Dissect update
Say hello to Dissect version 3.21
- Minimum Python version is now 3.10
- New dissect.apfs project โ initial support for macOS, available through the API
- Improved usability for interacting with nested targets
- Support for CramFS and Apple Sparse Image Format (ASIF)
And much more! check out the full release notes https://t.co/14R0adcZ20
Sharing is caring! We've uploaded malware samples from our latest Lazarus research to VirusTotal (d86c51db1a0f3c6b71b1b62a766d6daa). This includes macOS, Linux and Windows samples used by this actor, such as custom screenshotters and keyloggers. See our blogpost for the hashes: https://t.co/JJ71mCw4kp
๐ก๐ฒ๐ ๐๐ถ๐๐๐ฒ๐ฐ๐ ๐ฟ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ ๐.๐ฏ.๐ฎ๐ฌ.๐ญ ๐ถ๐ ๐ผ๐๐!
Important: deprecation notice for Python 3.9, next Dissect version will support Python 3.10 and up
- VMFS implementation rewritten from scratch
- Mounting btrfs subvolumes with target-mount enabled
- Performance improvements in dissect.util converting to Rust
- Reduced memory consumption by extfs
And much more! For full details see the release notes
https://t.co/OINLQNzmjZ
๐ง ๐ก๐ฒ๐ ๐ฏ๐น๐ผ๐ด: "๐ง๐ต๐ฟ๐ฒ๐ฒ ๐๐ฎ๐๐ฎ๐ฟ๐๐ ๐ฅ๐๐ง๐ ๐๐ผ๐บ๐ถ๐ป๐ด ๐ณ๐ผ๐ฟ ๐ฌ๐ผ๐๐ฟ ๐๐ต๐ฒ๐ฒ๐๐ฒ"
Read about PondRAT, ThemeForestRAT and RemotePE - three RATs we encountered during incident response involving the Lazarus group.
Check the indicators and don't let them steal your cheese!
#ThreatIntel #Lazarus #DFIR
https://t.co/JJ71mCw4kp
๐Great news for #DFIR folks! Dissect now supports both BitLocker & LUKS encrypted disks, making forensic analysis smoother and more comprehensive. Another step forward for digital forensics capabilities! Read more in this blog: https://t.co/r2LTD0sJqm #InfoSec#DigitalForensics
Dissect release v3.17 - what's new?
๐นSupport for BitLocker and LUKS encrypted disks
๐นSupport for BSD Vinum volumes
๐นA new MSSQL log parser
๐นRetrieve installed Ubuntu Snap & Windows applications
๐นNow possible to create aliases in target-shell
https://t.co/LhkbM62fYZ
Some of these servers show similarities with known attacker infra, like hosting *.js files. We observed compromised FortiManager devices use cURL to retrieve such files, e.g. dom.js. Another server had a file named https://t.co/DxfZJxlGrO, which is also a valid FortiManager version.
These are not hard links to FortiJump, but we wanted share this before going into the weekend.
#happyhunting #sharingiscaring
Pivoting on the SimpleHTTP server on port 443 (but not TLS) and ASN 20473 we found servers that are likely related to the #FortiJump#FortiManager CVE-2024-47575 exploitation campaign that are not yet publicly mentioned. IOCs:
* 107.191.63[.]169
* 139.180.138[.]190
* 149.28.157[.]135
* 167.179.90[.]211
* 216.238.98[.]214
* 65.20.78[.]114
These servers were observed over a period between May and October 2024. #threatintel #sharingiscaring
Our SOC detected suspicious activity from 158.247.199[.]37 directed at FortiManager ports as early as May 2024. #threatintel#fortianalyzer#fortijump
https://t.co/kRBlM8SNID
Hey cyber sleuths! Dissect open source just turned two, and we're not done celebrating. Surprise! Our Dissect add-on for Splunk is now also open sourced, making your Dissect records ingestion a breeze. Prepare to enhance your Splunk powers! ๐ฅณ https://t.co/qsiwGD8PZA
Say hello to Dissect summer release V.3.15!
ยท Major rewrite of dissect core engine โ cstruct v.4.0 is now released!
ยท Target tools usability improvements
ยท MPLog parser added to Windows defender plugin
ยท Identification of Windows 11 improved
Release 3.15 ยท fox-it/dissect ยท GitHub
This blog is part of a series written by various Dutch cyber security firms that have collaborated on the Cactus ransomware group, which exploits Qlik Sense servers for initial access.
https://t.co/xdBQsVxppe
Check out our latest blog where we pluck the feathers off Android Malware Vultur's latest variants, revealing its most recent developments in masquerading malicious activity and how it maximises remote control over infected devices. https://t.co/2PIqlNnHsZ
๐ Dissect Task Board Now Live! ๐
Dive into Dissect projects, select tasks, suggest features, and code with a global community. Let's innovate together!
๐ Look under issues in each Dissect project, or use this filter (log in needed) https://t.co/inQeXqymTh
- Support for Windows installations on drive letters other than C:\
- Support for Linux systems mounts by label
Check out all features and plugins improvements in the release notes! https://t.co/sQ2OMmAgxV
Time for a new Dissect release - v.3.13 is out!
Highlights:
- New fs support for vmtar and cpio
- New plugins for Brave browser, Doker logs, and Linux locate
- JSON, YAML and XML formats added to the unified configuration parser