07/20

APT41: A Case Sudy – Intrusion Truth

https://intrusiontruth.wordpress.com/2022/07/20/apt41/
APT41: A Case Sudy – Intrusion Truth

Continued cyber activity in Eastern Europe observed by TAG

https://blog.google/threat-analysis-group/continued-cyber-activity-in-eastern-europe-observed-by-tag/
Continued cyber activity in Eastern Europe observed by TAG

Is the Secret Service’s Claim About Erased Text Messages Plausible? (Updated)

https://zetter.substack.com/p/is-the-secret-services-claim-about
Is the Secret Service’s Claim About Erased Text Messages Plausible? (Updated)

How Meta and the security industry collaborate to secure the internet

https://engineering.fb.com/2022/07/20/security/how-meta-and-the-security-industry-collaborate-to-secure-the-internet/
How Meta and the security industry collaborate to secure the internet

IcedID/icedID_20.07.2022.txt at main · pr0xylife/IcedID · GitHub

https://github.com/pr0xylife/IcedID/blob/main/icedID_20.07.2022.txt
IcedID/icedID_20.07.2022.txt at main · pr0xylife/IcedID · GitHub

Arbitrary File Read on Skype For Business Server | VCSLab

https://lab.viettelcybersecurity.com/advisories/VCSA-97
Arbitrary File Read on Skype For Business Server | VCSLab

MalwareBazaar | SHA256 77c3de1c2a5ced907159777ff648c2a1f3c4bdb8b6a9fbc9d06c76d8e6cb2c8d (IcedID)

https://bazaar.abuse.ch/sample/77c3de1c2a5ced907159777ff648c2a1f3c4bdb8b6a9fbc9d06c76d8e6cb2c8d/
MalwareBazaar | SHA256 77c3de1c2a5ced907159777ff648c2a1f3c4bdb8b6a9fbc9d06c76d8e6cb2c8d (IcedID)

MalwareBazaar | SHA256 e3507aa2e857c8d0bb4cb36c6fc81ac4527ff1a76b370bdfefe4ccc0f2e09a53 (IcedID)

https://bazaar.abuse.ch/sample/e3507aa2e857c8d0bb4cb36c6fc81ac4527ff1a76b370bdfefe4ccc0f2e09a53/
MalwareBazaar | SHA256 e3507aa2e857c8d0bb4cb36c6fc81ac4527ff1a76b370bdfefe4ccc0f2e09a53 (IcedID)

[CVE-2022-34918] A crack in the Linux firewall

https://www.randorisec.fr/crack-linux-firewall/
[CVE-2022-34918] A crack in the Linux firewall

Cloaked Ursa (APT29) Hackers Use Trusted Online Storage Services

https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns/
Cloaked Ursa (APT29) Hackers Use Trusted Online Storage Services

Hatching Triage | Behavioral Report

https://tria.ge/220720-ls12haeecl/behavioral2
Hatching Triage | Behavioral Report

I see what you did there: A look at the CloudMensis macOS spyware | WeLiveSecurity

https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
I see what you did there: A look at the CloudMensis macOS spyware | WeLiveSecurity

Analyze .NET deserialization: TypeConfuseDelegate gadget chain with BinaryFormatter | Quang Vo

https://mr-r3bot.github.io/research/2022/07/18/Analyze-.NET-deserialization-TypeConfuseDelegate-gadget.html
Analyze .NET deserialization: TypeConfuseDelegate gadget chain with BinaryFormatter | Quang Vo

New Luna ransomware encrypts Windows, Linux, and ESXi systems

https://www.bleepingcomputer.com/news/security/new-luna-ransomware-encrypts-windows-linux-and-esxi-systems/
New Luna ransomware encrypts Windows, Linux, and ESXi systems

The FBI Forced A Suspect To Unlock Amazon’s Encrypted App Wickr With Their Face

https://www.forbes.com/sites/thomasbrewster/2022/07/19/fbi-forces-open-amazon-wickr-app-with-a-suspects-face/
The FBI Forced A Suspect To Unlock Amazon’s Encrypted App Wickr With Their Face

VirusTotal - File - 50e1203d5afefeed67f616b84459c55d8b38aafcacab7edab81f2055d21aefc1

https://www.virustotal.com/gui/file/50e1203d5afefeed67f616b84459c55d8b38aafcacab7edab81f2055d21aefc1
VirusTotal - File - 50e1203d5afefeed67f616b84459c55d8b38aafcacab7edab81f2055d21aefc1

New Rust-based Ransomware Family Targets Windows, Linux, and ESXi Systems

https://thehackernews.com/2022/07/new-rust-based-ransomware-family.html
New Rust-based Ransomware Family Targets Windows, Linux, and ESXi Systems