home.social

#pikabot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pikabot, aggregated by home.social.

fetched live
  1. 🔎 The Sekoia TDR team delved into the deep secrets and operations of #PikaBot.

    Our lastest report provides insights resulting from the PikaBot reverse engineering.

    Aditionally, this report shares technical details on tracking its C2 infrastructure.

    blog.sekoia.io/pikabot-a-guide

  2. 🔎 The Sekoia TDR team delved into the deep secrets and operations of #PikaBot.

    Our lastest report provides insights resulting from the PikaBot reverse engineering.

    Aditionally, this report shares technical details on tracking its C2 infrastructure.

    blog.sekoia.io/pikabot-a-guide

  3. 🔎 The Sekoia TDR team delved into the deep secrets and operations of #PikaBot.

    Our lastest report provides insights resulting from the PikaBot reverse engineering.

    Aditionally, this report shares technical details on tracking its C2 infrastructure.

    blog.sekoia.io/pikabot-a-guide

  4. 🔎 The Sekoia TDR team delved into the deep secrets and operations of #PikaBot.

    Our lastest report provides insights resulting from the PikaBot reverse engineering.

    Aditionally, this report shares technical details on tracking its C2 infrastructure.

    blog.sekoia.io/pikabot-a-guide

  5. We are proud to announce that Sekoia #TDR team contributed to the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot

    operation-endgame.com/

  6. We are proud to announce that Sekoia #TDR team contributed to the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot

    operation-endgame.com/

  7. We are proud to announce that Sekoia #TDR team contributed to the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot

    operation-endgame.com/

  8. Operation Endgame - Largest Ever Operation Against Botnets Hits Dropper Malware Ecosystem

    Date: May 30, 2024
    CVE: Not specified
    Vulnerability Type: Malware
    CWE: [[CWE-94]], [[CWE-502]]
    Sources: Europol News, Eurojust News

    Issue Summary

    Europol, in coordination with law enforcement agencies from multiple countries, conducted the largest ever operation targeting botnets. This operation, dubbed "Operation Endgame," took place from May 27 to 29, 2024, and led to the disruption of major malware droppers including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. The effort resulted in four arrests and the takedown of over 100 servers worldwide. These droppers were used to facilitate ransomware and other cyber-attacks by installing additional malware onto target systems. The operation was supported by Eurojust and involved contributions from countries including France, Germany, the Netherlands, Denmark, the UK, the US, and others. Private partners also played a role in the operation, which aimed to dismantle the infrastructure supporting these malicious activities. The success of this operation marks a significant step in combating cybercrime on a global scale.

    Operation Endgame, coordinated by Europol, dismantled several major botnets including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. This international effort involved law enforcement agencies from multiple countries and led to the arrest of four individuals and the takedown of over 100 servers. The botnets targeted facilitated ransomware and other cyber-attacks.

    Technical Key Findings

    The malware droppers involved are designed to infiltrate systems and install additional malware, often avoiding detection through sophisticated evasion techniques. These droppers were used to deploy ransomware and other malicious payloads by bypassing security measures and enabling further system compromises.

    Vulnerable Products

    The operation did not specify particular products but targeted the infrastructures supporting droppers like IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee.

    Impact Assessment

    If abused, these vulnerabilities could lead to widespread ransomware attacks, financial losses, and significant disruption of services. The infrastructure taken down had facilitated numerous cyber-attacks globally, highlighting the severe impact on cybersecurity.

    Patches or Workaround

    The report did not mention specific patches or workarounds. However, continuous monitoring and updating of security measures are recommended to protect against such threats.

