Useful Friday post
Useful Friday post 🫥 During threat research, there is often an urgent need to examine a malicious file/URL/domain. In this post, we have gathered the tools we a…
[ ARCHIVE ]
Useful Friday post 🫥 During threat research, there is often an urgent need to examine a malicious file/URL/domain. In this post, we have gathered the tools we a…
Attackers compromised dozens of NPM packages with ~2 billion downloads 🐾 What happened As part of a phishing campaign, maintainer Josh "Qix" Junon was…
Curing a problem 🔧 Recently, researchers from ARMO presented a paper and PoC for the Curing malware, which uses the io_uring interface to bypass monitoring of f…
Generating a COM vtable in IDA 🐍 While analyzing one of the Snake Keylogger variants, we needed to figure out which managed methods the native module calls thro…
OldGremlin with old tricks OldGremlin is known as a ransomware group 😭. To stop antiviruses (and any programs, for that matter) from running, it loads TinyKille…
Deep Dive into Imports: Continuing to Explore Static Resolution Techniques 🕵️♂️ Earlier we discussed how static import resolution can be implemented. However…
Pass Back vulnerabilities: what they are and how dangerous they are 🧐 There is a whole class of vulnerabilities that at first glance look harmless, and even hav…
HTML attachments as a phishing tool 🤑 Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting wit…
And we have big news!😡 At PT ESC, the Antivirus Laboratory has opened: we have combined the expertise of "VIRUSBLOCKADA" with our own, analyzing numerous sample…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
🧤 Now about the exploitation of the vulnerability CVE-2025-33073: • A domain account with the most ordinary privileges. • SMB signing is not enforced on the tar…
Reflection Relay. It never happened before, and now it's happening again (CVE-2025-33073) 😐 One of the most popular techniques for privilege escalation in an Ac…