home.social

#purerat β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #purerat, aggregated by home.social.

fetched live
  1. zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
    netresec.com/?b=267e877

  2. zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
    netresec.com/?b=267e877

  3. zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
    netresec.com/?b=267e877

  4. zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
    netresec.com/?b=267e877

  5. zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
    netresec.com/?b=267e877

  6. @james_inthe_box @da_667 FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS.

    Feel free to verify with:
    curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'

  7. @james_inthe_box @da_667 FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS.

    Feel free to verify with:
    curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'

  8. @james_inthe_box @da_667 FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS.

    Feel free to verify with:
    curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'

  9. @james_inthe_box @da_667 FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS.

    Feel free to verify with:
    curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'

  10. @james_inthe_box @da_667 FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS.

    Feel free to verify with:
    curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'

  11. @malware_traffic Thank you for sharing Brad!
    The TLS traffic to 173.232.146.62:25658 looks like #AsyncRAT or possibly #PureRAT. Can you confirm if it was generated by the powershell script with MD5 90389d2988cce2fe508087618dd2f519 from fnjnbehjangelkd[.]top?

  12. @malware_traffic Thank you for sharing Brad!
    The TLS traffic to 173.232.146.62:25658 looks like #AsyncRAT or possibly #PureRAT. Can you confirm if it was generated by the powershell script with MD5 90389d2988cce2fe508087618dd2f519 from fnjnbehjangelkd[.]top?

  13. @malware_traffic Thank you for sharing Brad!
    The TLS traffic to 173.232.146.62:25658 looks like #AsyncRAT or possibly #PureRAT. Can you confirm if it was generated by the powershell script with MD5 90389d2988cce2fe508087618dd2f519 from fnjnbehjangelkd[.]top?

  14. @malware_traffic Thank you for sharing Brad!
    The TLS traffic to 173.232.146.62:25658 looks like #AsyncRAT or possibly #PureRAT. Can you confirm if it was generated by the powershell script with MD5 90389d2988cce2fe508087618dd2f519 from fnjnbehjangelkd[.]top?

  15. @malware_traffic Thank you for sharing Brad!
    The TLS traffic to 173.232.146.62:25658 looks like #AsyncRAT or possibly #PureRAT. Can you confirm if it was generated by the powershell script with MD5 90389d2988cce2fe508087618dd2f519 from fnjnbehjangelkd[.]top?

  16. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  17. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  18. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  19. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  20. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  21. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  22. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  23. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  24. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  25. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  26. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  27. Mentioned Malware Families: ValleyRAT, PureRAT

    Aliases for ValleyRAT: win.valley_rat, Winos
    Malpedia link for ValleyRAT: malpedia.caad.fkie.fraunhofer.
    Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
    Malpedia link for PureRAT: malpedia.caad.fkie.fraunhofer.

    #ValleyRAT #PureRAT

    Aliases provided by Malpedia.

  28. RE: infosec.exchange/@VirusBulleti

    How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
    Here are some typical PureRAT indicators:
    :windows: .NET malware
    πŸ”‘ TLS version is 1.0
    πŸ«† JA3 fc54e0d16d9764783542f0146a98b300 / 07af4aa9e4d215a5ee63f9a0a277fbe3
    πŸ«† JA4 t10i070500_c50f5591e341_950472255fe9 / t10i060500_4dc025c38c38_950472255fe9
    πŸ«† JA3S b74704234e6128f33bff9865696e31b3
    πŸ“ X.509 cert expires 9999-12-31 23:59:59 UTC
    πŸ“‘ C2 often runs on TCP 56001
    All of them match on the sample analyzed in Trend's report

  29. RE: infosec.exchange/@VirusBulleti

    How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
    Here are some typical PureRAT indicators:
    :windows: .NET malware
    πŸ”‘ TLS version is 1.0
    πŸ«† JA3 fc54e0d16d9764783542f0146a98b300 / 07af4aa9e4d215a5ee63f9a0a277fbe3
    πŸ«† JA4 t10i070500_c50f5591e341_950472255fe9 / t10i060500_4dc025c38c38_950472255fe9
    πŸ«† JA3S b74704234e6128f33bff9865696e31b3
    πŸ“ X.509 cert expires 9999-12-31 23:59:59 UTC
    πŸ“‘ C2 often runs on TCP 56001
    All of them match on the sample analyzed in Trend's report

  30. RE: infosec.exchange/@VirusBulleti

    How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
    Here are some typical PureRAT indicators:
    :windows: .NET malware
    πŸ”‘ TLS version is 1.0
    πŸ«† JA3 fc54e0d16d9764783542f0146a98b300 / 07af4aa9e4d215a5ee63f9a0a277fbe3
    πŸ«† JA4 t10i070500_c50f5591e341_950472255fe9 / t10i060500_4dc025c38c38_950472255fe9
    πŸ«† JA3S b74704234e6128f33bff9865696e31b3
    πŸ“ X.509 cert expires 9999-12-31 23:59:59 UTC
    πŸ“‘ C2 often runs on TCP 56001
    All of them match on the sample analyzed in Trend's report

