09/07

Initial access broker repurposing techniques in targeted attacks against Ukraine

https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine/
Initial access broker repurposing techniques in targeted attacks against Ukraine

Get-RdpLogonEvent.ps1 · GitHub

https://gist.github.com/awakecoding/5fda938a5fd2d29ebffb31eb023fe51c
Get-RdpLogonEvent.ps1 · GitHub

DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa - Check Point Research

https://research.checkpoint.com/2022/dangeroussavanna-two-year-long-campaign-targets-financial-institutions-in-french-speaking-africa/
DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa - Check Point Research

Sensitive Command Token - So much offense in my defense

https://blog.thinkst.com/2022/09/sensitive-command-token-so-much-offense.html
Sensitive Command Token - So much offense in my defense

APT42: Crooked Charms, Cons, and Compromises | Mandiant

https://www.mandiant.com/resources/blog/apt42-charms-cons-compromises
APT42: Crooked Charms, Cons, and Compromises | Mandiant

Shikitega - New stealthy malware targeting Linux | AT&T Alien Labs

https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux
Shikitega - New stealthy malware targeting Linux | AT&T Alien Labs

Taggart Tech

https://taggart-tech.com/quasar-electron/
Taggart Tech

Working with HTTP/2 in Burp Suite - PortSwigger

https://portswigger.net/burp/documentation/desktop/http2
Working with HTTP/2 in Burp Suite - PortSwigger

SOC Core Skills w/ John Strand - Antisyphon

https://www.antisyphontraining.com/soc-core-skills-w-john-strand/
SOC Core Skills w/ John Strand - Antisyphon

Material on foreign nation’s nuclear capabilities seized at Trump’s Mar-a-Lago - The Washington Post

https://www.washingtonpost.com/national-security/2022/09/06/trump-nuclear-documents/
Material on foreign nation’s nuclear capabilities seized at Trump’s Mar-a-Lago - The Washington Post

MalwareBazaar | SHA256 5a394d20736a664d2d1bdf79c05799eb30739c7c21770671e93110792914b02e (Vjw0rm)

https://bazaar.abuse.ch/sample/5a394d20736a664d2d1bdf79c05799eb30739c7c21770671e93110792914b02e/
MalwareBazaar | SHA256 5a394d20736a664d2d1bdf79c05799eb30739c7c21770671e93110792914b02e (Vjw0rm)

200,000 North Face accounts hacked in credential stuffing attack

https://www.bleepingcomputer.com/news/security/200-000-north-face-accounts-hacked-in-credential-stuffing-attack/
200,000 North Face accounts hacked in credential stuffing attack

New Linux malware evades detection using multi-stage deployment

https://www.bleepingcomputer.com/news/security/new-linux-malware-evades-detection-using-multi-stage-deployment/
New Linux malware evades detection using multi-stage deployment

ShmooCon – Less Moose Than Ever

http://www.shmoocon.org
ShmooCon – Less Moose Than Ever

Brooklyn Public Library - Library Card Application

https://disc.bklynlibrary.org/card/
Brooklyn Public Library - Library Card Application

MalwareBazaar | SHA256 ee37c95d10c93066599d6de775cc3b91503feff1509d12257fa5c83e7875e0f1 (AgentTesla)

https://bazaar.abuse.ch/sample/ee37c95d10c93066599d6de775cc3b91503feff1509d12257fa5c83e7875e0f1/
MalwareBazaar | SHA256 ee37c95d10c93066599d6de775cc3b91503feff1509d12257fa5c83e7875e0f1 (AgentTesla)

IcedID_09_07_2022.txt · GitHub

https://gist.github.com/myrtus0x0/26855fd256af1dedc728583512f138e2
IcedID_09_07_2022.txt · GitHub

Payloads All The Things

https://swisskyrepo.github.io/PayloadsAllTheThingsWeb/
Payloads All The Things

#StopRansomware: Vice Society | CISA

https://www.cisa.gov/uscert/ncas/alerts/aa22-249a
#StopRansomware: Vice Society | CISA