    Tags

    #Botnets #Malware #Ransomware #Cybersecurity #Europol #OperationEndgame #Cybercrime #IcedID #SystemBC #Pikabot #Smokeloader #Bumblebee

  9. Operation Endgame - Largest Ever Operation Against Botnets Hits Dropper Malware Ecosystem

    Date: May 30, 2024
    CVE: Not specified
    Vulnerability Type: Malware
    CWE: [[CWE-94]], [[CWE-502]]
    Sources: Europol News, Eurojust News

    Issue Summary

    Europol, in coordination with law enforcement agencies from multiple countries, conducted the largest ever operation targeting botnets. This operation, dubbed "Operation Endgame," took place from May 27 to 29, 2024, and led to the disruption of major malware droppers including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. The effort resulted in four arrests and the takedown of over 100 servers worldwide. These droppers were used to facilitate ransomware and other cyber-attacks by installing additional malware onto target systems. The operation was supported by Eurojust and involved contributions from countries including France, Germany, the Netherlands, Denmark, the UK, the US, and others. Private partners also played a role in the operation, which aimed to dismantle the infrastructure supporting these malicious activities. The success of this operation marks a significant step in combating cybercrime on a global scale.

    Operation Endgame, coordinated by Europol, dismantled several major botnets including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. This international effort involved law enforcement agencies from multiple countries and led to the arrest of four individuals and the takedown of over 100 servers. The botnets targeted facilitated ransomware and other cyber-attacks.

    Technical Key Findings

    The malware droppers involved are designed to infiltrate systems and install additional malware, often avoiding detection through sophisticated evasion techniques. These droppers were used to deploy ransomware and other malicious payloads by bypassing security measures and enabling further system compromises.

    Vulnerable Products

    The operation did not specify particular products but targeted the infrastructures supporting droppers like IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee.

    Impact Assessment

    If abused, these vulnerabilities could lead to widespread ransomware attacks, financial losses, and significant disruption of services. The infrastructure taken down had facilitated numerous cyber-attacks globally, highlighting the severe impact on cybersecurity.

    Patches or Workaround

    The report did not mention specific patches or workarounds. However, continuous monitoring and updating of security measures are recommended to protect against such threats.

    Tags

    #Botnets #Malware #Ransomware #Cybersecurity #Europol #OperationEndgame #Cybercrime #IcedID #SystemBC #Pikabot #Smokeloader #Bumblebee

  10. Operation Endgame - Largest Ever Operation Against Botnets Hits Dropper Malware Ecosystem

    Date: May 30, 2024
    CVE: Not specified
    Vulnerability Type: Malware
    CWE: [[CWE-94]], [[CWE-502]]
    Sources: Europol News, Eurojust News

    Issue Summary

    Europol, in coordination with law enforcement agencies from multiple countries, conducted the largest ever operation targeting botnets. This operation, dubbed "Operation Endgame," took place from May 27 to 29, 2024, and led to the disruption of major malware droppers including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. The effort resulted in four arrests and the takedown of over 100 servers worldwide. These droppers were used to facilitate ransomware and other cyber-attacks by installing additional malware onto target systems. The operation was supported by Eurojust and involved contributions from countries including France, Germany, the Netherlands, Denmark, the UK, the US, and others. Private partners also played a role in the operation, which aimed to dismantle the infrastructure supporting these malicious activities. The success of this operation marks a significant step in combating cybercrime on a global scale.

    Operation Endgame, coordinated by Europol, dismantled several major botnets including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. This international effort involved law enforcement agencies from multiple countries and led to the arrest of four individuals and the takedown of over 100 servers. The botnets targeted facilitated ransomware and other cyber-attacks.

    Technical Key Findings

    The malware droppers involved are designed to infiltrate systems and install additional malware, often avoiding detection through sophisticated evasion techniques. These droppers were used to deploy ransomware and other malicious payloads by bypassing security measures and enabling further system compromises.

    Vulnerable Products

    The operation did not specify particular products but targeted the infrastructures supporting droppers like IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee.

    Impact Assessment

    If abused, these vulnerabilities could lead to widespread ransomware attacks, financial losses, and significant disruption of services. The infrastructure taken down had facilitated numerous cyber-attacks globally, highlighting the severe impact on cybersecurity.

    Patches or Workaround

    The report did not mention specific patches or workarounds. However, continuous monitoring and updating of security measures are recommended to protect against such threats.

