chartingshow / crypto-firewall

🎁 Blocks browser-based crypto mining, cryptojacking, banking and crypto malware and phishing websites, apps and hackers command-and-control (C2) servers.
GNU General Public License v3.0
11 stars 0 forks source link

Block `JSOutProx` malware targeting VISA institutions and their customers #484

Closed summercms closed 5 months ago

summercms commented 5 months ago

Enhancement idea

Description

JSOutProx, is targeting financial services and organizations in the APAC and MENA regions. JSOutProx is a sophisticated attack framework utilizing both JavaScript and .NET. It employs the .NET (de)serialization feature to interact with a core JavaScript module running on the victim's machine. Once executed, the malware enables the framework to load various plugins, which conduct additional malicious activities on the target. This malware was first identified in 2019 and was initially attributed to SOLAR SPIDER's phishing campaigns, which delivered the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and Southeast Asia.

Links

https://www.resecurity.com/blog/article/the-new-version-of-jsoutprox-is-attacking-financial-institutions-in-apac-and-mena-via-gitlab-abuse

IOC

I2P websites

n/a

IPFS websites

n/a

Tor2web websites

n/a

TOR websites

n/a

URL's

n/a

Folders

github.com/agbusi/
raw.githubusercontent.com/agbusi/
gitlab.com/godicolony4040/

Above: The accounts are now 404.

Sub-Domains

eopgupgdpopopfuupi.ddns.net
hudukpgdgfytpddswq.ddns.net
kiftpuseridsfryiri.ddns.net
mdytreudsgurifedei.ddns.net
suedxcapuertggando.ddns.net
ykderpgdgopopfuvgt.ddns.net

Above: Already blocking ddns.net free dns service.

Domains

n/a

IP's

103.212.81.155
103.212.81.157
185.244.30.218
79.134.225.17

ASN's

n/a

Emails

mike.will@my.com

Wallet addresses

n/a

Mining pool addresses

n/a