Added some more #KQL queries to the repo. 🏹
- Scheduled Task AppData
- Defender AV Exclusion Events
- Rare .lnk File Created on Desktop
https://t.co/EcTUgZCwcy
The queries were already supported in #KustoHawk
Interesting new project: 'LOLbin-CTI Driven'. It's an app that visually demonstrates how a LOLbin can be used during an intrusion. And it uses the STIX format. 👍
#infosec#malware#lolbin#threatintel
👉App: https://t.co/paV7I9UtvJ
👉Project: https://t.co/Nq6eaqwOJ1
#TA577 - Back on the scene pushing #Darkgate
Time to resume tracking operations, welcome back Tramp.
Distro 👇
url > zip > lnk
url > xll
pdf > url > xll > msi
Samples 👇
https://t.co/IF3KJIbPjf
https://t.co/b49huhI9FI
https://t.co/YNz4LgCWXO
https://t.co/2oP6ZKlNUL
#Follina (cve-2022-30190)
THE FUTURE OF OCC MEETINGS IN 2022.docx
d16427f5cff23f456934e7aecaba226c
https://consumerfinanceguide[.]com/blog/index/blog.html
(The domain is registered 8 days ago)
The payload seems to be #CobaltStrike
gpupdate.exe
8336a6aeb41b066918c5cc7f27a4c36b
#Follina CVE-2022-30190
Payment Notification.pdf.RTF
https://t.co/cfOw1ifHdi
Not your normal "default Apache2 welcome page"
URL: http://simpant[.]sc[.]ug/ccc/expl.html
https://t.co/YwWuCnwWPi
In phishing mail attachments we often find a suspicious name or double extension (e.g. .doc.exe) in the directory records of an attached ZIP archive
Let's use that for a generic #YARA rule that detects ZIP archives with these characteristics
https://t.co/beSnZttzv0
Let's detect these ZIP attachments with .lnk file contents
- magic header check
- size
- location of string ".lnk" relative to end of file
Example
https://t.co/pvgGLcGZvI
Now Lapsus$ claims on its Telegram channel that it's compromised Okta as well as Microsoft and LG Electronics lately.
It previously hit Nvidia, Samsung, and others. Context: https://t.co/TdSNooeiQW
Further background: https://t.co/v0EBteEyeu
.@TrendMicro released a paper on a new ransomware variant named "Nokoyawa". TrendMicro believes Nokoyawa to be connected to the notorious HIVE ransomware group.
HIVE recently ransomed Rompetrol, the 2nd largest gas-station network in Romania.
Download: https://t.co/zpxqOAxMhX
A botnet of thousands of compromised #GitLab instances (exploited via CVE-2021-22205) is generating DDoS attacks in excess of 1 Tbps. Please patch your servers!
So again @Microsoft@onedrive hasn't acted on abuse reports since Thursday. Now #Hancitor is using it for doc delivery and #BazaLoader#BazarLoader is using it for zip > iso > lnk/DLL. 374 files not acted on, every single one will lead to #ransomware several times over!