    Tags

    #Botnets #Malware #Ransomware #Cybersecurity #Europol #OperationEndgame #Cybercrime #IcedID #SystemBC #Pikabot #Smokeloader #Bumblebee

  11. Operation Endgame - Largest Ever Operation Against Botnets Hits Dropper Malware Ecosystem

    Date: May 30, 2024
    CVE: Not specified
    Vulnerability Type: Malware
    CWE: [[CWE-94]], [[CWE-502]]
    Sources: Europol News, Eurojust News

    Issue Summary

    Europol, in coordination with law enforcement agencies from multiple countries, conducted the largest ever operation targeting botnets. This operation, dubbed "Operation Endgame," took place from May 27 to 29, 2024, and led to the disruption of major malware droppers including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. The effort resulted in four arrests and the takedown of over 100 servers worldwide. These droppers were used to facilitate ransomware and other cyber-attacks by installing additional malware onto target systems. The operation was supported by Eurojust and involved contributions from countries including France, Germany, the Netherlands, Denmark, the UK, the US, and others. Private partners also played a role in the operation, which aimed to dismantle the infrastructure supporting these malicious activities. The success of this operation marks a significant step in combating cybercrime on a global scale.

    Operation Endgame, coordinated by Europol, dismantled several major botnets including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. This international effort involved law enforcement agencies from multiple countries and led to the arrest of four individuals and the takedown of over 100 servers. The botnets targeted facilitated ransomware and other cyber-attacks.

    Technical Key Findings

    The malware droppers involved are designed to infiltrate systems and install additional malware, often avoiding detection through sophisticated evasion techniques. These droppers were used to deploy ransomware and other malicious payloads by bypassing security measures and enabling further system compromises.

    Vulnerable Products

    The operation did not specify particular products but targeted the infrastructures supporting droppers like IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee.

    Impact Assessment

    If abused, these vulnerabilities could lead to widespread ransomware attacks, financial losses, and significant disruption of services. The infrastructure taken down had facilitated numerous cyber-attacks globally, highlighting the severe impact on cybersecurity.

    Patches or Workaround

    The report did not mention specific patches or workarounds. However, continuous monitoring and updating of security measures are recommended to protect against such threats.

    Tags

    #Botnets #Malware #Ransomware #Cybersecurity #Europol #OperationEndgame #Cybercrime #IcedID #SystemBC #Pikabot #Smokeloader #Bumblebee

  12. Operation Endgame - Largest Ever Operation Against Botnets Hits Dropper Malware Ecosystem

    Date: May 30, 2024
    CVE: Not specified
    Vulnerability Type: Malware
    CWE: [[CWE-94]], [[CWE-502]]
    Sources: Europol News, Eurojust News

    Issue Summary

    Europol, in coordination with law enforcement agencies from multiple countries, conducted the largest ever operation targeting botnets. This operation, dubbed "Operation Endgame," took place from May 27 to 29, 2024, and led to the disruption of major malware droppers including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. The effort resulted in four arrests and the takedown of over 100 servers worldwide. These droppers were used to facilitate ransomware and other cyber-attacks by installing additional malware onto target systems. The operation was supported by Eurojust and involved contributions from countries including France, Germany, the Netherlands, Denmark, the UK, the US, and others. Private partners also played a role in the operation, which aimed to dismantle the infrastructure supporting these malicious activities. The success of this operation marks a significant step in combating cybercrime on a global scale.

    Operation Endgame, coordinated by Europol, dismantled several major botnets including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee. This international effort involved law enforcement agencies from multiple countries and led to the arrest of four individuals and the takedown of over 100 servers. The botnets targeted facilitated ransomware and other cyber-attacks.

    Technical Key Findings

    The malware droppers involved are designed to infiltrate systems and install additional malware, often avoiding detection through sophisticated evasion techniques. These droppers were used to deploy ransomware and other malicious payloads by bypassing security measures and enabling further system compromises.

    Vulnerable Products

    The operation did not specify particular products but targeted the infrastructures supporting droppers like IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee.

    Impact Assessment

    If abused, these vulnerabilities could lead to widespread ransomware attacks, financial losses, and significant disruption of services. The infrastructure taken down had facilitated numerous cyber-attacks globally, highlighting the severe impact on cybersecurity.

