01/12

VirusTotal - User - CYBERCOM_Malware_Alert

http://www.Virustotal.com/en/user/CYBERCOM_Malware_Alert
VirusTotal - User - CYBERCOM_Malware_Alert

FBI Honeypot Phone Company Anom Shipped Over 100 Phones to the United States

https://www.vice.com/en/article/epxp8w/fbi-anom-shipped-100-phones-united-states
FBI Honeypot Phone Company Anom Shipped Over 100 Phones to the United States

firmwire-ndss22-hernandez.pdf

https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
firmwire-ndss22-hernandez.pdf

Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle's Shibboleth · Haxolot.com

https://haxolot.com/posts/2022/moodle_pre_auth_shibboleth_rce_part2/
Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle's Shibboleth · Haxolot.com

Objective-See's Blog

https://objective-see.com/blog/blog_0x6C.html
Objective-See's Blog

Zero Day Initiative — Pwn2Own Vancouver Returns for the 15th Anniversary of the Contest

https://www.zerodayinitiative.com/blog/2022/1/12/pwn2own-vancouver-2022-luanch
Zero Day Initiative — Pwn2Own Vancouver Returns for the 15th Anniversary of the Contest

New SysJoker Backdoor Targets Windows, Linux, and macOS - Intezer

https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
New SysJoker Backdoor Targets Windows, Linux, and macOS - Intezer

Malware development part 1 - basics – 0xPat blog – Red/purple teamer

https://0xpat.github.io/Malware_development_part_1/
Malware development part 1 - basics – 0xPat blog – Red/purple teamer

Who is the Network Access Broker ‘Wazawaka?’ – Krebs on Security

https://krebsonsecurity.com/2022/01/who-is-the-network-access-broker-wazawaka/
Who is the Network Access Broker ‘Wazawaka?’ – Krebs on Security

Iranian intel cyber suite of malware uses open source tools > U.S. Cyber Command > News

https://www.cybercom.mil/Media/News/Article/2897570/iranian-intel-cyber-suite-of-malware-uses-open-source-tools/
Iranian intel cyber suite of malware uses open source tools > U.S. Cyber Command > News

Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969) | by frycos | Medium

https://medium.com/@frycos/searching-for-deserialization-protection-bypasses-in-microsoft-exchange-cve-2022-21969-bfa38f63a62d
Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969) | by frycos | Medium

New SysJoker Espionage Malware Targeting Windows, macOS, and Linux Users

https://thehackernews.com/2022/01/new-sysjoker-espionage-malware.html
New SysJoker Espionage Malware Targeting Windows, macOS, and Linux Users

Malware-Traffic-Analysis.net - 2022-01-11 (Tuesday) - Emotet activity

https://www.malware-traffic-analysis.net/2022/01/11/index.html
Malware-Traffic-Analysis.net - 2022-01-11 (Tuesday) - Emotet activity

OceanLotus hackers turn to web archive files to deploy backdoors

https://www.bleepingcomputer.com/news/security/oceanlotus-hackers-turn-to-web-archive-files-to-deploy-backdoors/
OceanLotus hackers turn to web archive files to deploy backdoors

CVE-2021-20038 | AttackerKB

https://attackerkb.com/topics/QyXRC1wbvC/cve-2021-20038/rapid7-analysis?fbclid=IwAR1ldORiwotSY0HeF_aLrYra1LuvJk7nlzfWg1HOT8AvnnvBfVcvUE1siTw
CVE-2021-20038 | AttackerKB

405 Banned

https://urlhaus.abuse.ch/browse/tag/emotet/
405 Banned

Hackers Use Cloud Services to Distribute Nanocore, Netwire, and AsyncRAT Malware

https://thehackernews.com/2022/01/hackers-use-cloud-services-to.html
Hackers Use Cloud Services to Distribute Nanocore, Netwire, and AsyncRAT Malware