That's an OVH Singapore IP, did they flag this to OVH? That server should be taken offline and the contents preserved for forensics.
bri3d•32m ago
I’m not sure this isn’t just some garden variety RAT that was named “audiod.exe”? The author seems kind of confused; there’s nothing driver related I can see here. They claim the malware was “injected” into a legitimate process, but the Microsoft audio graph process is “audiodg.exe”
fishgoesblub•20m ago
"compressed .wav files"
Interesting that the malware author isn't using actual compressed audio (No idea why the Twitter poster seems to think wave files are compressed) I would assume that you'd want to transmit as little data to evade detection.
I’m not even convinced the audiod thing is Regin; it’s way less sophisticated even based on what the OP posted from volatility. I think this person is just karma/clout farming badly and the screenshots are of some even more basic RAT.
efilife•7m ago
I quickly skimmed at through twitter and youtube profiles and it's apparent that this guy has no idea of what he's talking about
treetalker•1h ago