__atinder__ · @__atinder__
1 followers · 5 posts · Server cyberplace.social

using another LOLBIN colorcpl.exe as alternative to copy bitsadmin to different path before executing

isc.sans.edu/diary/rss/29814

#guildma

Last updated 2 years ago

Brad · @malware_traffic
2051 followers · 79 posts · Server infosec.exchange

2023-01-03 (Tuesday) and 01-04 (Wednesday): Doing this as a separate post as well...

Follow-up on activity reported in today's (2023-01-05) ISC diary at: isc.sans.edu/diary/More%20Braz

A more complete list of indicators, files, and () malware samples now available at: malware-traffic-analysis.net/2

On the first pcap, I opened the banco.bradesco site in a web browser after letting the infection run overnight. So that particular traffic was -not- caused by the malware.

After opening that banking website, the infected host immediately generated more HTTP POST requests, sending encoded data to the C2 server.

#pcap #astaroth #guildma

Last updated 3 years ago

Brad · @malware_traffic
2054 followers · 79 posts · Server infosec.exchange

@sans_isc A more complete list of indicators, files, and () malware samples from this diary are now available at: malware-traffic-analysis.net/2

#pcap #astaroth #guildma

Last updated 3 years ago

ISC diary: @malware_traffic finds more pushing () in January 2023 i5c.us/d29404

#malspam #astaroth #guildma

Last updated 3 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Ghimob Android Banking Trojan Targets 153 Mobile Apps - A banking trojan is targeting mobile app users in Brazil - and researchers warn that its operator ... threatpost.com/ghimob-android-

#google #ghimob #brazil #tetrade #guildma #android #mobileapp #bankingfraud #cybercriminal #bankingtrojan #mobilesecurity

Last updated 5 years ago