    Patches or Workaround

    The report did not mention specific patches or workarounds. However, continuous monitoring and updating of security measures are recommended to protect against such threats.

    Tags

    #Botnets #Malware #Ransomware #Cybersecurity #Europol #OperationEndgame #Cybercrime #IcedID #SystemBC #Pikabot #Smokeloader #Bumblebee

  13. We are proud to announce that we assisted the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot 🔥

    abuse.ch has provided key infrastructure to LEA and internal partners to disrupt these botnet operations 🛑

    More information on the operation is available here:
    👉 operation-endgame.com/

  14. We are proud to announce that we assisted the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot 🔥

    abuse.ch has provided key infrastructure to LEA and internal partners to disrupt these botnet operations 🛑

    More information on the operation is available here:
    👉 operation-endgame.com/

  15. We are proud to announce that we assisted the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot 🔥

    abuse.ch has provided key infrastructure to LEA and internal partners to disrupt these botnet operations 🛑

    More information on the operation is available here:
    👉 operation-endgame.com/

  16. We are proud to announce that we assisted the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot 🔥

    abuse.ch has provided key infrastructure to LEA and internal partners to disrupt these botnet operations 🛑

    More information on the operation is available here:
    👉 operation-endgame.com/

  17. We are proud to announce that we assisted the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot 🔥

    abuse.ch has provided key infrastructure to LEA and internal partners to disrupt these botnet operations 🛑

    More information on the operation is available here:
    👉 operation-endgame.com/

  18. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  19. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  20. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  21. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  22. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  23. Zscaler identified Pikabot malware loader's string obfuscation algorithm. They describe the algorithm and their approach to decrypt the binary strings using IDA's microcode. They developed an IDA plugin to automatically decrypt Pikabot's obfuscated strings and released the source code. IOC provided. 🔗 zscaler.com/blogs/security-res

    #Pikabot #threatintel #IOC #IDA

  24. Zscaler identified Pikabot malware loader's string obfuscation algorithm. They describe the algorithm and their approach to decrypt the binary strings using IDA's microcode. They developed an IDA plugin to automatically decrypt Pikabot's obfuscated strings and released the source code. IOC provided. 🔗 zscaler.com/blogs/security-res

    #Pikabot #threatintel #IOC #IDA

  25. Zscaler identified Pikabot malware loader's string obfuscation algorithm. They describe the algorithm and their approach to decrypt the binary strings using IDA's microcode. They developed an IDA plugin to automatically decrypt Pikabot's obfuscated strings and released the source code. IOC provided. 🔗 zscaler.com/blogs/security-res

    #Pikabot #threatintel #IOC #IDA

  26. Zscaler identified Pikabot malware loader's string obfuscation algorithm. They describe the algorithm and their approach to decrypt the binary strings using IDA's microcode. They developed an IDA plugin to automatically decrypt Pikabot's obfuscated strings and released the source code. IOC provided. 🔗 zscaler.com/blogs/security-res

    #Pikabot #threatintel #IOC #IDA

  27. Zscaler identified Pikabot malware loader's string obfuscation algorithm. They describe the algorithm and their approach to decrypt the binary strings using IDA's microcode. They developed an IDA plugin to automatically decrypt Pikabot's obfuscated strings and released the source code. IOC provided. 🔗 zscaler.com/blogs/security-res

    #Pikabot #threatintel #IOC #IDA

  28. Campagne #Malware #Italy Week 13

    👻💣🔥☠️
    #AgentTesla: Pagamenti
    #Remcos: Delivery
    #Irata: APK Bank
    #Phorpiex: Documenti
    #Guloader: Ordine
    #PlanetStealer: Conferma
    #Lokibot: Preventivo
    #Pikabot: Resend

    #mwitaly

  29. Bleeping describes this #pikabot campaign aimed at stealing NTLM hashes with connection information.
    ⬇️​
    👀​⚠️​
    "Vulnerability researcher Will Dormann suggests that it's possible that the hashes are not being stolen to breach networks but rather as a form of reconnaissance to find valuable targets."
    👇​
    bleepingcomputer.com/news/secu

