[ GROUP // INDICATORS & C2 // 48 ITEMS ]

INDICATORS & C2

> in section Threats

// Threats

C2 hunting: part 2.

C2 hunting: part 2. Hunting for hacker servers by external signs 😁 In the previous part, we talked about how to expand knowledge about hackers' infrastructure u…

ti_author
// Threats

(Ex)Cobalt in container

(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…

oUth0R
// Threats

Your hash, please… Thank you!

Your hash, please… Thank you! 🙏 In early January, we discovered a file that drew attention for its content and structure. An examination of the document's metad…

ti_author
// Threats

Lok'tar ogar!

Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…

global_author
// Threats

One lazy driver

🚘 One lazy driver Recently, the PT ESC cyber intelligence group discovered an executable file with an "unusual" name, reinforced by a distinctive PDF file icon…

ti_author
// Threats

Copy, copy, can you hear us?

Over, over, can you hear us? 😲 Despite the fact that hackers have recently gotten lazy and increasingly don't develop anything of their own, original attack ide…

ti_author