Shadow Chaser Group
@ShadowChasing1
Shadow Chaser Group is a sub-group of the GcowSec team which consists of college students who love it.Shadow Chaser Group focused on APT hunt and analysis
ID:1248410640634359808
https://github.com/Gcow-Sec 10-04-2020 00:41:39
2,2K Tweets
9,5K Followers
517 Following
'NVUnityPlugin.dll' seen from Pakistan: 09d152aa2b6261e3b0a1d1c19fa8032f215932186829cfcca954cc5e84a6cc38
C2 domain: www.mingeloem[.]com - Namecheap.com registered...
Shadow Chaser Group Jazi
Due to some reasons, I will deactivate all activities related to crazyman_army from now on. Please follow the new account crazyman
At the same time, all information about crazyman_army will be invalid
#SideWinder #WhisperGate > Pakistan ๐ต๐ฐ
๐ฆ 6509a51daf061b40fef419d641ea73ed (BenevolentFundAndGroupInsurance.pdf)
Connects to
https://finance-gov-pk.rf[.]gd/BenevolentFundAndGroupInsurance to download a zip file 2ce216e4c430e4445c7e9682493e3a27 (BenevolentFundAndGroupInsurance)
#APT28 seems to have used #SmartScreen Zero-Day[CVE-2024-21412]
http[:]//194.126.178[.][email protected]/webdav/Python39/Client.py
I'm looking for some work opportunities with basic reverse (malware analysis) and some forensic knowledge. Have experience in malware tracking. The account is Shadow Chaser Group . Welcome to DM me and email of [email protected]. I'd be happy to work for you.
We are organising a conference on 26th - 27th June 2024
Attention Speakers: Our 2024 Call for Papers is now open! #OffByOne2024 ? Learn all about it:
offbyone.sg/cfp/
Nice Hunt MalwareHunterTeam
I guess the backdoor is here -> pycryptoenv\__init__.py -> crypt() func. So i guess the actor will first install this backdoor python module and drop some script to run it.But it's really weriod.And seems we won't know the key.
Another sample part of this campagin: #SugarGh0st RAT
852aa98d908fe1e09f985cd403fcf9a5
Presentation HAZARASP FEZ (eng) (1) .lnk
9d2ec11446e0cb5c9ae35575a5eb2031
~46727395.js
account.drive-google-com[.]tk
twitter.com/h2jazi/status/โฆ
Hello potential sponsors, we currently need some funds to support our trip to DiceCTF 2024 final. Of course if you are interested please contact [email protected]. We will provide more information. Welcome to mail!