    #cyberveille

  30. Bleeping describes this #pikabot campaign aimed at stealing NTLM hashes with connection information.
    ⬇️​
    👀​⚠️​
    "Vulnerability researcher Will Dormann suggests that it's possible that the hashes are not being stolen to breach networks but rather as a form of reconnaissance to find valuable targets."
    👇​
    bleepingcomputer.com/news/secu

    #cyberveille

  31. Description par bleeping de l'enchaînement de cette campagne #pikabot visant à voler le hashs NTLM avec les information de connexions
    ⬇️​
    👀​⚠️​
    "Vulnerability researcher Will Dormann suggests that it's possible that the hashes are not being stolen to breach networks but rather as a form of reconnaissance to find valuable targets."
    👇​
    bleepingcomputer.com/news/secu

    #cyberveille

  32. Bleeping describes this #pikabot campaign aimed at stealing NTLM hashes with connection information.
    ⬇️​
    👀​⚠️​
    "Vulnerability researcher Will Dormann suggests that it's possible that the hashes are not being stolen to breach networks but rather as a form of reconnaissance to find valuable targets."
    👇​
    bleepingcomputer.com/news/secu

    #cyberveille

  33. New blog post! In this one I look at a Java-based dropper for Pikabot that TA577 used in mid-February 2024.
    forensicitguy.github.io/dissec
    #malware #pikabot #ta577

  34. New blog post! In this one I look at a Java-based dropper for Pikabot that TA577 used in mid-February 2024.
    forensicitguy.github.io/dissec
    #malware #pikabot #ta577

  35. New blog post! In this one I look at a Java-based dropper for Pikabot that TA577 used in mid-February 2024.
    forensicitguy.github.io/dissec
    #malware #pikabot #ta577

  36. New blog post! In this one I look at a Java-based dropper for Pikabot that TA577 used in mid-February 2024.
    forensicitguy.github.io/dissec
    #malware #pikabot #ta577

  37. Pikabot Malware Loader Returns with New Features

    The full set of SHA256 codes for the next generation of cyber-security tools has been released by the National Security Agency (NSA) in the United States, as well as the UK.

    Pulse ID: 65e169fa0fc802f904b6ef29
    Pulse Link: otx.alienvault.com/pulse/65e16
    Pulse Author: cryptocti
    Created: 2024-03-01 05:39:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #UK #RAT #PikaBot #UnitedStates #NationalSecurityAgency #cryptocti

  38. So, according to Any.Run
    👇​
    🐦​🔗​twitter[.]com/anyrun_app/status/1762854550627561852

    and Deutsche Telecom's CERT,
    👇​
    🐦​🔗​
    twitter[.]com/DTCERT/status/1762808435723145366

    the objective of this strange campaign iteration is to "simply" capture hashes (and IP address, username, victim's computer name) from NTLMv2 connections through SMB.
    This occurs because Edge and Chrome establish connections without prompting users for authorization. (enumeration operation)

    IoCs --> file://SMB IP
    👇​
    threatfox.abuse.ch/browse/malw

    (image by any.run)
    #CyberVeille #Pikabot

  39. So, according to Any.Run
    👇​
    🐦​🔗​twitter[.]com/anyrun_app/status/1762854550627561852

    and Deutsche Telecom's CERT,
    👇​
    🐦​🔗​
    twitter[.]com/DTCERT/status/1762808435723145366

    the objective of this strange campaign iteration is to "simply" capture hashes (and IP address, username, victim's computer name) from NTLMv2 connections through SMB.
    This occurs because Edge and Chrome establish connections without prompting users for authorization. (enumeration operation)

    IoCs --> file://SMB IP
    👇​
    threatfox.abuse.ch/browse/malw

    (image by any.run)
    #CyberVeille #Pikabot

  40. So, according to Any.Run
    👇​
    🐦​🔗​twitter[.]com/anyrun_app/status/1762854550627561852

    and Deutsche Telecom's CERT,
    👇​
    🐦​🔗​
    twitter[.]com/DTCERT/status/1762808435723145366

    the objective of this strange campaign iteration is to "simply" capture hashes (and IP address, username, victim's computer name) from NTLMv2 connections through SMB.
    This occurs because Edge and Chrome establish connections without prompting users for authorization. (enumeration operation)

