Learning to Recover VMProtect Imports
Learning to Recover VMProtect Imports ⚙️ VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only si…
[ ARCHIVE ]
Learning to Recover VMProtect Imports ⚙️ VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only si…
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
Catching bug hunters again 💀 In one of our previous posts we wrote about traces of bug bounty activity targeting "Yandex". History repeated itself, but this tim…
🛠 Reverse Engineering Delphi without IDR When you're actively involved in reverse engineering, sooner or later you encounter an executable file written in Delph…
🟥 ⚔️ 💿 Virtual Disk as the Start of an Attack In early September, experts from the TI cyberintelligence group of the PT ESC department discovered an interesting…
Colonels write first! (🔞) The collection of malicious mass mailings sent in the name of law enforcement agencies has a new addition. In September, several recip…
Phishing Legitimacy 😂 During an analysis of one phishing email, we noticed how attackers attempted to place phishing content on a page of the telegra․ph domain…
СHavocают Recently, a phishing email fell into our hands. The email subject is in the best traditions of phone spam calls, when someone calls you from the FSB a…
🗂 Useful Data Sources: MISP Warning Lists Information security analysts deal with massive volumes of threat data on a daily basis. To extract the most relevant…
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…
Open source passions: part two Infostealers 🧋 No one is surprised by them anymore, since this is a popular class of malware, often mentioned in the news. Most t…