Discussion about this post

User's avatar
gerdona's avatar

You started with just a few Lumma samples and ended up peeling back layers like an onion—CDNs filtered out, IPs grouped, certs matched, and boom: a suspicious hosting provider that reeks of bulletproof vibes.

Love how you connected the dots between the subnets and mapped out their roles (droppers here, C2 there, exfil over there)—it’s like watching a cybercrime ecosystem unfold in real time. And that Telegram bot + super-cheap VPS + UK shell game? Classic red flags.

Seriously great work—super detailed but still easy to follow. Thanks for sharing the hunt! Hope you catch even more in the next round. Stay sharp

Expand full comment

No posts

Ready for more?