  31. RE: infosec.exchange/@VirusBulleti

    How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
    Here are some typical PureRAT indicators:
    :windows: .NET malware
    πŸ”‘ TLS version is 1.0
    πŸ«† JA3 fc54e0d16d9764783542f0146a98b300 / 07af4aa9e4d215a5ee63f9a0a277fbe3
    πŸ«† JA4 t10i070500_c50f5591e341_950472255fe9 / t10i060500_4dc025c38c38_950472255fe9
    πŸ«† JA3S b74704234e6128f33bff9865696e31b3
    πŸ“ X.509 cert expires 9999-12-31 23:59:59 UTC
    πŸ“‘ C2 often runs on TCP 56001
    All of them match on the sample analyzed in Trend's report

  32. RE: infosec.exchange/@VirusBulleti

    How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
    Here are some typical PureRAT indicators:
    :windows: .NET malware
    πŸ”‘ TLS version is 1.0
    πŸ«† JA3 fc54e0d16d9764783542f0146a98b300 / 07af4aa9e4d215a5ee63f9a0a277fbe3
    πŸ«† JA4 t10i070500_c50f5591e341_950472255fe9 / t10i060500_4dc025c38c38_950472255fe9
    πŸ«† JA3S b74704234e6128f33bff9865696e31b3
    πŸ“ X.509 cert expires 9999-12-31 23:59:59 UTC
    πŸ“‘ C2 often runs on TCP 56001
    All of them match on the sample analyzed in Trend's report

  33. πŸ›‘ New and ongoing β€œI Paid Twice” scam hits hotels and guests using via ClickFix attack. Attackers breach booking accounts like .com, then message travelers about fake payment issues to steal bank info.

    Read πŸ”— hackread.com/i-paid-twice-scam

  34. πŸ›‘ New and ongoing β€œI Paid Twice” scam hits hotels and guests using #PureRAT via ClickFix attack. Attackers breach booking accounts like #Booking.com, then message travelers about fake payment issues to steal bank info.

    Read πŸ”— hackread.com/i-paid-twice-scam

    #Cybersecurity #HotelFraud #Malware #Phishing #ClickFix

  35. πŸ›‘ New and ongoing β€œI Paid Twice” scam hits hotels and guests using #PureRAT via ClickFix attack. Attackers breach booking accounts like #Booking.com, then message travelers about fake payment issues to steal bank info.

    Read πŸ”— hackread.com/i-paid-twice-scam

    #Cybersecurity #HotelFraud #Malware #Phishing #ClickFix

  36. πŸ›‘ New and ongoing β€œI Paid Twice” scam hits hotels and guests using #PureRAT via ClickFix attack. Attackers breach booking accounts like #Booking.com, then message travelers about fake payment issues to steal bank info.

    Read πŸ”— hackread.com/i-paid-twice-scam

    #Cybersecurity #HotelFraud #Malware #Phishing #ClickFix

  37. The technical detail in this PureRAT analysis by Heejae Hwang (ν™©ν¬μž¬) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress. It even uses the same C2 server 157.66.26.209:56001.

  38. The technical detail in this PureRAT analysis by Heejae Hwang (ν™©ν¬μž¬) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress. It even uses the same C2 server 157.66.26.209:56001.

  39. The technical detail in this PureRAT analysis by Heejae Hwang (ν™©ν¬μž¬) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress. It even uses the same C2 server 157.66.26.209:56001.

  40. The technical detail in this PureRAT analysis by Heejae Hwang (ν™©ν¬μž¬) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress. It even uses the same C2 server 157.66.26.209:56001.

  41. The technical detail in this PureRAT analysis by Heejae Hwang (ν™©ν¬μž¬) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress. It even uses the same C2 server 157.66.26.209:56001.

  42. Phishing emails that look legit and hidden DLLs are paving the way for a new breed of cyber threats. How did attackers upgrade from a simple infostealer to a full-blown RAT? Dive into the evolution of PureRAT to find out.

    thedefendopsdiaries.com/dissec

    #purerat
    #cyberattack
    #dllsideloading
    #remotetrojan
    #defenseevasion

  43. Phishing emails that look legit and hidden DLLs are paving the way for a new breed of cyber threats. How did attackers upgrade from a simple infostealer to a full-blown RAT? Dive into the evolution of PureRAT to find out.

    thedefendopsdiaries.com/dissec

    #purerat
    #cyberattack
    #dllsideloading
    #remotetrojan
    #defenseevasion

  44. Phishing emails that look legit and hidden DLLs are paving the way for a new breed of cyber threats. How did attackers upgrade from a simple infostealer to a full-blown RAT? Dive into the evolution of PureRAT to find out.

    thedefendopsdiaries.com/dissec

    #purerat
    #cyberattack
    #dllsideloading
    #remotetrojan
    #defenseevasion

  45. Phishing emails that look legit and hidden DLLs are paving the way for a new breed of cyber threats. How did attackers upgrade from a simple infostealer to a full-blown RAT? Dive into the evolution of PureRAT to find out.

    thedefendopsdiaries.com/dissec

    #purerat
    #cyberattack
    #dllsideloading
    #remotetrojan
    #defenseevasion