Excited to be teaching ARTOC @defcon this year!
Focused on modern tradecraft, tooling development, and building real skills from preparation to execution of real-world adversary emulation engagements.
#DEFCON#redteam
@luke92881@SquiblydooBlog@JAMESWT_MHT@SebastianWalla @AnFam17 @osipov_ar I've seen this before and I had issues retrieving the script prior due to AV, but thank you for the sample. I got the the remaining pieces to the puzzle now. If you need the decryption method, its there for you.
https://t.co/Hg00ie6bGz
@nosecurething Observed four hits so far, but different dir path. In the process of retrieving the file atm. Hashes were all the same.
profile\AppData\Local\Installinipsk\avolkov.exe
d75680a5fcfd6839d40e5b4e379726ec0c01278709265ace4f1ba7327886b41c
@th3_protoCOL Any sandbox of the initial delivery mechanism that created this scheduled task? I am the threat actor may have taken a similar approach as to using an ISO to deliver the executable. Upon investigation, I did not see any signs of mounting of ISO or executable as of yet. 1/2