Indicators of Compromise Associated with LockBit 2.0
Ransomware π΅οΈπΎπ₯οΈπ
https://www.ic3.gov/Media/News/2022/220204.pdf
π£CryptoInsane
π@malwr
Ransomware π΅οΈπΎπ₯οΈπ
https://www.ic3.gov/Media/News/2022/220204.pdf
π£CryptoInsane
π@malwr
If anyone wants practice with packet analysis, hereβs a lab I give to my Security class each semester. Includes a real PCAP from @defcon #PcapsOrItDidntHappen
https://github.com/tuftsdev/DefenseAgainstTheDarkArts/blob/gh-pages/labs/lab02-pcaps.md
π£0xmchow
π@malwr
https://github.com/tuftsdev/DefenseAgainstTheDarkArts/blob/gh-pages/labs/lab02-pcaps.md
π£0xmchow
π@malwr
GitHub
DefenseAgainstTheDarkArts/labs/lab02-pcaps.md at gh-pages Β· tuftsdev/DefenseAgainstTheDarkArts
Contribute to tuftsdev/DefenseAgainstTheDarkArts development by creating an account on GitHub.
I've updated the Antivirus Event Analysis Cheat Sheet to v1.9.0
- updates in all sections
- MS Exchange exploitation related indicators
- updated identifiers
Could @SophosLabs please fix the spelling of Webshel+l?
https://www.nextron-systems.com/2022/02/06/antivirus-event-analysis-cheat-sheet-v1-9-0/
π£cyb3rops
π@malwr
- updates in all sections
- MS Exchange exploitation related indicators
- updated identifiers
Could @SophosLabs please fix the spelling of Webshel+l?
https://www.nextron-systems.com/2022/02/06/antivirus-event-analysis-cheat-sheet-v1-9-0/
π£cyb3rops
π@malwr
Decoding Cobalt Strike: Understanding Payloads
https://decoded.avast.io/threatintel/decoding-cobalt-strike-understanding-payloads/
π£pentest_swissky
π@malwr
https://decoded.avast.io/threatintel/decoding-cobalt-strike-understanding-payloads/
π£pentest_swissky
π@malwr
Gendigital
Decoding Cobalt Strike: Understanding payloads
Identifying and Parsing Cobalt Payloads
IDACode - An Integration For IDA And VS Code Which Connects Both To Easily Execute And Debug IDAPython Scripts https://ift.tt/9jM4DvH #cybersecurity #bugbountytips #hacking #tools
π£santosomar
π@malwr
π£santosomar
π@malwr
π₯4
The Walmart Global Tech security team write about the Sugar ransomware operation, which appears to actively target individual computers rather than entire enterprises. https://medium.com/walmartglobaltech/sugar-ransomware-a-new-raas-a5d94d58d9fb
π£virusbtn
π@malwr
π£virusbtn
π@malwr
Cuckoo and CAPE sandbox evasion in one legitimate Windows API function call? It is possible due to issues we found in Cuckoo and CAPE monitor.
@CapeSandbox @cuckoosandbox
https://research.checkpoint.com/2022/invisible-cuckoo-cape-sandbox-evasion
π£_CPResearch_
π@malwr
@CapeSandbox @cuckoosandbox
https://research.checkpoint.com/2022/invisible-cuckoo-cape-sandbox-evasion
π£_CPResearch_
π@malwr
Check Point Research
Invisible Sandbox Evasion - Check Point Research
Cuckoo and CAPE sandbox evasion in one legitimate Windows API function call? It is possible due to issues we found in Cuckoo and CAPE monitor.
