Colin Cowie · @th3_protoCOL
681 followers · 303 posts · Server infosec.exchange

My latest blog: Decoding a New JavaScript Malware Campaign!
🔗​ th3protocol.com/2023/New-JS-Ma

Earlier today researchers from HuntressLabs shared observations about a case involving RClone. They identified initial access as a javascript file named “Invoice-DocuSign-Mar03-2023.js"

In my blog post I walk through analyzing this JavaScript malware, identifying persistency and decoding C2 traffic!
: github.com/colincowie/colincow

🔗​ poc for decoding the C2 traffic:
gist.github.com/colincowie/2bb

💬​ Authors Note:
Recently I've been feeling a little bit burnt out - this research excited me and provided some internal encouragement 😃

​​

#AvosLocker #iocs #threatintel #cti #malware #ransomware #javascript #virustotal

Last updated 1 year ago

grey · @grey
59 followers · 49 posts · Server infosec.exchange

AvosLocker looks to be taking a more active stance in purchasing access. They've moved from bidding in single auctions to listing a purchase offer for any valid privileged RDP/VPN/Citrix/RDWeb/Pulse Security access.

#threatintelligence #threatintel #cti #ransomware #AvosLocker #ctituesday

Last updated 2 years ago

grey · @grey
64 followers · 77 posts · Server infosec.exchange

AvosLocker looks to be taking a more active stance in purchasing access. They've moved from bidding in single auctions to listing a purchase offer for any valid privileged RDP/VPN/Citrix/RDWeb/Pulse Security access.

#threatintelligence #threatintel #cti #ransomware #AvosLocker #ctituesday

Last updated 2 years ago

grey · @grey
64 followers · 77 posts · Server infosec.exchange

After a several week hiatus has started bidding in auctions held by initial access brokers again. I expect to see new victims posted soon on their blog.

#AvosLocker #osint #threatintel #cti #ransonware #thrunting

Last updated 2 years ago

grey · @grey
57 followers · 39 posts · Server infosec.exchange

Looks like has apparently stopped buying up access on darknet forums as of 11/17 and is getting close to the two month mark of no publicly posted victims. Going out with a whimper or rebranding? Only time will tell.

#AvosLocker #threatintelfeed #threatintel #cti #ransomware #thrunting

Last updated 2 years ago

grey · @grey
57 followers · 39 posts · Server infosec.exchange

Has anyone else noticed that hasn't posted to their blog in over 40 days? I wonder if they're rebranding or trying to keep a low profile. They are still posting on certain forums buying up access 👀

#AvosLocker

Last updated 2 years ago

Günter Born · @gborn
504 followers · 2049 posts · Server social.tchncs.de
Tarnkappe.info · @tarnkappeinfo
1530 followers · 3787 posts · Server social.tchncs.de
Tarnkappe.info · @tarnkappeinfo
1530 followers · 3787 posts · Server social.tchncs.de