Malicious #simplehelp #rmm #opendir at:
https://katz.adv\.br/dhl/
Malicious #simplehelp #rmm #opendir at:
https://katz.adv\.br/dhl/
@james_inthe_box Seems like HTTP over TCP 443 is "normal" for this one...
Other C2 servers used by same type of RMM/RAT: