04/26

CySource virus total blog

https://www.cysrc.com/blog/virus-total-blog
CySource virus total blog

Microsoft finds new elevation of privilege Linux vulnerability, Nimbuspwn - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/
Microsoft finds new elevation of privilege Linux vulnerability, Nimbuspwn - Microsoft Security Blog

Reduce SOC & IR Analyst Fatigue with Automation | SANS Institute

https://www.sans.org/webcasts/reduce-soc-ir-analyst-fatigue-with-automation/
Reduce SOC & IR Analyst Fatigue with Automation | SANS Institute

GitHub - trustedsec/CS-Remote-OPs-BOF

https://github.com/trustedsec/CS-Remote-OPs-BOF
GitHub - trustedsec/CS-Remote-OPs-BOF

NATO - NATO Vacancies

https://nato.taleo.net/careersection/2/jobdetail.ftl?job=220353
NATO - NATO Vacancies

Quantum Ransomware – The DFIR Report

https://thedfirreport.com/2022/04/25/quantum-ransomware/
Quantum Ransomware – The DFIR Report

Facebook Doesn’t Know What It Does With Your Data, Or Where It Goes: Leaked Document

https://www.vice.com/en/article/akvmke/facebook-doesnt-know-what-it-does-with-your-data-or-where-it-goes
Facebook Doesn’t Know What It Does With Your Data, Or Where It Goes: Leaked Document

Researchers Takeover Unpatched 3rd-Party Antivirus Sandboxes via VirusTotal

https://thehackernews.com/2022/04/researchers-report-critical-rce.html
Researchers Takeover Unpatched 3rd-Party Antivirus Sandboxes via VirusTotal

INDUSTROYER.V2: Old Malware Learns New Tricks | Mandiant

https://www.mandiant.com/resources/industroyer-v2-old-malware-new-tricks
INDUSTROYER.V2: Old Malware Learns New Tricks | Mandiant

EVTX-ATTACK-SAMPLES/privesc_KrbRelayUp_windows_4624.evtx at master · sbousseaden/EVTX-ATTACK-SAMPLES · GitHub

https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES/blob/master/Privilege%20Escalation/privesc_KrbRelayUp_windows_4624.evtx
EVTX-ATTACK-SAMPLES/privesc_KrbRelayUp_windows_4624.evtx at master · sbousseaden/EVTX-ATTACK-SAMPLES · GitHub

VMWare Identity Manager Attack: New Backdoor Discovered

https://blog.morphisec.com/vmware-identity-manager-attack-backdoor
VMWare Identity Manager Attack: New Backdoor Discovered

MalwareBazaar | SHA256 70a0b1f467a348965f9242ec8c81ecfa26046ce3a4eda63630aba0bd5a051759

https://bazaar.abuse.ch/sample/70a0b1f467a348965f9242ec8c81ecfa26046ce3a4eda63630aba0bd5a051759/
MalwareBazaar | SHA256 70a0b1f467a348965f9242ec8c81ecfa26046ce3a4eda63630aba0bd5a051759

Gold Ulrick Hackers Still in Action Despite Massive Conti Ransomware Leak

https://thehackernews.com/2022/04/gold-ulrick-hackers-still-in-action.html
Gold Ulrick Hackers Still in Action Despite Massive Conti Ransomware Leak

Spectre

https://ghostbin.com/YEJG5/raw
Spectre

NSA Goes Beyond Info-Sharing to Defend US Firms From Russia, China

https://www.businessinsider.com/nsa-beyond-info-sharing-to-defend-firms-from-russia-china-2022-4
NSA Goes Beyond Info-Sharing to Defend US Firms From Russia, China

Learning Machine Learning Part 2: Attacking White Box Models | by Will Schroeder | Posts By SpecterOps Team Members

https://posts.specterops.io/learning-machine-learning-part-2-attacking-white-box-models-1a10bbb4a2ae
Learning Machine Learning Part 2: Attacking White Box Models | by Will Schroeder | Posts By SpecterOps Team Members

Emotet Malware Tests New Delivery Techniques | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques
Emotet Malware Tests New Delivery Techniques | Proofpoint US

Malware-Traffic-Analysis.net - 2022-04-25 (Monday) - Emotet epoch4 activity (LNK files)

https://www.malware-traffic-analysis.net/2022/04/25/index.html
Malware-Traffic-Analysis.net - 2022-04-25 (Monday) - Emotet epoch4 activity (LNK files)

Emotet Testing New Delivery Ideas After Microsoft Disables VBA Macros by Default

https://thehackernews.com/2022/04/emotet-testing-new-delivery-ideas-after.html
Emotet Testing New Delivery Ideas After Microsoft Disables VBA Macros by Default

Qakbot/Qakbot_obama180_26.04.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_obama180_26.04.2022.txt
Qakbot/Qakbot_obama180_26.04.2022.txt at main · pr0xylife/Qakbot · GitHub

Defeating BazarLoader Anti-Analysis Techniques

https://unit42.paloaltonetworks.com/bazarloader-anti-analysis-techniques/
Defeating BazarLoader Anti-Analysis Techniques

MalwareBazaar | SHA256 a0f4813e8bfd1ec7850dd61f39be5e62c98a1fdd71e98d29e3d19a534096394d (Heodo)

https://bazaar.abuse.ch/sample/a0f4813e8bfd1ec7850dd61f39be5e62c98a1fdd71e98d29e3d19a534096394d/
MalwareBazaar | SHA256 a0f4813e8bfd1ec7850dd61f39be5e62c98a1fdd71e98d29e3d19a534096394d (Heodo)

Emotet/e4_emotet_26.04.2022.txt at main · pr0xylife/Emotet · GitHub

https://github.com/pr0xylife/Emotet/blob/main/e4_emotet_26.04.2022.txt
Emotet/e4_emotet_26.04.2022.txt at main · pr0xylife/Emotet · GitHub

Not Found

https://play.google.com/store/apps/details?id=com.moneyy.magicmoneyok
Not Found