Randy :donor: · @rmceoin
148 followers · 421 posts · Server infosec.exchange

Here's a handy script to gather up hashes for all Rclone releases, along with the current results.

gist.github.com/rmceoin/efedac

The recent year in review by has a ton of great intel and as I've seen many times before rclone is called out. It is frequently used for exfil.

So, along with other tools, rclone has been on my hit list to chase down the hashes and see what our defenses think of them and if used internally.

It turns out Rclone is on GitHub and appears to host the last several years of releases there. With a little GitHub and Bash magic out pops all the recent hashes. I stayed focused just on the Windows hashes.

No doubt a TA would pivot to another method, but the hope would be it'd delay them and help set off more alarms as they bump around.

#dfirreport #threatintel

Last updated 1 year ago

Ján Trenčanský · @j91321
74 followers · 127 posts · Server infosec.exchange

2022 year in review is out. Great reading as always. thedfirreport.com/2023/03/06/2

#dfirreport

Last updated 1 year ago

acrypthash👨🏻‍💻 · @acrypthash
189 followers · 87 posts · Server infosec.exchange

The new report from is insane!

#dfirreport

Last updated 2 years ago

acrypthash👨🏻‍💻 · @acrypthash
189 followers · 87 posts · Server infosec.exchange

Last spam toot and then I need to get into the projects, the new is out!

thedfirreport.com/2022/10/31/f

#dfirreport

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online