Gobot #IoTMalware#botnet#opendir
-supports macOS
-written in Go
-controlled via IRC
macho -5b1219ae05b3128f7028fa3f788f33ea
x86 - d6bda304f4a59e36e5ffefe421d84396
I will be presenting at the #CSO50 conference in April in Arizona. I will be discussing #phishing and #malware detection in an automated fashion using #machinelearning.
Heads up: @bankofireland 365 Online phishing campaign at online365boi[.]eu currently happening. Propagating through text on a Sunday afternoon. Please don't fall for it. Cc: @talktoBOI@irisscert@malwrhunterteam
@bankofireland 365 Online phishing campaign making the rounds again. Via SMS. The phishing site is 365boi[.]net. Note that the legitimate is https://t.co/Eb8SX8oo21.
Cc: @talktoBOI@irisscert@malwrhunterteam
OK, folks, I hear that John McAfee claims to have invented cyber security. (I don't know; he has blocked me.)
Gather 'round the fire, kids, for a short story, because I was around at the time.
New #Emotet epoch 1 payloads as of 09:00EDT+:
https://t.co/2QebcSHxxH
/www.yetanothersteve.com/Xs6TPwnAAJ/
/flewer.pl/pub/s99556m/
/www.hotelcapital.ru/f6FBJD/
/dc.amegt.com/wp-content/oC4gy4aGL/
/www.armanitour.com/kuNOqI/
New #Emotet Epoch 1 payloads as of 11:30EDT+:
https://t.co/7QaWnFubqH
/www.avemeadows.com/gbPAHU/
/kosilloperutours.com/mrep9aHq/
/www.customaccessdatabase.com/joiuehtr/9g94p2/
/www.deimplant.com/CFsF9RU/
/nfusedigital.co.za/ECbcfDxq/
Heads up: @bankofireland 365 Online phishing campaign at online365boi[.]eu currently happening. Propagating through text on a Sunday afternoon. Please don't fall for it. Cc: @talktoBOI@irisscert@malwrhunterteam
New #emotet epoch 1 payloads 19:30EDT+ and new/old doc look. We are back to the Wells Fargo Overlay again:
https://t.co/dLHyEtEE81
/www.apiperjuangan.com/LrfK/
/www.graca.com.np/zCtof/
/www.answerthebeacon.com/YYCUNZ0/
/www.imperiaskygardens.site/Su7FZ/
/www.katexs.com/rogV/
Here is today's notes for #emotet. I go into more in depth analysis of the dual variant/epoch hypothesis in the notes section at the bottom. IOCs are at the top like normal. Will keep updating as I can. https://t.co/v4wRyFheB6