profile-img
The DFIR Report

@TheDFIRReport

Real Intrusions by Real Attackers, the Truth Behind the Intrusion.

Services: https://t.co/XW613EKt2w

calendar_today03-04-2020 01:33:43

1,2K Tweets

52,4K Followers

0 Following

The DFIR Report(@TheDFIRReport) 's Twitter Profile Photo

A threat actor recently dropped/executed Network Scanner (NS.exe) in the honeypot. This time, it was bundled with NJRAT.

➡️NJRAT: C:\ProgramData\Synaptics\Synaptics.exe
➡️C2: 69.42.215[.]252:80
➡️VT: virustotal.com/gui/file/e4b0f…
➡️Any Run: app.any.run/tasks/566223f6…

A threat actor recently dropped/executed Network Scanner (NS.exe) in the honeypot. This time, it was bundled with NJRAT. ➡️NJRAT: C:\ProgramData\Synaptics\Synaptics.exe ➡️C2: 69.42.215[.]252:80 ➡️VT: virustotal.com/gui/file/e4b0f… ➡️Any Run: app.any.run/tasks/566223f6…
account_circle