#rogueraticate — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rogueraticate, aggregated by home.social.
-
#FakeSG / #RogueRaticate leading to #netsupportrat
ebodyfit[.]com/wp-content/uploads/ultimatemember/58/downloading-(114.0.522735.199%20(Official%20Build).url
ebodyfit[.]com/wp-content/uploads/ultimatemember/57/consciousnessx.hta
ebodyfit[.]com/wp-content/uploads/ultimatemember/56/housealba.zip
ebodyfit[.]com/wp-content/uploads/ultimatemember/56/clients32.exe
-
They updated the LNK to point to a different HTA which in turn grabs a different NetSupport INI to point at a new gateway. Curious how frequently this group rotates the chain.
Infection chain
compromised site
google-analytiks[.]com/sBY76j
-->
hXXps://esteticalocarno[.]com/wp-content/uploads/2023/02/Install%20Updater%20(V105.215.8412_silent).url
-->
hXXp://185[.]252.179.64:80/Downloads/shdeulerinstall[.]lnk
-->
hXXps://www[.]esteticalocarno[.]com/wp-content/uploads/2018/5/XVXCSASD.hta
-->
NetSupport GatewayAddress 94[.]158.244.41:4430e74d799e5486979f7cafb3c6bbd8fab224f882b82197eb8975818bd61cbb667 XVXCSASD[.]hta