    IoCs --> file://SMB IP
    👇​
    threatfox.abuse.ch/browse/malw

    (image by any.run)
    #CyberVeille #Pikabot

  41. So, according to Any.Run
    👇​
    🐦​🔗​twitter[.]com/anyrun_app/status/1762854550627561852

    and Deutsche Telecom's CERT,
    👇​
    🐦​🔗​
    twitter[.]com/DTCERT/status/1762808435723145366

    the objective of this strange campaign iteration is to "simply" capture hashes (and IP address, username, victim's computer name) from NTLMv2 connections through SMB.
    This occurs because Edge and Chrome establish connections without prompting users for authorization. (enumeration operation)

    IoCs --> file://SMB IP
    👇​
    threatfox.abuse.ch/browse/malw

    (image by any.run)
    #CyberVeille #Pikabot

  42. very good analysis of last week's #pikabot campaign

    ✉️​➡️​link➡️​zip➡️​js+data➡️​:terminal:​ .ps
    👇​
    elastic.co/security-labs/pikab

    if anyone understands this week's chaining or has managed to grab the payload, I'm interested

    ✉️➡️​​zip➡️​html+data➡️​html refresh➡️​file: //xxx.xxx.xxx.xxx/xxx/xxx.txt

    :blobcatwaitwhat:​
    👇​
    bazaar.abuse.ch/browse/tag/Pik

    [IP SMB]
    👇​
    threatfox.abuse.ch/browse/malw

    #CyberVeille #malspam

  43. very good analysis of last week's #pikabot campaign

    ✉️​➡️​link➡️​zip➡️​js+data➡️​:terminal:​ .ps
    👇​
    elastic.co/security-labs/pikab

    if anyone understands this week's chaining or has managed to grab the payload, I'm interested

    ✉️➡️​​zip➡️​html+data➡️​html refresh➡️​file: //xxx.xxx.xxx.xxx/xxx/xxx.txt

    :blobcatwaitwhat:​
    👇​
    bazaar.abuse.ch/browse/tag/Pik

    [IP SMB]
    👇​
    threatfox.abuse.ch/browse/malw

    #CyberVeille #malspam

  44. very good analysis of last week's #pikabot campaign

    ✉️​➡️​link➡️​zip➡️​js+data➡️​:terminal:​ .ps
    👇​
    elastic.co/security-labs/pikab

    if anyone understands this week's chaining or has managed to grab the payload, I'm interested

    ✉️➡️​​zip➡️​html+data➡️​html refresh➡️​file: //xxx.xxx.xxx.xxx/xxx/xxx.txt

    :blobcatwaitwhat:​
    👇​
    bazaar.abuse.ch/browse/tag/Pik

    [IP SMB]
    👇​
    threatfox.abuse.ch/browse/malw

    #CyberVeille #malspam

  45. very good analysis of last week's #pikabot campaign

    ✉️​➡️​link➡️​zip➡️​js+data➡️​:terminal:​ .ps
    👇​
    elastic.co/security-labs/pikab

    if anyone understands this week's chaining or has managed to grab the payload, I'm interested

    ✉️➡️​​zip➡️​html+data➡️​html refresh➡️​file: //xxx.xxx.xxx.xxx/xxx/xxx.txt

    :blobcatwaitwhat:​
    👇​
    bazaar.abuse.ch/browse/tag/Pik

    [IP SMB]
    👇​
    threatfox.abuse.ch/browse/malw

    #CyberVeille #malspam

  46. Campagne #Malware #Italy Week 07

    🔥👻💣☠️
    #AgentTesla: Ordine
    #PureLog: Quotazione
    #Pikabot: Resend
    #Astaroth: Fattura
    #Irata / #SpyNote: APK Bank
    #Ransomware: Condivisione
    #Remcos: Avviso Giacenza GLS
    #SnakeKeylogger: Ordine
    #DanaBot: Agenzia Entrate

    #mwitaly