Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @CapeSandbox
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @CapeSandbox
-
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
CAPE Sandbox proslijedio/la je Tweet
New CAPE Sandbox module released for FAME platform
@CertSG@CapeSandbox https://github.com/jmesa/cape_module …pic.twitter.com/2H0gAxhgAT
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
From grain to glass:
#Emotet maldoc -> unpacked malware payload & 127 C2s in one run: https://capesandbox.com/analysis/9983 MD5: 93eed51374a6f51f6b83fa343b69c5d3pic.twitter.com/TNCT4dNqrD
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
If multiple epochs are submitted, then there will be multiple keys and again a monster combined c2 list. Here is an example with 7 samples from 3 epochs: https://capesandbox.com/analysis/6635
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#Emotet batch config extraction as suggested by@daevlin The result of a batch is a combined config, so if you include only one epoch, it should be a single key and combined c2 list from all samples. For example: https://capesandbox.com/analysis/6638 https://twitter.com/daevlin/status/1188105653556043776 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CAPE Sandbox proslijedio/la je Tweet
"Screen-Error-Visible.pif" - signed Remcos RAT sample: https://www.virustotal.com/en/file/cf52d23a1909c21d0966be6184e2958aa1ab0e02515ff9c0720d0fc35b43c928/analysis/1556723011/ … C2: infosblogwar.duckdns[.]org:2404 - known one... Thanks to
@CapeSandbox for detection and config extraction.pic.twitter.com/Ryn5sBZZ7j
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Sadly CAPE may have missed things launched or injected via Heaven's Gate - I began working on a package for it (https://github.com/ctxis/capemon/tree/HeavensGate …) but never got it finished or working. Maybe I should dust it off...
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Looks like the module containing Heaven's Gate is downloaded from the C2 - there are calls to HttpSendRequest then InternetReadFile just prior to the allocation of the memory for this DLL.pic.twitter.com/ZjDIm4QnUj
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#Emotet with 64-bit payloads launched via Heaven's Gate in an embedded 32-bit DLL. Payloads can be downloaded from: https://cape.contextis.com/analysis/69249 pic.twitter.com/lkwuCovsz6
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CAPE Sandbox proslijedio/la je Tweet
Detection and config parser has been added for Remcos RAT to
@CapeSandbox.
Example: https://cape.contextis.com/analysis/59793/
(Sample used: https://twitter.com/malwrhunterteam/status/1104327117309968384 …)pic.twitter.com/8Rg0bWUnbl
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#QakBot dished out by#Emotet yesterday: https://cape.contextis.com/analysis/33874 pic.twitter.com/bhJUjBdqO4
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#QakBot sample config date 16/1/2019: https://cape.contextis.com/analysis/30910 pic.twitter.com/S2LQ47s4Sd
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CAPE Sandbox proslijedio/la je Tweet
Very impressed with the work from
@CapeSandbox,@sysopfb and@pollo290987 for the emotet extraction module. Give it a go at the public instance of CAPE! I now am using this for my#emotet work and@unixronin has been using this for awhile in the@Cryptolaemus1 automation.https://twitter.com/CapeSandbox/status/1085115586550603776 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#Emotet configs now with RSA public keys - thanks to@pollo290987 for the suggestion and code!pic.twitter.com/fHasltwLaG
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#Ryuk ransomware payload signature added to CAPE - some recent examples: https://cape.contextis.com/analysis/29668 https://cape.contextis.com/analysis/29670 https://cape.contextis.com/analysis/29672Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#Shade (#Troldesh) ransomware payload signature now in CAPE: https://cape.contextis.com/analysis/28279 https://cape.contextis.com/analysis/29288 https://cape.contextis.com/analysis/29293Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
New
#Remcos RAT payload signature in CAPE. A couple of recent examples: https://cape.contextis.com/analysis/29119 https://cape.contextis.com/analysis/29139Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#Azorult payload signature now in CAPE - a few recent examples: https://cape.contextis.com/analysis/25585 https://cape.contextis.com/analysis/25586 https://cape.contextis.com/analysis/25587 pic.twitter.com/UiXolkQG1R
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

