[ GROUP // GENERAL // 103 ITEMS ]

GENERAL

> in section Detection

// Threats

OWOWA

⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…

oUth0R
// Threats

Gapucino* is GOFFEE

Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…

oUth0R
// Detection

Here's the continuation

🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that lande…

global_author
// Detection

X-user data filtering

📫 X-Filtering of User Data In the process of analyzing email traffic, we periodically encounter the implementation of unusual malicious techniques. Today we wan…

global_author
// Threats

How to get on the internet

How to get to the internet 🚶‍♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…

oUth0R
// Threats

C2 hunting: part 1

C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…

ti_author
// Threats

Team46 group attacks

Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…

ti_author