Again CFG
CFG again 👋 A common task when extracting malware configurations at scale is obtaining function boundaries and references. The most typical example is string de…
[ ARCHIVE ]
CFG again 👋 A common task when extracting malware configurations at scale is obtaining function boundaries and references. The most typical example is string de…
Click trap: not only for users, but also for link analyzers 🐭 When manually analyzing links, we typically ask ourselves only one question — “is it safe?” ✔️❌ Tr…
Dissecting network traffic with ML in search of new malware 📖 🧪 We — the network expertise department team of the ESC antivirus laboratory and the machine learn…
PDQ-Masters 🧙♂️ The main attack vector using malware is phishing campaigns via email. The ideal phishing email with malware differs from a legitimate email onl…
Sold a phone with my personal data ☹️ When purchasing donor devices on platforms for selling personal items, a negative trend is emerging: many people rarely wo…
A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…
Using IoC in a Non-Standard Way. Part 2. Threat Landscape 🧘♀️ Earlier, we discussed how to use indicators of compromise for Threat Hunting. This time, we’ll ta…
Using IoC in a non-standard way. Part 1. Threat hunting 🧐 When we talk about indicators of compromise, we usually mean a reactive approach to defense: a securit…
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simples…
Continuing to reproduce the attack from the post above 🔼 3️⃣ Creating a public API Gateway trigger (screenshot 1) At the end, we need to expose the function to…
☁️ AWS backdoor as a service: persistence in the cloud via Lambda The cloud threat landscape is constantly evolving, and attackers are increasingly abusing legi…
How to create rules for network traffic to address a future threat 🤨 This was discussed this week in China during the third cybersecurity summit, which included…