Stef Rand · @techieStef
129 followers · 5 posts · Server infosec.exchange

Our monthly Intelligence Insight for December is out!

Highlighted topics this month are (aka aka ), and recent changes to TTPs.

redcanary.com/blog/intelligenc

#yellowcockatoo #solarmarker #jupyterinfostealer #Gootloader

Last updated 3 years ago

Stef Rand · @techieStef
134 followers · 7 posts · Server infosec.exchange

Our monthly Intelligence Insight for December is out!

Highlighted topics this month are (aka aka ), and recent changes to TTPs.

redcanary.com/blog/intelligenc

#yellowcockatoo #solarmarker #jupyterinfostealer #Gootloader

Last updated 3 years ago

David Prahl · @infosec_chonk
15 followers · 37 posts · Server infosec.exchange

Whoa. You can use OpenAI to deobfuscate . Here's a chunk of old , which it correctly summarized.

#malware #solarmarker #infosec

Last updated 3 years ago

Jérôme Segura · @malwareinfosec
174 followers · 22 posts · Server infosec.exchange

The campaign which normally delivers , or is currently redirecting to a tech support scam :blobeyes:​

friscomusicgroup[.]com/br2

existsupport22[.]z13[.]web[.]core[.]windows[.]net

#sczriptzzbn #netsupportrat #solarmarker #icedid

Last updated 3 years ago

seadev · @seadev
123 followers · 65 posts · Server infosec.exchange

This awesome blog about / / infostealer by Squiblydoo doubles as a really great beginner walk through from a blue team perspective. They provide easy to spot red flags, and explain how to break down a script into digestible pieces.

squiblydoo.blog/2022/09/27/sol

#solarmarker #yellowcockatoo #jupyter #powershell

Last updated 3 years ago