My team #Kimbabasaksaksak recently won 1st place at the Digital Forensics Challenge 2023.๐
๐Hereโs writeup -> https://t.co/OMUO3vnHQH
#Forensics#CTF#DFC
#SearchAndRescue@USCG crews are searching for 36-year-old Vitali Kremez, last seen wearing a black wetsuit and scuba tank while diving near #HollywoodBeach, Florida.
Anyone with information is asked to call Sector Miami at (305) 535-4472.
#MASSCAN#RANSOMWARE#MASSCANRANSOMWARE adds ".MASSCAN-{1 of "F", "R", "G"}-{first 8 characters of a GUID}" to the file extension.
There are slight differences between the three types(F, R, G).
Ransom note : "RECOVERY INFORMATION !!!"
#Symrise#Clop#Ransomware#TA505
Signed : Insite Software Inc.
(Signature Date : 2020-12-11)
MD5 : ed9b015082f1be50fcf08fecdb6f76d1
https://t.co/u4NEnZv3MY
@Deepesh349 As you can see in the last ransom note capture. Clop Ransomware writes a ransom note specifying the target company as "Dear ~". (ex. Software AG, NOVABIO, kmall) This could be one of the reasons. ๐
#TA505#CLOP#ransomware ๐
โ๏ธ Signed : Infoware Cloud Limited(this certificate first used in Oct 2019 by TA505)
โ๏ธ MD5 : 4dfb145cec1456cf6cf145f32f01ceff
โ Related Sample : 92d0ca02e6874926e5b5fe7cf7351d7b
- Same certificate with Clop
- Enable Window Defender
#SNAKE#Ransomware
โ๏ธ GetAddrInfo of "https://t.co/KUD9Zrt1fw"
โ๏ธ block inbound and outbound traffic that does not meet the subsequent firewall rules
โ๏ธ turn off Windows Firewall
MD5 : ed3c05bde9f0ea0f1321355b03ac42d0
#EKANS#HONDA