Here's a brief breakdown of NJRAT, that has been recently modified and used in various campaigns. Its initial steps are now concealed within VBS scripts and encoded in PowerShell, making it more challenging for malware analysts to reverse
#CyberAttack
https://t.co/gwvDVUyvRY
They lied to you about Iraq.
They lied to you about COVID.
They lied to you about Russiagate.
They lied to you about the Ukraine War.
They lied to you about beheaded babies.
But you think they’re telling you the truth about who bombed a hospital in Gaza?
Wake up.
🌐 Everest #Ransomware team just added The Brazil Government to the victim's list 🚨
Everest selling access to Gov Brazil network, "more than 3 TB of data" 🇧🇷
#Everest
Want to learn how a simple UAC bypass / priv elevation works? Start msconfig, go to Tools menu, select "Command Prompt", and click Launch. Depending on your system configuration, a shell will pop open as a child process of msconfig, with elevated privileges and higher integrity.
Little quick TIP for .NET #Reversing (DnSpyEx) -> To view field values which are not accessible in Locals -> Use the Watch Window (Debug->Windows->Watch), trust me you won´t regret and probably save some time 👍😉🤠
Anaya shoot feedback.docx
Submitted from IN
e64399c152f9bedd3ca54cccdab6469e
Attached template: https://templatesoffices[.]com/en-us/letters/tm83/csd/flyer.png
8cf97f8f60792dc2c7b9dd0ab55b0bd2
Anti-VM
ZIP file after the "@@@===@@@" marker.
- document01.docx
- theme01.xml -> PE
This payloads is awesome.
I got RXSS on https://t.co/8SpdYpjHXr with this payload.🤩
Try these once:
'-alert(1)-'
"-alert(1)-"
";alert(1)//
\"+alert(1)+"
#Malware protectors often use unique functions to #obfuscate strings. Using powershell, you can dynamically invoke those functions to bypass the obfuscation and dump hidden content. Below is an #AgentTesla malware sample de-obfuscated using this technique.
1/