[ ARCHIVE ]

Author: global_author

// Practice

Useful Friday post

Useful Friday post 🫥 During threat research, there is often an urgent need to examine a malicious file/URL/domain. In this post, we have gathered the tools we a…

global_author
// Threats

Curing a problem

Curing a problem 🔧 Recently, researchers from ARMO presented a paper and PoC for the Curing malware, which uses the io_uring interface to bypass monitoring of f…

global_author
// Threats

OldGremlin with old tricks

OldGremlin with old tricks OldGremlin is known as a ransomware group 😭. To stop antiviruses (and any programs, for that matter) from running, it loads TinyKille…

global_author
// Threats

And we have big news!

And we have big news!😡 At PT ESC, the Antivirus Laboratory has opened: we have combined the expertise of "VIRUSBLOCKADA" with our own, analyzing numerous sample…

global_author
// Detection

Detecting CVE-2025-33073

Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️‍♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…

global_author