
YungBinary
@YungBinary
Followers
618
Following
954
Media
53
Statuses
138
New blog on #Sinobi ransomware! They used an MSP's compromised SonicWall SSL VPN creds for initial access. Decryption is impossible w/o the attacker's private key, unless of course you hooked CryptGenRandom😜.
4
57
153
Seeing a (potential new?) python-based backdoor we're tracking as #PyNightshade for the second time delivered via #ClickFix that uses sockets for C2. Supports several commands from C2, including: remote shell, uploading files from the victim host, and self-deletion. It uses RC4
2
39
164
New blog is out on #InterlockGroup and has a wealth of TTPs for detection engineers, tools for security researchers, deobfuscated scripts, and a C2 simulation script for #InterlockRAT ! Screenshots below show the deobfuscated PHP-based backdoor and annotated communications of
1
27
82
Indicators of Compromise can be found here ->
github.com
Contribute to eSentire/iocs development by creating an account on GitHub.
1
1
7
#CyberStealer malware targets everything from crypto wallets to password managers. New malware analysis blog out now!.
3
28
88
RT @p3bt3b: Just dropped a blog uncovering #GhostCrypt👻, a novel crypter powering the #PureRAT (successor of #PureHVNC). It uses #Process….
0
24
0
Looks like #Interlock #Ransomware group has logic in their backend to detect sandboxes and virtual machines by sending data retrieved via the systeminfo command and matching strings, then they return a benign PowerShell command that downloads/executes a .NET SDK installer rather
0
6
28