obfuscation.

webhook:telegram

A Telegram webhook is used to send collected data.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • hxxps://gist.github.com/keyiflerolsun/5127472bed55917e8945bf8699cc844a

Packages in the campaign

campaign:2024-10-kekiktaban