polygonben Profile Banner
Ben Profile
Ben

@polygonben

Followers
671
Following
1K
Media
54
Statuses
246

SOC analyst @HuntressLabs | GCFA | Views are my own

Joined November 2022
Don't wanna be here? Send us removal request.
@polygonben
Ben
8 days
Interesting hands-on-keyboard case today @HuntressLabs . -> Suspected VPN initial access.-> TA used this to RDP to DC & RDS.-> TA created a hidden accounts for persistence.-> TA attempted to clear logs for defence evasion.-> Huntress evicted TA 😎.
5
26
174
@polygonben
Ben
14 hours
RT @gleeda: We’ve started seeing Crux ransomware, which seems to be related to / affiliated with BlackByte ransomware (maybe?). Since we ha….
0
15
0
@polygonben
Ben
4 days
RT @EncapsulateJ: If your organisation uses a third-party managed IT provider, and said IT provider says you have a shiny VPN with logging….
0
1
0
@polygonben
Ben
4 days
RT @HuntressLabs: Congratulations to @RussianPanda9xx & @polygonben for having talks accepted at #defcon33! . Follow these folks and if you….
0
19
0
@polygonben
Ben
5 days
RT @virusbtn: Researchers from The DFIR Report, in partnership with Proofpoint, have identified a PHP variant of Interlock RAT (aka NodeSna….
0
17
0
@polygonben
Ben
5 days
RT @BSidesChelt: It's the week of BSides Cheltenham, and we're looking for some final prize donations for our Charity Raffle. We're suppo….
0
5
0
@polygonben
Ben
6 days
RT @sudo_Rem: I've started the rather tedious project of labeling every Cloudflared account ID that is observed on multiple, unrelated orga….
0
1
0
@polygonben
Ben
7 days
RT @0xBurgers: Always learned about these but never seen ITW myself until yesterday. WebDAV abuse in phishing kits isn’t dead. file:// UNC….
0
8
0
@polygonben
Ben
8 days
'обытия_очистить.cmd' (translates to Event_clear.cmd) is a script that clears every event log on the host.
Tweet media one
1
4
11
@polygonben
Ben
8 days
'Genry.bat' is used to enumerate the Administrator's group before creating a new hidden account 'Administratar' with the password 'SL?yl2025' for persistence. Registry entry for 'Administratar' in 'HKLM\Software\Microsoft\Windows
Tweet media one
1
4
18
@polygonben
Ben
8 days
After landing on the DC, the threat actor dropped two scripts:. C:\Users\<username>\Desktop\Genry.bat.C:\Users\<useranme>\Pictures\События_очистить.cmd.
1
3
9
@polygonben
Ben
13 days
RT @ajpc500: Turns out the same ClickFix mitigation of ‘disabling’ the Win+R shortcut (HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Polic….
0
77
0
@polygonben
Ben
14 days
RT @MalwareVillage: The Call for Sponsors for #MalwareVillage at @DEFCON 33 is open until July 7, 2025!. 📄 Sponsor Package: .
0
10
0
@polygonben
Ben
14 days
RT @BSidesChelt: Announcing our Opening Keynote 🎉. @NCSC CTO @ollieatnowhere will give us an overview of what a nation scale set of challen….
0
14
0
@polygonben
Ben
22 days
RT @Antonlovesdnb: Coming up on my 1 year anniversary with @HuntressLabs ! . Taking this opportunity to go over some things myself and the….
0
47
0
@polygonben
Ben
1 month
RT @Level_Effect: Workshops, or dare we say "micro courses"? We’re talking full malware labs, not just slides and talking for 20 minutes. T….
0
6
0
@polygonben
Ben
1 month
@polygonben
Ben
1 month
Following on from this, I only just realised their was a linked Telegram bot embedded with. the infostealer binary. Message @Phantomsoftwares_bot to buy using crypto
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
0
2
@polygonben
Ben
1 month
The above TAs BTC address has recieved currently $106,198. $7k to the Litecoin address . Couldn’t track the USDT, will try later!.
0
0
0
@polygonben
Ben
1 month
1 year - Phantom Stealer basic - $750. 3 months $189. 1 month - $70
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
0
0
@polygonben
Ben
1 month
1 year - Phantom Stealer advanced - $1080. 3 month = $270. 1 month = $100
Tweet media one
Tweet media two
Tweet media three
1
0
0