Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @hatching_io
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @hatching_io
-
You can fetch the HTA via the http://Tria.ge API - 1. Check the sample's dumped files: curl -sH "Authorization: Bearer <API-KEY>" https://api.tria.ge/v0/samples/200204-akqmaz2wqx/task1/report_triage.json … | jq .dumped 2. Fetch the HTA file curl -sH "Authorization: Bearer " https://api.tria.ge/v0/samples/200204-akqmaz2wqx/task1/files/0x0003000000012fe7-0.dat … --output note.htapic.twitter.com/XAfx2lF9qD
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Looks like some
#Cerber samples recently seen in the wild aren't dropping .txt ransom notes, and are only dropping .HTA applications in each folder with encrypted files. No more "READ_THIS" etc. files https://tria.ge/reports/200204-akqmaz2wqx/task1 …pic.twitter.com/WgIjtBnMSa
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Same keys in newer versions ( used to replicate the traffic communication + and fetch JSON config). Keys: https://tria.ge/reports/200203-nvt5qhha2x/task1 …https://twitter.com/0xAmit/status/1224369244797796352 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Detected as Danabot ( config included ): (cc https://tria.ge/reports/200203-dsclmgmn4x/task1 …). Also needed interaction to be triggered ( click OK in the MessageBox )
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Having trouble running your
#Qakbot samples? Don't forget that the filename can matter! Try submitting with a short, more 'normal' name and it may just run properly Left: name is 'jphxaul.exe' Right: name is 'Qakbot_[SHA256].exe' https://tria.ge/reports/191111-jzlt6rkwlj/task1 …pic.twitter.com/OfOYBAAKNe
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Seems to be also downloading something from h[.]t[.]t[.]p[.]s://share.dmca.gripe (cc https://tria.ge/reports/200203-h9sfxz22ne/task1 …)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
I also just released a vaccine for
#Emotet. A protection and detection tool to avoid get infected by Emotet payload. The code and the binaries are in my repository.#malwarehttps://github.com/d00rt/emotet_protection_tools …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Blog: Tracking
#REvil: our analysis of sample configurations, ransom demands and sinkhole data. The REvil affiliates operate at a huge scale encrypting 1000s of systems at once. And we're only seeing a fraction of the total activity.https://www.kpn.com/security-blogs/Tracking-REvil.htm …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Excellent research on
#REvil released by@rikvduijn today, using http://tria.ge in the process! :)https://www.kpn.com/security-blogs/Tracking-REvil.htm …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Not Win10 but Office16 is the solution. Great triage
@Casperinous !!!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Seems to be triggering currently in a Win10 VMhttps://tria.ge/reports/200127-j991m7rsfn/task2 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
still lokibot, VT AV signatures are pretty low confidence, also Lokibot is sort of a fork of pony which makes sense why some vendors would label it that wayhttps://tria.ge/reports/200124-5qsf9yzpk2/task1# …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Got a sample which needs extra DLLs? Find out how to submit multiple files at once to Triage in this week's bloghttps://hatching.io/blog/archive-submissions …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
#Powershell Static Analysis &#Emotet results#hatchingiohttps://hatching.io/blog/powershell-analysis …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
You can grab a screencap via CLI using URLSCAN. i usually do a dig $hostname ping -a $hostname nslookup $hostname then double check / confirm with those websites for sandbox i use
@anyrun_app and@hatching_io (thanks for the "researcher" tier license!)pic.twitter.com/QnmluALBA8
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Looking for a video to help wind down the week? Just uploaded one in which I analyze an
#emotet word doc from this morning (1/17/20). Focus is on macro analysis, but I do discuss a little traffic analysis and execution in@cuckoosandbox/@anyrun_app https://youtu.be/u_zqw19iWPY pic.twitter.com/ZS2Znh1uMK
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
日本語のマルウェアメールを観測しています。 Malware mail in Japanese observed.
#formbook Subject : 見積依頼 Sample : https://app.any.run/tasks/bc521b9f-d5e9-4aee-9612-26c6be3d20f4 … https://tria.ge/monitor/200117-h8zvmw3ggx …pic.twitter.com/dLly4B5Ep6
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Kicking off a new blog series on Emotet over at the
@gigamonATR blog with@criznash - huge props and thanks to@Carlos_Perez,@Cryptolaemus1 and@skier_t http://atr-blog.gigamon.com/2020/01/13/emo …#EmotetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Added enrichment for the data published by
@hatching_io about#emotet https://github.com/seifreed/malware/blob/master/stuff/enrichment_emotet.7z …https://twitter.com/hatching_io/status/1214595382048632833 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hatching proslijedio/la je Tweet
Couple of samples of the new Ako ransomware running nicely in Triage. Just implemented family classifications and ransomnote extraction, should be available in reports over the next day or 2 https://tria.ge/reports/200113-6r2c898g9n/task1 … https://tria.ge/reports/200113-kak3j7cc6j/task1 …https://www.bleepingcomputer.com/news/security/ako-ransomware-another-day-another-infection-attacking-businesses/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
Just reversed a new variant of
IOCS
: 34.65.176.45 [C2 and serving other stage codes for the malware], serralheriacic[.]com[.]br, Dropper md5: dcf7a5b5cc303de2b291a9995b5af988