Security Analyst | Blue Team | Windows Engineer | Father | Lover of coffee and whiskey | Wishing we wouldn’t be a$$holes to one another | Opinions are my own
Observed a new RMM tool in the wild today. I don't see this tool listed on https://t.co/i24emEBxrW
Miradore Online Client
MiradoreClient.exe
More IOCs found here:
https://t.co/RTdvxVzUZK
@svch0st I’ve always enjoyed the DFIR reports you’ve worked on and wanted to ask what tooling you use to build the visual timelines for your investigations? I’m looking for suggestions on building quality visuals for our reports/write ups. Thx!
Thanks @olafhartong for taking the time to chat with the team and I! I appreciate you sharing your experiences and helping to validate the path we're headed down.
Seeing a large uptick in #Darkgate#malware over the past 48 hours.
.xlsx > wscript.exe > powershell.exe > certutil.exe | AutoHotKeys.exe | attrib.exe +h C:/\d{2,4}
.xlsx naming: \w{3,}-\w{4,6}-\w{3,8}\.xlsx
.vbs naming: EXCEL_OPEN_DOCUMENT.vbs
Microsoft has identified new Qakbot phishing campaigns following the August 2023 law enforcement disruption operation. The campaign began on December 11, was low in volume, and targeted the hospitality industry. Targets received a PDF from a user masquerading as an IRS employee.