http://tweedge32j4ib2hrj57l676twj2rwedkkkbr57xcz5z73vpkolws6vid.onion/2022/evolution-of-vipersoftx-dga
June 15th, 2022 Dropper: Load from file at offset, then base64 C2: One known domain, wmail-service.com , uses HTTP Payload: Not witnessed On June 15th, 2022, a topic on malwareremoval.com is started by a person who found a task running on startup: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NonInteractive -WindowStyle Hidden -ExecutionPolicy RemoteSigned -Command &{$env:psmodulepath = [IO.Directory]::GetCurrentDirectory(); import-module AppvClient;...
1 similar result skipped