JhoneRAT uses Google Drive, Twitter, ImgBB, and Google Forms to target countries in Middle East
🗣quellaman
🎖@malwr
🗣quellaman
🎖@malwr
Security Affairs
JhoneRAT uses Google Drive, Twitter, ImgBB, and Google Forms to target countries in Middle East
Researchers from Cisco Talos discovered a new Trojan named JhoneRAT that was used in targeted attacks against entities in the Middle East.
The Year 2038 problem (also called Y2038 or Unix Y2K) relates to representing time in many digital systems as the number of seconds passed since 00:00:00 UTC on 1 January 1970 and storing it as a signed 32-bit integer.
https://en.m.wikipedia.org/wiki/Year_2038_problem
🎖@malwr
https://en.m.wikipedia.org/wiki/Year_2038_problem
🎖@malwr
Wikipedia
Year 2038 problem
problem affecting digital systems that store system time as a signed 32-bit integer
av evasion techniques
i need a updated list(prefer 2019) of av evasion techniques (no tools, only docs) an types
The ones I found on Google, are incomplete or outdated, this
https://marcoramilli.com/2013/07/20/malware-evasion-chart/
is one of the best I found but it is 7 years ago and I am not sure that the techniques mentioned are still in use
Thanks for the help
🗣bl455
MITRE ATT&CK Defense Evasion Tactic
👤dakeytheone
🎖@malwr
i need a updated list(prefer 2019) of av evasion techniques (no tools, only docs) an types
The ones I found on Google, are incomplete or outdated, this
https://marcoramilli.com/2013/07/20/malware-evasion-chart/
is one of the best I found but it is 7 years ago and I am not sure that the techniques mentioned are still in use
Thanks for the help
🗣bl455
MITRE ATT&CK Defense Evasion Tactic
👤dakeytheone
🎖@malwr
Marco Ramilli Web Corner
Malware Evasion Chart
Plenty of documents are describing how Malwares implement “Escape” techniques in order to evade Malware analysis. I did write posts on several of the most interesting evasion techniques…
An attacker logged into the honeypot, dropped XMRig, mimikatz, and a bunch of usernames and passwords. See below for info on XMRig, intrusion summary, OPSEC fail, and IOCs.
🗣InfoSecJim
🎖@malwr
🗣InfoSecJim
🎖@malwr
Wilbur Security
XMRig and OPSEC Fail
An attacker logged into the honeypot, dropped XMRig and mimikatz, and then ran XMRig. XMRig installed Netshta to maintain persistence and then started mining Monero. When the attacker dropped mimikatz, they accidentally dropped a list of usernames and passwords.…
TikTok vulnerability: Chinese firm buckles up with more safety features as criticism mounts [Exclusive](https://www.ibtimes.sg/tiktok-vulnerability-chinese-firm-buckles-more-safety-features-criticism-mounts-exclusive-38025)
🗣BhaswatiGuha19
🎖@malwr
🗣BhaswatiGuha19
🎖@malwr
International Business Times, Singapore Edition
TikTok vulnerability: Chinese firm buckles up with more safety features as criticism mounts [Exclusive]
Since TikTok's parent company is Beijing-based ByteDance, the app has been targeted by lawmakers and regulators who are suspicious of Chinese technology