SECUINFRA FALCON TEAM(@SI_FalconTeam) 's Twitter Profile Photo

Today in our section on 'uncoventional delivery': archives! 📦
ARJ (Archived by Robert Jung) has been around since the MS-DOS days and is occasionally used to deliver e.g. , or
1/4 🧵

Today in our section on 'uncoventional #Malware delivery': #ARJ archives! 📦
ARJ (Archived by Robert Jung) has been around since the MS-DOS days and is occasionally used to deliver e.g. #AgentTesla, #Formbook or #Guloader
1/4 🧵
account_circle
Saharsh(@saharshtapi) 's Twitter Profile Photo

OneNote Malware Campaign Insights
Malware List:
1️⃣ Qakbot
2️⃣ Emotet
3️⃣ AgentTesla
4️⃣ IcedID
...
research.loginsoft.com/threat-researc…

account_circle
reverseame(@reverseame) 's Twitter Profile Photo

AgentTesla - Full Loader Analysis - Resolving API Hashes Using Conditional Breakpoints embee-research.ghost.io/agenttesla-ful…

account_circle
Matthew(@embee_research) 's Twitter Profile Photo

🚨Malware Tips 🚨 - Resolving API Hashes Using Conditional Breakpoints.

By adding breakpoints and log conditions to a function that resolves api hashes, it's possible to quickly resolve api hashes in bulk.

Thread
[1/11] 👇

🚨Malware Tips 🚨 - Resolving API Hashes Using Conditional Breakpoints. 

By adding breakpoints and log conditions to a function that resolves api hashes, it's possible to quickly resolve api hashes in bulk.

Thread
[1/11] 👇

#Malware #AgentTesla #Ghidra #Debugging
account_circle
JAMESWT(@JAMESWT_MHT) 's Twitter Profile Photo

📩
⚰️>jemyy.theworkpc.]com
⚰️>109.248.144.]235:5401
⚰️>139.177.146.165:4848
⚰️>menu@rzr0ngtai.]com
🧰Samples🔽
bazaar.abuse.ch/browse/tag/jem…

📩#Vjw0rm #WSHRAT #Agenttesla
⚰️>jemyy.theworkpc.]com 
⚰️>109.248.144.]235:5401
⚰️>139.177.146.165:4848
⚰️>menu@rzr0ngtai.]com
🧰Samples🔽
bazaar.abuse.ch/browse/tag/jem…
account_circle
M.Ali(@sysk1ll3r) 's Twitter Profile Photo

d4rk3r Hey there! There is actually hex reading/writing codes contained on signature analysis module also resource checker module is detect and carve possible PE files from .NET malware samples such as AgentTesla and similar family samples.

account_circle
Hootsuite 🦉(@hootsuite) 's Twitter Profile Photo

Look, some brands are going to create incredible content for social media. They have budget, they have a big team, they have the resources, they have hired agencies.

Don't compare your work as a single social media manager to a multi-billion dollar brand. You're doing great.

account_circle
Piotr Kowalczyk(@pmmkowalczyk) 's Twitter Profile Photo

targeting 🇵🇱 in via malspam attachments:

Gz->vbs->powershell script dropping payload from:
s://tajvand.com/dgwMbIMr64.bin

Exfil through FTP: ftp[.]riodancestudio[.]com[.]au

CERT Orange Polska CSIRT KNF Mikhail Kasimov Kili JAMESWT James reecDeep

#AgentTesla targeting 🇵🇱 in via malspam attachments: 

Gz->vbs->powershell script dropping payload from:
s://tajvand.com/dgwMbIMr64.bin

Exfil through FTP: ftp[.]riodancestudio[.]com[.]au

@CERT_OPL @CSIRT_KNF @500mk500 @kilijanek @JAMESWT_MHT @James_inthe_box @reecdeep
account_circle
Fate112(@tosscoinwitcher) 's Twitter Profile Photo

RussianPanda 🐼 🇺🇦 Gi7w0rm proxylife 0xToxin🕷️ James I know this is old new but this bad actor nuked all their other payloads and has just one called blessed. Best thing is the only data in the files is there own. They tested on their machine. The payload was created 30seconds before I found it.

@AnFam17 @Gi7w0rm @pr0xylife @0xToxin @James_inthe_box I know this is old new but this bad actor nuked all their other #AgentTesla payloads and has just one called blessed. Best thing is the only data in the files is there own. They tested on their machine. The payload was created 30seconds before I found it.
account_circle
Perception Point Attack Trends(@AttackTrends) 's Twitter Profile Photo

'AgentTesla - DeepAnalysis _Stage2'
Capabilities_ > ⚠️⚠️⚠️

✴️ Persistence
✴️SMTP creds + Attacker Location
✴️Browsers + Cookies
✴️VPN / VNC / FTP
✴️Checking External IP [API]
✴️HKEYS + Windows Credentials
✴️KeyStrokes + Email Protocols

IOC's:
tinyurl.com/5n7ychur

'AgentTesla - DeepAnalysis _Stage2'
Capabilities_ > ⚠️⚠️⚠️

✴️ Persistence
✴️SMTP creds + Attacker Location
✴️Browsers + Cookies 
✴️VPN / VNC / FTP
✴️Checking External IP [API]
✴️HKEYS + Windows Credentials 
✴️KeyStrokes + Email Protocols

IOC's: 
 tinyurl.com/5n7ychur
account_circle
ANY.RUN(@anyrun_app) 's Twitter Profile Photo

TOP10 last week's threats by uploads 📊

⬆️ 245 (238)
⬆️ 138 (138)
⬇️ 94 (127)
⬆️ 73 (51)
⬆️ 55 (54)
⬇️ 52 (77)
⬆️ 49 (41)
⬆️ 48 (17)
⬆️ 46 (33)
⬆️ 46 (27)

any.run/malware-trends…

TOP10 last week's threats by uploads 📊

⬆️ #Redline 245 (238)
⬆️ #Njrat 138 (138)
⬇️ #Remcos 94 (127)
⬆️ #Asyncrat 73 (51)
⬆️ #Raccoon 55 (54)
⬇️ #Orcus 52 (77)
⬆️ #Vidar 49 (41)
⬆️ #Dcrat 48 (17)
⬆️ #Arkei 46 (33)
⬆️ #Agenttesla 46 (27)

any.run/malware-trends…
account_circle
reecDeep(@reecdeep) 's Twitter Profile Photo

targeting using fake document as a lure.

📨exfiltration of stolen data via SMTP:
🔥
clairemoon444[@[yandex,com
info[@[grasscarpet,ae
mail,grasscarpet,ae

urity

#AgentTesla #Malware targeting #italy using fake #DHL document as a lure.

📨exfiltration of stolen data via SMTP:
 🔥
clairemoon444[@[yandex,com
info[@[grasscarpet,ae
mail,grasscarpet,ae

#infosecurity #infosec #CyberSecurity #cybercrime
account_circle
Fate112(@tosscoinwitcher) 's Twitter Profile Photo

RussianPanda 🐼 🇺🇦 Gi7w0rm proxylife 0xToxin🕷️
James Your huckleberry added a few new payloads today. Couple and a .
They moved away from the 'IP/file' style of the originals and are using API's on the new ones.tria.ge/230605-xj4a2sa…

@AnFam17 @Gi7w0rm @pr0xylife @0xToxin 
@James_inthe_box Your huckleberry added a few new payloads today. Couple #AgentTesla and a #AsyncRat.
They moved away from the 'IP/file' style of the originals and are using API's on the new ones.tria.ge/230605-xj4a2sa…
account_circle