| Tweetovi |
| Maʁsɛl proslijedio/la je tweet | ||
|
S⃣ A⃣ S⃣ A⃣
@gorimpthon
|
14 h |
|
#emotet only epoch2 looks updated C2 communication protocol so far.
Samples:
Epoch1:
app.any.run/tasks/a39a93ac…
Epoch2:
app.any.run/tasks/fa1c6f9b…
Epoch3:
app.any.run/tasks/4530e3c2… twitter.com/Cryptolaemus1/…
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
17 h |
|
hxxps[://]r371gcneei1[.]disghneied[.]xyz/
hxxps[://]wvyp2fvia8e[.]bowsandstone[.]surf/
hxxps[://]t382dgjuu7i[.]disghneied[.]xyz/
hxxps[://]wet86sfuu8a[.]bowsandstone[.]surf/
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
17 h |
|
hxxps[://]ta95dkceie3[.]splatterdesu[.]surf/
hxxps[://]wea950ou4y[.]hellishacidicphotography[.]xyz/
hxxps[://]hnbrtawa87[.]hellishacidicphotography[.]xyz/
hxxps[://]8oq8nb3at8[.]maplesan[.]monster/
hxxps[://]qsdktawaa3[.]maplesan[.]monster/
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
17 h |
|
hxxps[://]rt86sjyaeot[.]anomax1z[.]xyz/
hxxps[://]krnie1sai89[.]delstrryus[.]monster/
hxxps[://]era90fuuyp[.]delstrryus[.]monster/
hxxps[://]ue6svfcawt[.]elfinwistful[.]club/
hxxps[://]39xkdrnei1s[.]elfinwistful[.]club/
hxxps[://]ta81fjeaaua[.]splatterdesu[.]surf/
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
17 h |
|
New #Azorult out there:
hxxps[://]et82geaer4[.]gamystrom[.]website/
hxxps[://]cwwea39eegk[.]gamystrom[.]website/
hxxps[://]fjyyi19ua89[.]p1q15ir0n7[.]monster/
hxxps[://]ise3vn3aet[.]anomax1z[.]xyz/
hxxps[://]895fwv4ioq7[.]p1q15ir0n7[.]monster/
@AZORult_Tracker @CloudflareAbuse
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
23 h |
|
Me missing #bluehatil after 3 years of consecutively going. pic.twitter.com/cEKieMtXc6
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
Trevor Taylor
@0x5858c390
|
4. velj |
|
My team talking about some of the things we've seen recently.
microsoft.com/security/blog/…
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
C J is pronounced "siege"
@ceejbot
|
4. velj |
|
Count votes on paper ballots. By hand.
signed,
a software professional
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
4. velj |
|
Where is part 1?
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
SANS ISC
@sans_isc
|
3. velj |
|
Analysis of a triple-encrypted AZORult downloader i5c.us/3b2v4Jc pic.twitter.com/WawmyF13e1
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
3. velj |
|
|
||
|
Maʁsɛl
@marcelmalware
|
3. velj |
|
English subtitles
youtu.be/uywqKdFXQCw
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
Mark Simos
@MarkSimos
|
29. sij |
|
Need a SOC Reference Architecture? Check out this one we put together to show how Microsoft technology integrates into a SOC.
Slide 73 of Azure Security Compass - aka.ms/azuresecurityc…
@ajohnsocyber @MalwareJake @_sarahyo @RavivTamir @JohnLaTwC pic.twitter.com/hI0eT0Tu14
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
Adam Toscher
@W00Tock
|
29. sij |
|
How to Red Team #1 - A twitter red team mind map
Need credentials from the outside?
1. OSINT (Find e-mail/PII)
2. Social Engineer (Trick someone into clicking an e-mail you sent them w/o a payload)
3. Target External Services (Password Spray or find a vulnerable service )
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
Ophir Harpaz
@OphirHarpaz
|
27. sij |
|
Understanding this tweet was the best moment of my day.
Sincerely yours,
the person who never quite understood Public Key Infrastructure.
[Thanks @TalBeerySec for writing the blog post that put all the pieces together medium.com/zengo/win10-cr…. and still expect some questions] twitter.com/CasCremers/sta…
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
Richard Gold
@drshellface
|
28. sij |
|
1. Windows Defender 2. EDR 3. Automated defanging of documents 4. Disabling macros, OLE, DDE, etc. 5. Disabling Windows Script Hosting 6. Private VLANs 7. Application whitelisting 8. Users not being local admins 9. 2FA on everything 10. Up-to-date patching twitter.com/jhencinski/sta…
|
||
|
|
||
| Maʁsɛl proslijedio/la je tweet | ||
|
Joshua Saxe
@joshua_saxe
|
28. sij |
|
1\ Surprisingly, you could build a very mediocre PE malware detector with a single PE feature: the PE compile timestamp. In fact, I built a little random forest detector that uses only the timestamp as its feature that gets 62% detection on previously unseen malware at a 1% FPR.
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
28. sij |
|
"Hackers exploit 'bug' with oversized meat-space payload" pic.twitter.com/AsHgzKdOgp
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
28. sij |
|
But that's bing and not calculator
|
||
|
|
||
|
Maʁsɛl
@marcelmalware
|
28. sij |
|
Twitter mobile is like 50% ads
|
||
|
|
||