Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @bigmacjpg
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @bigmacjpg
-
Personally I'm not very sad that AV flags this file. If its a business process it should be reworked.https://twitter.com/JohnLaTwC/status/1224889455980371969 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
For the past few months, I've been diving into Apple's Endpoint Security Framework. This post shares how I use the framework for detection engineering purposes. https://posts.specterops.io/detection-engineering-using-apples-endpoint-security-framework-affdbcb18b02 …pic.twitter.com/PEpNy4v7jV
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
On successful compromise of the user endpoint, the red team deployed their ultimate weaponhttps://twitter.com/SamNChiet/status/1222647282237169671 …
0:45Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
Our latest
@McAfee_Labs blog takes a deep dive into Microsoft Rich Text Format and OLE Exploits: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/an-inside-look-into-microsoft-rich-text-format-and-ole-exploits …#malware#cybersecurity#infosecpic.twitter.com/ZGs368sa6Q
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
#badbullz Jscript dropper: https://app.any.run/tasks/341a19d0-6871-4159-b64b-dc56bbbab359 … Decoy doc suggests Poland FI targeting. Drops and executes what look like#darkrat ? https://www.virustotal.com/gui/file/a1657a30275a1334a9e115471497a412 … Gotta love the pokemon image droppedPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
2020: still "2" lines of code to get browsers saved creds and so many security products with no resilient detection/prevention for the same issuepic.twitter.com/ieIUMZDtnt
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
Perhaps to honor Acad. Sendov's memory, I should tell you the story about how our Lab was created. So, gather 'round the fire, kids, etc., etc. It's story time...
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
interesting sample, uses ShellWindows COM to bypass suspicious office child processes, try to download calc.bin from a likely legit/compromised bitcoin related website: https://app.any.run/tasks/29e2b46d-407b-493b-aee4-550159622ce3/ …pic.twitter.com/8XJDj4i6ZJ
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Kirk Sayre proslijedio/la je Tweet
Microsoft added Event ID 1 to the Application Log to show attempted exploitation of CVE-2020-0601 (via new CveEventWrite function). Use Splunk? Collect that EID and alert on: sourcetype=WinEventLog EventCode=1 LogName=Application Message="*[CVE-2020-0601]*" (tweak as needed)
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
Slides from my
#acod2020 talk on MacOS detections and post infection analysis: https://github.com/cedowens/Presentations/blob/master/ACoD_2020_macOS_Post_Infection_Analysis_.pdf …. Gave shoutouts to@thomasareed and@its_a_feature_ . Thanks to everyone who attended!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
Rough Patch: I Promise It'll Be 200 OK (CVE-2019-19781) |
@FireEye https://www.fireeye.com/blog/products-and-services/2020/01/rough-patch-promise-it-will-be-200-ok.html …pic.twitter.com/6ehR8JGQGE
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
Nothing says "have a nice weekend" better than releasing a zero day exploit on a late Friday eveningpic.twitter.com/flXSYIZq7Y
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Kirk Sayre proslijedio/la je Tweet
Heads up! Emotet is back and just re-started it's spam campaigns
Doc (MD5): aead1225141fadd849a27de8a27d16be
Payload delivery URLs via URLhaus:
https://urlhaus.abuse.ch/browse/tag/emotet/ …pic.twitter.com/C5HOIMbaxT
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
I often hear: 'but, but attackers will use a modified version of my tool to evade the detection method that you've just published' Truth is, 98% of attackers use your tools exactly as you've dropped them.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fantastic. What a mess ...https://twitter.com/a_tweeter_user/status/1214641030240321538 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
https://www.virustotal.com/gui/file/ddcb75ffdf9e3beddb1318f61145737f20f1544f6ba344d95ff69f642234ddae/detection … is an interesting maldoc. The VBA pops up a custom password box and the shell payload is only executed if the entered password begins with a 'c' or 'C'. Low detection rate and will foil sandboxes. Hits http[:]//quickwaysignstx[.]com/view.php for 2nd stage.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
this one is also one of my favorite quick-hunts to check for the occurence of any rogue shell (cmd.exe) based on top seen publicly abused (servicedll, dll via rundll32, injection) parent processes, below an e.g. for zxshell remote shell behavior
#threathunting#eqlpic.twitter.com/ag7IQNfF7a
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Kirk Sayre proslijedio/la je Tweet
Open-sourcing
#PEbear was one of my goals for 2019, but I failed this one. I resumed the development, and did some refactoring, but it’s not ready yet - sorry! I’m moving this goal to 2020.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.


Targeted Ransomware|"We breached your corporate network..."
Str->'FileName'->'IV'->'ENCRYPTED_AES_Key'->'EKANS' Marker
Path:
C:/Users/WIN1/go/src/.../crypt.go
h/t