Stealer infection: a new USB strain
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…
⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…
🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that lande…
Have you heard about the public repository of Suricata rules Attack Detection? Yes, that's meeee Within the large PT Expert Security Center team, there is a sep…
A word about the obfuscated batch file... We're publishing this post as a follow-up to the recent one about the EXE hidden under a hex dump in a Base64 request…
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
🔎 Quick-and-dirty network research, or How to find a new, previously undiscovered activity of a known group in 15 minutes While analyzing external expertise on…
🥷 Cobalt Strike Beacon and MSBuild The practice of our incident investigations shows that threat actors are still using the Microsoft Build Engine to compile .N…