Who even are these PhaseShifters of yours?
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…
Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…
🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that lande…
A word about the obfuscated batch file... We're publishing this post as a follow-up to the recent one about the EXE hidden under a hex dump in a Base64 request…
📫 X-Filtering of User Data In the process of analyzing email traffic, we periodically encounter the implementation of unusual malicious techniques. Today we wan…
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
How to get to the internet 🚶♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…
Gsocket: how to find one of the most popular tools 🙂 In the course of investigating numerous incidents involving the compromise of Linux nodes, we often discove…
TLS on the network: what to do 🤷♂️ You are a powerful network traffic analysis engine. You work for the benefit of the information security system, grinding th…
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…