We're streaming one of the most popular talks from our Threat Detection Series. Pop in as @ForensicITGuy teaches us about capabilities of common stealers, how to detect the malware, and how to respond.
I have posted the slides for the #BlackHat talk @chompie1337 and I gave yesterday -> Close encounters of the advanced persistent kind: Leveraging rootkits for post-exploitation
github.com/FuzzySecurity/…
Interesting #FakeSG execution from an HTA payload that leads to #NetSupport. Find my SIGMA rule for detecting this cool cmstp.exe execution technique below:
➡️Lots of initial PowerShell obfuscated scripts
➡️Using cmstp.exe to install a fake connection manager service profile named Notepad (See screenshot 1 and .INF file on screenshot 2)
⚙️cmstp.exe /au "C:\Users\\AppData\Local\Temp\CMSTP.inf"
💡[RunPreSetupCommandsSection]: This section contains commands to run before setup. A smart way of executing malicious code while blending in and masquerading as a legit service.
➡️Downloads and opens a decoy Chrome PNG image
➡️Downloaded artifacts from the below domains
⚡️www[.]redconsultora[.]com | 185.222.158.82:443
1⃣hxxps[://]www[.]redconsultora[.]com/campus/forestry.zip --- (Status: Offline)
2⃣hxxps[://]www[.]redconsultora[.]com/campus/client32.exe (Status: Offline)
⚡️cdn-icons-png[.]flaticon[.]com | 23.41.4.217:443
- hxxps[://]cdn-icons-png[.]flaticon[.]com/512/152/152759.png (Non-Malicious)
Sigma Rule: github.com/tsale/Sigma_ru…
HTA File: bazaar.abuse.ch/sample/645c680…
INF FIle: bazaar.abuse.ch/sample/0cb8d04…
I discovered stealer known as #Agniane , malware is designed to target various crypto-related platforms, offering support for over 70+ crypto extensions, 10+ crypto wallets, gather sensitive information such as Telegram sessions, Discord tokens, Steam sessions.
[BLOG]
Short post on using the Process Inject Kit in Cobalt Strike, which I feel is quite under-utilized based on the projects I've seen online.
offensivedefence.co.uk/posts/cs-proce…
8K Followers 6K Following#InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
6K Followers 935 Followinghttps://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
6K Followers 3K FollowingHunt & Response Senior Manager @HuntressLabs || "Competition is the law of the jungle, but cooperation is the law of civilisation” - Kropotkin
225K Followers 947 FollowingResearcher and a best-selling author. Keynote talks at RSA, Black Hat & DEF CON. TED Speaker. Chief Research Officer at Sensofusion.
604 Followers 27 FollowingIn the wild of cyberspace, 'Atomics on a Friday' is the El Camino of security testing. Guiding defenders with vital content to safeguard their organizations.
772 Followers 376 FollowingRandom infosec guy. Rainbow-teamer. Focusing on windows security. Powershell enthusiast. tweets are my own. 🇺🇦@[email protected]
329K Followers 118 FollowingEmpowering the world to fight cyber threats with indispensable cybersecurity skills and resources.
Support queries: https://t.co/HtFpqjjlRZ
47K Followers 0 FollowingDarkFeed: Cyber Threat Intelligence Platform, Putting things at order in the ransomware crazy world
#OSINT | #Ransomware | #Cyberattacks | #Hacktivism
15K Followers 916 FollowingWindows Internals expert, author, and trainer. Teaching system programming & debugging at TrainSec. Check out my books & courses! 🚀 #WindowsInternals #TrainSec
6K Followers 536 FollowingAnimal liberation activist 🌟 Forbes 30 Under 30 • Sr. Principal Researcher @ Unit 42 • Maintainer of Cutter and Rizin
I don't eat animals.
40K Followers 12 FollowingHusband | Vet | Founder @TCMSecurity | YouTuber | Professor | Disrupting the education industry via TCM Academy and #PNPT
https://t.co/aIcaYyoDlK