http://tweedge32j4ib2hrj57l676twj2rwedkkkbr57xcz5z73vpkolws6vid.onion/2022/evolution-of-vipersoftx-dga
One known domain, wmail-endpoint.com , uses HTTP Payload: Similar to known ViperSoftX samples (Un)coincidentally only a couple days later on June 22nd, Xavier Mertens would publish a SANS ISC diary about a peculiar PowerShell script which would: Steal information about cryptocurrency browser extensions, Monitor the clipboard of the infected computer (but this was commented out), and Communicate to C2 using a similar but not identical domain, wmail-endpoint.com This is very similar to the...