@james_inthe_box Thanks for sharing! Looks like it (OriginLogger?) is exfiltrating to:
🔥 cvgrf[.]biz
🔥 knjghuig[.]biz
🔥 npukfztj[.]biz
🔥 przvgke[.]biz
🔥 pywolwnvd[.]biz
🔥 ssbzmoy[.]biz
@netresec That's the expiro at work :) ftp.aventour\.com\.mx is the originlogger exfil.
@james_inthe_box Ah, yes of course! Thanks for pointing that out 🙏