Slam screen locker. What are you?
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
Methods for Masking a Virtual Environment 😷 During malware analysis, you may encounter samples that will not function fully in a virtual environment. This is be…
Everyone says: learn the basics! But how do you use them afterward? For example, like this 👇 1. Base64 — an encoding algorithm that can encode any data as a seq…
Gsocket: how to find one of the most popular tools 🙂 In the course of investigating numerous incidents involving the compromise of Linux nodes, we often discove…
TLS on the network: what to do 🤷♂️ You are a powerful network traffic analysis engine. You work for the benefit of the information security system, grinding th…
🟥 ⚔️ 💿 Virtual Disk as the Start of an Attack In early September, experts from the TI cyberintelligence group of the PT ESC department discovered an interesting…
Phishing Legitimacy 😂 During an analysis of one phishing email, we noticed how attackers attempted to place phishing content on a page of the telegra․ph domain…
How not to fight obfuscation 🫤 Automatic configuration extraction simplifies the identification of new C2s. We reverse a malware family, find the configuration…
🗂 Useful Data Sources: MISP Warning Lists Information security analysts deal with massive volumes of threat data on a daily basis. To extract the most relevant…
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
Proxying WebSocket nginx — payload detection 👀 Checking configurations of various services sometimes helps find unknown malware that is not detected by antiviru…
😈 Exfiltration Gone Wrong When investigating incidents, we periodically encounter threat actors exfiltrating data before encrypting infrastructure. One of the e…