Where can I find the PowerShell command history?
Where can the history of PowerShell commands be found? 🧐 Surely the first things that come to mind are Windows logs and the ConsoleHost_history.txt file, but th…
[ ARCHIVE ]
Where can the history of PowerShell commands be found? 🧐 Surely the first things that come to mind are Windows logs and the ConsoleHost_history.txt file, but th…
A fool and his money are soon parted, APK is not a video 🦣 In late 2024 — early 2025, information about the spread of the Mamont virus in Telegram was actively…
Static resolution of imports 👨💻 Dynamic resolution of imports by hash sums in malware is a well-worn topic, but to perform static analysis it is necessary to l…
How long has it been since you reversed JavaScript? 😲 Continuing the phishing theme (we previously looked at targeted suspicious documents leading to initial ac…
Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…
😏 Useful tools: Mandiant capa Imagine the situation: you are a malware analyst or an incident response specialist and you need to analyze a large volume of bina…
🔄 Major malware rules update Suricata I hope you remember that we have a public Suricata rules repository (we wrote about launching the resource in another post…
📲 Cloud services from the "MeHaFon" operator News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government orga…
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…
An endless chain of redirects ♾️ Quite often, when sending phishing links via email, attackers do not attach them explicitly to the email but use various redire…
How to fix CFG 🔧 In the process of reverse engineering malware, we encounter cases where obfuscation hinders understanding the overall algorithm. One example is…
🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that lande…