Some of these servers show similarities with known attacker infra, like hosting *.js files. We observed compromised FortiManager devices use cURL to retrieve such files, e.g. dom.js. Another server had a file named https://t.co/DxfZJxlGrO, which is also a valid FortiManager version.
These are not hard links to FortiJump, but we wanted share this before going into the weekend.
#happyhunting #sharingiscaring
Our SOC detected suspicious activity from 158.247.199[.]37 directed at FortiManager ports as early as May 2024. #threatintel#fortianalyzer#fortijump
https://t.co/kRBlM8SNID
@JuhoJauhiainen@FitsecLtd Are you familiar with Fitsec? Their X/Insta is looking dubious to say the least. Video related to Akira is also AI generated.
A new year, a new Dissect release! Dissect v3.12 ๐ท
Highlights (1/2):
- FortiOS platform is now supported as a Linux sub-OS
- Improved parsing of complex ACLs in NTFS
- Sparse indirect blocks in ExtFS now work properly
- Windows and Linux PuTTY artefact parsing plugin added
We created Skrapa, a zero dependency and customizable Python library for scanning Windows and Linux process memory. Harnessing memory attributes, Skrapa elevates your capability to explore patterns in memory. ๐ https://t.co/giEDUsnA9o
Dissect Release v.3.10ย is available!
- New Unix unified configuration parser
- New volumes for LUKS V2 and DDF
- New OVA files loader
- New etc plugin based on the unified configuration parser
- Dry run and exclude command added to target-query
https://t.co/k2F9oUYwbV
Today we celebrate the 1 year anniversary of open sourcing Dissect, and what a year it has been!
And like it was meant to be: today Dissect inventor @Schamperr will take the stage at @OneConferenceNL together with the Joint Sigint Cyver Unit and talk Dissect.
๐ฆ๐
@UID_ Betalingen verbieden is in mijn optiek ook niet de oplossing. Maar waarom beginnen we niet met een registratieplicht bij ransomwarebetalingen (confidentieel richting de overheid)? Alleen dit zou al veel informatie geven over de ernst van de situatie in Nederland.