Me watching somebody try to decrease Emotet AV detection by uploading stuff to VirusTotal π
π£GossiTheDog
π@malwr
π£GossiTheDog
π@malwr
Decrypted: Avast releases #free #decryptor for the #TargetCompany #ransomware: #AvastDecoded
https://decoded.avast.io/threatresearch/decrypted-targetcompany-ransomware/
π£AvastThreatLabs
π@malwr
https://decoded.avast.io/threatresearch/decrypted-targetcompany-ransomware/
π£AvastThreatLabs
π@malwr
Gendigital
Decrypted: TargetCompany ransomware
TargetCompany Ransomware Analysis Details
π2
Another new post to start the week! This time around I take a look at a RTF document that exploits MS Office Equation Editor to deploy AgentTesla:
#malware #agenttesla
https://forensicitguy.github.io/agenttesla-rtf-dotnet-tradecraft/
π£ForensicITGuy
π@malwr
#malware #agenttesla
https://forensicitguy.github.io/agenttesla-rtf-dotnet-tradecraft/
π£ForensicITGuy
π@malwr
Tony Lambert
AgentTesla From RTF Exploitation to .NET Tradecraft
When adversaries buy and deploy threats like AgentTesla you often see this functional and entertaining chain of older exploitation activity with some .NET framework tradecraft youβd expect from some modern implants. In this post Iβll walk through analyzingβ¦
Guess I will get to see how my theory on this will play out in real life now
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
π£HackingLZ
π@malwr
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
π£HackingLZ
π@malwr
TECHCOMMUNITY.MICROSOFT.COM
Helping users stay safe: Blocking internet macros by default in Office | Microsoft Community Hub
To protect our customers, users will no longer be able to enable macros obtained from the internet.
This media is not supported in your browser
VIEW IN TELEGRAM
Just released a new, fast-paced, interactive binary patching plugin for IDA Pro. Check out a small blurb about it on the @HexRaysSA blog: https://hex-rays.com/blog/introducing-the-patching-plugin/
Code: https://github.com/gaasedelen/patching
π£ret2systems
π@malwr
Code: https://github.com/gaasedelen/patching
π£ret2systems
π@malwr
Microsoft blocks VBA macros originating from Internet based on MOTW flag.
I'm now sharing a tool presenting risk for MOTW bypasses, which will play crucial role in evading MS default setting and smuggle macros back in.
Threat Actors already do that.
https://github.com/mgeeky/PackMyPayload
π£mariuszbit
π@malwr
I'm now sharing a tool presenting risk for MOTW bypasses, which will play crucial role in evading MS default setting and smuggle macros back in.
Threat Actors already do that.
https://github.com/mgeeky/PackMyPayload
π£mariuszbit
π@malwr
π2
This media is not supported in your browser
VIEW IN TELEGRAM
How can we run arbitrary code without allocating/overwriting executable memory? We "borrow" (abuse) instructions from ntdll.dll!
https://www.x86matthew.com/view_post?id=windows_no_exec
π£x86matthew
π@malwr
https://www.x86matthew.com/view_post?id=windows_no_exec
π£x86matthew
π@malwr
Today we published a new report on the new ModifiedElephant APT, and the years of attacks against groups and individuals in India.
Blog: https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/
Full Report: https://assets.sentinelone.com/sentinellabs-apt/modified-elephant-apt
π£TomHegel
π@malwr
Blog: https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/
Full Report: https://assets.sentinelone.com/sentinellabs-apt/modified-elephant-apt
π£TomHegel
π@malwr
SentinelOne
ModifiedElephant APT and a Decade of Fabricating Evidence
A previously unreported threat actor has been targeting civil society for over a decade. Read about how it operates and its relationships to other threats.
Good news for all the infosec community. Now you can Export/Import VT Collections into/from MISP Events π by
@thetravelr https://blog.virustotal.com/2022/02/misp-and-vt-collections.html
π£virustotal
π@malwr
@thetravelr https://blog.virustotal.com/2022/02/misp-and-vt-collections.html
π£virustotal
π@malwr
FTK Imager Version 4.7.1 released >>
https://accessdata.com/product-download/ftk-imager-version-4-7-1
π£chadtilbury
π@malwr
https://accessdata.com/product-download/ftk-imager-version-4-7-1
π£chadtilbury
π@malwr
Exterro
Data Risk Management - Data Discovery & Privacy Platform | Exterro
Exterro's powerful data risk management platform unifies e-discovery, privacy, data governance, digital forensics, and cybersecurity compliance toβ¦