Malicious #simplehelp #rmm #opendir at:

https://katz.adv\.br/dhl/

c2: funsunmexicobizz.top
@james_inthe_box HTTP on TCP port 443 
154.29.76.245:443

@james_inthe_box Seems like HTTP over TCP 443 is "normal" for this one...
Other C2 servers used by same type of RMM/RAT:

  • 147.45.218.66:443
  • 185.80.234.36:443
  • 91.211.251.233:443 🔥