home.social

#lolbin — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lolbin, aggregated by home.social.

fetched live
  1. her living of the land techniques have inspired generations of hackers with #lolbin attacks as well
    #infosec

  2. RE: infosec.exchange/@netresec/115

    Here’s a good example on why you should have network egress filtering on your network. Nobody uses the finger protocol any more. But the binary still exists in Windows! And if you don’t block outbound port 79/tcp your users are at risk #cybersecurity #LOLBIN

  3. There's a new acronym out there, LOTS. Its the SaaS version of LOL (Living Of the Land). It stands for Living Off Trusted Sites. I've only seen it in a few blog posts, but wanted to put this out there.
    #LOTS #LOLbin #Infosec

  4. Cisco Talos discloses a new Vietnamese financially-motivated actor dubbed CoralRaider, targeting victims in several Asian and Southeast Asian countries since at least 2023. They focus on stealing victims’ credentials, financial data, and social media accounts, including business and advertisement accounts. Known malware used are a QuasarRAT variant called RotBot, and XClient stealer. TTPs include abusing a legitimate service to host the C2 configuration file and uncommon living-off-the-land binaries (LoLBins), including Windows Forfiles.exe and FoDHelper.exe. IOC provided. 🔗 blog.talosintelligence.com/cor

    #CoralRaider #Vietnam #cybercrime #threatintel #IOC #QuasarRAT #RotBot #XClient #LoLBin

  5. Happy Friday everyone!

    The Threat Hunters at Group-IB share their tactics and techniques, this time when they are hunting for suspicious or malicious activity related to adversaries leveraging the living-off-the-land binary (#LOLBIN) wmic.exe, or Windows Management Instrumentation, or WMI. What I really like about this, aside from some experts sharing their knowledge, is that they not only touch on the execution but share other ways to hunt for follow on activity, for example, what activity looks like when WMI is the parent process. These are always a great read! Enjoy and Happy Hunting!

    Hunting Rituals #4: Threat hunting for execution via Windows Management Instrumentation
    group-ib.com/blog/hunting-ritu

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  6. LNK file with "Copy" command used as simple downloader for #Xworm #RAT and #AsyncRAT The source argument of copy command is the network location in this case, which effectively means that the remote BAT file is downloaded to the victim computer.

    LNK files are often used for malicious purposes. For example, they can be the delivered as email attachments and can run malicious PowerShell commands. However, this one is demonstration of KISS principle - simple and stupid (or actually smart) usage of essential utility.

    Ref: app.any.run/tasks/1cbca783-832

    #malware #malwareanalysis #lolbin #sandbox #AnyRun