Skip to content

Latest commit

 

History

History
61 lines (38 loc) · 1.76 KB

File metadata and controls

61 lines (38 loc) · 1.76 KB

I4 Theft

Date:: July 22nd, 2024

Amount Stolen: $1.5m (409+ ETH)

Tags:: 🔑 SquidSquad (Protected)


Email

  • Purportedly from "Dovey Wan" via lpnnews[.]com, sent on July 17, 2024

  • Subject line: "New Era for Stablecoins and Defi (Protected)"

Malware C2s

  • 23.254.253[.]75
  • 172.86.104[.]191

On-chain

  • Hvk6kcxFvJmpqZBJdVRMd5zdSuazwRFLFpXUcukxZ7nD - Theft
  • 2oWRWtokB1gZTzEt5fHrsQXHHvmuh296LHFtSq9oHKdD - July 22nd, 2024
  • DHyDV2ZjN3rB6qNGXS48dP5onfbZd3fAEz6C5HJwSqRD - July 22nd, 2024
  • 0x600cd901d0407753c212ed17d8c6cae014ee300e - Theft
  • 0x457Ce73FbB19283EbAcbFd1984CCf8a34953cad3 - ChangeNOW Depo
  • 0xFf268C515366AB8448b39318FeEe84138153B8b0 - Railgun Input
  • 0x21bD4526655Ac2E965Be95030c53bD4BC458790f - Railgun Input
  • 0xFf87A4dF67068464e5f4e3B546f556b2DFfB6DfB - Railgun Output
  • 0xA81eAC50C0B17aEe3132f40f7398087e457Ca054 - Railgun Input
  • 0x9f71f8c67c1e8d9466aa0391b222e2d964dc35b6 - Railgun Withdrawer
  • 0xb8a0349228C78f83c7Faa48f62E6Dbbde783bb99 - July 31st, 2024
  • 0x2c3824da360d817ebb9adb52161888f54a0344d1
  • 0xddb2e9feaf0a122b43be14bc085cf713703ce45c
  • 0xa890696868b64570c8bd04f8713a0431b911a6fa
  • 0x1bc1c835ceeb4063a5dbe01d1a13f8c4669ca667 - FixedFloat Depo
  • bc1qxukac40lkxefef6jq3czj4cw8nuer6fdzlz2vx
  • https://mayascan.org/tx/033F3532C7772A8E1DBE2A76A9BD29AA7C4261731436E7C75C11C89FE7BFE9DC

Laundry IoCs

  • Date: 2024-07-22
  • UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
  • Timezone: Asia/Tokyo
  • Lang: en-US,en;q=0.8
  • IP: 84.247.59.158 & 84.247.59.193 (ExpressVPN)

Connections

  • Comingles extensively with ALEX Labs stolen funds

  • $1m in 0x7EF94684238844AC5616a3D1366348c8FAC81BEE frozen by Tether mid-August (not sure if these are ALEX or I4 funds...will check later)