Today I got the first ever LockBit 3.0 Ransomware sample on my hand, my initial findings are:
1-) They are using Anti Analysis technique to hide them self.
2-) It don't executed without a Password just like BlackCat.
3-) It have command line argument feature 🧐
@vxunderground
Subdomain enumeration with open source tool called SubEnum > F5 BIG-IP (CVE-2023-46747) exploit > ARP scan on internal network after the exploit > Port / Service enumeration > Lateral movement to MSSQL Database Server > Credential dump from MSSQL server > RDP into MSSQL server > data exfiltration.
Linked to the Cyber Court and Makhlab al-Nasr, Pro-Palestinian hacking group. cc @BushidoToken
I love my chaotic keyboard situation
Keychron K2 board
Mode Signal switches
3 different sets of key caps
Custom built by by another YouTuber🤓 https://t.co/qZNTYOSNkq
Boot into Safe Mode, "Advanced Startup" with Command Prompt, and use this command to remove faulty channel files:
del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"
This is a better choice than changing the folder name for the CrowdStrike driver, but as always, YMMV.