Hiding Your Tracks: Bash History
π£bad3r_
Nice! I would add another one, kill the console to quit bash without saving history:
kill -9 $$
π€ReigningShells
π@malwr
π£bad3r_
Nice! I would add another one, kill the console to quit bash without saving history:
kill -9 $$
π€ReigningShells
π@malwr
What do you use for IP Reputation?
We are currently using IBM X-force, but o don't find it that reliable there is a lot if false positives in there.
Any suggestions? Especially for one were we can get a feed from (API or something)
π£Mo7Robot
https://www.abuseipdb.com/register
https://talosintelligence.com/reputation\_center
https://www.apivoid.com/api/ip-reputation/
π€chrisknight1985
If you are looking for malicious domains the Fortinet threat feed is pretty good. It's part of their Fortinet Developer's Network Site License. It's an API feed that supports csv and stix formats.
π€Defiant_Success
π@malwr
We are currently using IBM X-force, but o don't find it that reliable there is a lot if false positives in there.
Any suggestions? Especially for one were we can get a feed from (API or something)
π£Mo7Robot
https://www.abuseipdb.com/register
https://talosintelligence.com/reputation\_center
https://www.apivoid.com/api/ip-reputation/
π€chrisknight1985
If you are looking for malicious domains the Fortinet threat feed is pretty good. It's part of their Fortinet Developer's Network Site License. It's an API feed that supports csv and stix formats.
π€Defiant_Success
π@malwr
Reddit
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
OP Glowing Symphony β How US military claims to have disrupted ISIS βs propaganda
π£quellaman
π@malwr
π£quellaman
π@malwr
Security Affairs
OP Glowing Symphony - How US military claims to have disrupted ISIS 's propaganda
US military claims to have disrupted the online propaganda activity of the Islamic State (ISIS) in a hacking operation dating back at least to 2016.
sLoad malware gang returns: Microsoft detects quickly revamped 2.0 version
π£BhaswatiGuha19
π@malwr
π£BhaswatiGuha19
π@malwr
International Business Times
sLoad malware gang returns: Microsoft detects quickly revamped 2.0 version
sLoad malware has been around for years but after the detection, in December it again returned with 2.0 version named as Starslord earlier this month
Local Privilege Escalation in many Ricoh Printer Drivers for Windows (CVE-2019-19363) + Exploit
π£aunga
π@malwr
π£aunga
π@malwr
Pentagrid AG
Local Privilege Escalation in many Ricoh Printer Drivers for Windows (
A local privilege escalation in Ricoh Windows printer drivers is affecting many Ricoh printer models.
Israeli security pros using βCybernetβ social network for threat intelligence
π£tds_404
π@malwr
π£tds_404
π@malwr
The Daily Swig | Cybersecurity news and views
Israeli security pros using βCybernetβ social network for threat intelligence
Infosec platform is free to join, but members are subject to approval process
Ubisoft send 2FA recovery code by email
π£-d4v3-
Once someone has access to your email they can take away the 2FA anyways. So it's not really weird or smth
π€Axua247
π@malwr
π£-d4v3-
Once someone has access to your email they can take away the 2FA anyways. So it's not really weird or smth
π€Axua247
π@malwr
Emotet file hashes, Compromised IP addresses and domains, and malicious powershell artifacts
While collecting malware samples on pastebin, my bot found an anonymous paste that contained a large amount of data relating to emotet.
It includes a section of file hashes, malicious IP addresses, compromised servers, compromised domains, and a few obfuscated powershell artifacts that look to either be post-exploitation or an alternative infection method.
File samples can be collected by simply using wget on a live compromised domain.
Here is a link to a reupload of the document:
https://pastebin.com/V6GGEPVA
π£NovateI
π@malwr
While collecting malware samples on pastebin, my bot found an anonymous paste that contained a large amount of data relating to emotet.
It includes a section of file hashes, malicious IP addresses, compromised servers, compromised domains, and a few obfuscated powershell artifacts that look to either be post-exploitation or an alternative infection method.
File samples can be collected by simply using wget on a live compromised domain.
Here is a link to a reupload of the document:
https://pastebin.com/V6GGEPVA
π£NovateI
π@malwr
Pastebin
Copy of An Emotet Report - Pastebin.com
Need to know how to setup a "Basic" Vulnerability Management program? Follow these steps to start 2020 off right in VM!
https://cyberpulse.tech/2020/01/21/create-a-basic-vulnerability-management-program/
π£Siloras
π@malwr
https://cyberpulse.tech/2020/01/21/create-a-basic-vulnerability-management-program/
π£Siloras
π@malwr
Cyberpulse
Create a basic Vulnerability Management program - Cyberpulse
Create a successful and modern Vulnerability Management program by following these phases. Plan, Design, and Execute the following steps to be secure!
Fake Company, Real Threats: Logs From a Smart Factory Honeypot - Security News
π£_TM_dude
The most interesting part of this piece was the layout they used on their website to show the story.
It looks like it was running for several months, but didn't produce any revealing information. A few non-technical ransomware attacks. Simple stuff caused by poor security, which, I get it, it was mainly to show how weak security is a main point of entry. Not exactly revolutionary.
π€DegenerateJC
Disappointed. I wish the guy came from real APT group doing more sophisticated or unknown exploits. No PLC system were harmed or attempted.
π€thanoscsgo
I like the guy who acted like he was installing ransomware then renamed their files instead.
π€steezefries
π@malwr
π£_TM_dude
The most interesting part of this piece was the layout they used on their website to show the story.
It looks like it was running for several months, but didn't produce any revealing information. A few non-technical ransomware attacks. Simple stuff caused by poor security, which, I get it, it was mainly to show how weak security is a main point of entry. Not exactly revolutionary.
π€DegenerateJC
Disappointed. I wish the guy came from real APT group doing more sophisticated or unknown exploits. No PLC system were harmed or attempted.
π€thanoscsgo
I like the guy who acted like he was installing ransomware then renamed their files instead.
π€steezefries
π@malwr
Trendmicro
Fake Company, Real Threats: Logs From a Smart Factory Honeypot
To determine threat actors' degree of knowledge in compromising a smart factory, we deployed our most elaborate honeypot to date. The incidents we observed show the kinds of attacks that can easily affect poorly secured manufacturing environments.