LSDM · @lsdm
418 followers · 2624 posts · Server mamot.fr
Scripter :verified_flashing: · @scripter
255 followers · 1292 posts · Server social.tchncs.de
Scripter :verified_flashing: · @scripter
255 followers · 1291 posts · Server social.tchncs.de
Tarnkappe.info · @tarnkappeinfo
2090 followers · 4472 posts · Server social.tchncs.de
Colin Cowie · @th3_protoCOL
613 followers · 152 posts · Server infosec.exchange

After a brief hiatus (life happens😅)​ I'm picking back up with Day 5️⃣​- Detecting clipboard patterns used by cryptocurrency stealers!

🔗​: github.com/colincowie/100DaysO

📖​ Background reading on clipboard stealer: decoded.avast.io/janrubin/vipe

I had trouble with this rule when using strings. Switching to hex-based detection worked a lot better!

#100DaysofYARA #vipersoftx

Last updated 3 years ago

TechHelpKB.com 📚 · @techhelpkb
233 followers · 1207 posts · Server mastodon.social

A malicious for -based web has been observed to be distributed via a long-standing information stealer called . tchlp.com/3gsbuxD

#extension #chromium #browsers #windows #vipersoftx

Last updated 3 years ago

TechHelpKB.com 📚 · @techhelpkb
339 followers · 1848 posts · Server mastodon.social

A malicious for -based web has been observed to be distributed via a long-standing information stealer called . tchlp.com/3gsbuxD

#extension #chromium #browsers #windows #vipersoftx

Last updated 3 years ago

Jan Rubín · @janrubin
17 followers · 9 posts · Server infosec.exchange

stealer is still kicking and distributing another stealer in the form of a browser extension for Chromium-based browsers, called , which performs man-in-the-browser attacks and much more.
Read my latest analysis on
decoded.avast.io/janrubin/vipe

#vipersoftx #venomsoftx #AvastDecoded

Last updated 3 years ago