Watermark

CTI Telemetry

VirusTotal Analysis

Infostealer analysis by HudsonRock

34
🧠 Dispositivi infetti
30
🌐 Utenti compromessi
4
πŸ§‘β€πŸ’Ό Dipendenti compromessi
0
πŸ”‘ Password aziendali
0
πŸ”‘ Password users

Lumma 22
RedLine 18
StealC 14
Raccoon 6
Vidar 4

https://adss.fksgroup.com:9251/authorization.do 3
https://password.fksgroup.com/RDWeb/Pages/en-US/password.aspx 1
https://portalaudit.fksgroup.com:8383 1

https://ffswms.fksgroup.com/login 4
https://ffs.fksgroup.com:988/procure-link 4
http://pms.fksgroup.com/ 3
https://bolaloyalty.fksgroup.com/customer/reset/mQdZTwtiAHpBCnhTJFeX 3
https://ffswms.fksgroup.com 3
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’ 3
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’ 2
http://β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 2
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’ 2
https://β€’-β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’.β€’β€’β€’ 2
http://β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 2
http://β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 2
http://β€’β€’β€’β€’β€’β€’.fksgroup.com 1
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’/β€’β€’β€’/β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
http://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com 1
http://β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’.β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’_β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’.fksgroup.com/β€’β€’β€’β€’_β€’β€’β€’β€’ 1
http://β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’ 1
http://β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’.fksgroup.com:β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’-β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
http://β€’β€’β€’.fksgroup.com 1
https://β€’β€’β€’.fksgroup.com:β€’β€’β€’/β€’β€’β€’/β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’.fksgroup.com:β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fksgroup.com:β€’β€’β€’β€’ 1

Windows Defender 1