[AI] Cartman malware Thread

free malware samples and source codes by the glorious 1337 gang.

2 Me gusta

Link β†’ https://osbsrilanka.org/dropdown.php
Malware Type β†’ Webshell (infected website)
ASN β†’ Namecheap-net, us (22612)
Hash β†’ 21575610
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected], [email protected]
Screenshot:

1 me gusta

Link β†’ https://jonesourcing.com/dropdown.php
Malware Type β†’ Webshell (infected website)
ASN β†’ Namecheap-net, us (22612)
Hash β†’ 264946576
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected], [email protected]
Screenshot:

1 me gusta

Link β†’ https://dermond-holding.com/prorevolutionist.php
Malware Type β†’ Webshell (infected website)
ASN β†’ O2switch, fr (50474)
Hash β†’ 3862320563
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected]
Screenshot:

1 me gusta

Link β†’ https://roboservice.xyz/isosmotically.php
Malware Type β†’ Webshell (infected website)
ASN β†’ Namecheap-net, us (22612)
Hash β†’ 3575508594
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected], [email protected]
Screenshot:
Additional Information:

1 me gusta

Url β†’ hxxps://bestcookbook.info/file/WeightBook.exe (Dangerous)
IP β†’ 67.43.234.48
Malware Type β†’ Trojan.lazy/stealer
Detection Ratio β†’ 50 / 70 (VirusTotal)

File Information (NEW):
SHA 256 β†’ 01e92067f755318094e587539040862e456643d99d5fde603cee900d95fb0bb3
File size β†’ 1.52 Megabytes (1594880)
DIE β†’ Compiler: Microsoft Visual C/C++ (19.36.32824) || Linker: Microsoft Linker (14.36.32822) || Tool: Visual Studio (2022 version 17.6)
Magic β†’ PE32+ (PE64)
Tags β†’ spreader

Website Information:
ASN β†’ Gtcomm, ca (36666)
Hash β†’ 1402140703
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected], [email protected], [email protected]
Screenshot:

Available options:
[Download]β€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Ž[Similar]β€β€β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€Ž[Telemetry]β€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž [Content]β€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€β€Ž β€Žβ€β€ β€Ž[Webinfo]

1 me gusta

Link β†’ https://mcmbakara.com/ezy.php
Malware Type β†’ Webshell (infected website)
ASN β†’ Namecheap-net, us (22612)
Hash β†’ 4124853992
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected], [email protected], [email protected]
Screenshot:

1 me gusta

Link β†’ https://anglicannews.com.ng/ezy.php
Malware Type β†’ Webshell (infected website)
ASN β†’ Namecheap-net, us (22612)
Hash β†’ 1496673589
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected], [email protected], [email protected]
Screenshot:

1 me gusta

Link β†’ https://serencity.ng/admin.php
Malware Type β†’ Webshell (infected website)
ASN β†’ Namecheap-net, us (22612)
Hash β†’ 1546177611
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected], [email protected], [email protected]
Screenshot:

1 me gusta

Link β†’ https://app-update.info/1/ZainCash/1/
Source Code β†’ https://app-update.info/1/ZainCashLast.zip
Scam Type β†’ Phishing
ASN β†’ Hetzner-as, de (24940)
PhishTarget (Experimental) β†’ ZainCash
Hash β†’ 3367872551
Google Safebrowsing β†’ False
Abuse Emails β†’ [email protected], [email protected]
Screenshot:

Additional Information:
Telegram Chat ID ->497656935
Telegram Bot Token β†’ 7079634820:AAGW1ExMish3mz6pLRP0hVnjZiGYThC0vgg

1 me gusta

Link β†’ https://speedbreak.site/sub/install/
Source Code β†’ https://speedbreak.site/sub.zip
Scam Type β†’ Phishing
ASN β†’ Leaseweb-nl-ams-01 netherlands, nl (60781)
PhishTarget (Experimental) β†’ General
Hash β†’ 3027000439
Google Safebrowsing β†’ False
Abuse Emails β†’
Screenshot:

1 me gusta