Phishing legitimacy
Phishing Legitimacy 😂 During an analysis of one phishing email, we noticed how attackers attempted to place phishing content on a page of the telegra․ph domain…
[ FEED // CHRONO // 267 ITEMS ]
Phishing Legitimacy 😂 During an analysis of one phishing email, we noticed how attackers attempted to place phishing content on a page of the telegra․ph domain…
How not to fight obfuscation 🫤 Automatic configuration extraction simplifies the identification of new C2s. We reverse a malware family, find the configuration…
СHavocают Recently, a phishing email fell into our hands. The email subject is in the best traditions of phone spam calls, when someone calls you from the FSB a…
🗂 Useful Data Sources: MISP Warning Lists Information security analysts deal with massive volumes of threat data on a daily basis. To extract the most relevant…
We, ESC-VR, have successfully reproduced the exploit for CVE-2024-30085 😎 The vulnerability was featured at the recent Pwn2Own 2024 in Vancouver, where Team The…
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…
Open source passions: part two Infostealers 🧋 No one is surprised by them anymore, since this is a popular class of malware, often mentioned in the news. Most t…
Open Source Drama: Mafia, Stealers, and Bug Hunting of Yandex Projects 🐱 Over the past two weeks, a lot of interesting things have happened in the Python Packag…
Proxying WebSocket nginx — payload detection 👀 Checking configurations of various services sometimes helps find unknown malware that is not detected by antiviru…
By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…
😈 Exfiltration Gone Wrong When investigating incidents, we periodically encounter threat actors exfiltrating data before encrypting infrastructure. One of the e…