#castleloader β Public Fediverse posts
Live and recent posts from across the Fediverse tagged #castleloader, aggregated by home.social.
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Here's the full infection chain:
198.211.110.107:79finger connects to finger[.]cloudyape[.]com172.67.190.68:80curl triescloudyape[.]com/uvey.php?holt=2but server responds with '301 Moved Permanently' and redirects to HTTPS172.67.190.68:443dropper download172.67.190.68:80curl getscloudyape[.]com/uvey.php?holt=1server redirects to HTTPS172.67.190.68:443dropper download170.130.165.201:80Download offile4.bin(#StealC) with fakeGoogeBotuser agent170.130.165.201:80#StealC v2 C2 / exfiltration170.130.55.38:80#CastleLoader traffic194.76.227.242:9999#CastleRAT C2 traffic