home.social

#ursnif — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ursnif, aggregated by home.social.

fetched live
  1. Cybercriminals are using #Scalable_Vector_Graphics (#SVG) files to deliver malware because SVG is an XML-based vector image format for two-dimensional graphics that supports interactivity and animation. SVG files can natively contain #JavaScript code, which can be executed by browsers when the SVG is loaded.
    They do this by leveraging the #AutoSmuggle tool introduced in May 2022. This tool embeds malicious files into SVG/HTML content, bypassing security measures. Notably, SVG files were exploited to distribute #ransomware in 2015 and the #Ursnif malware in January 2017. A significant advancement occurred in 2022, with malware like #QakBot being delivered through SVG files containing embedded .zip archives. AutoSmuggle campaigns in December 2023 and January 2024 delivered the #XWorm #RAT and #Agent_Tesla #Keylogger, respectively, showcasing a shift towards embedding executable files directly within SVG files to evade detection by Secure Email Gateways (#SEGs). This evolution underscores the need for updated security measures to combat sophisticated malware delivery methods.
    The misuse of SVG files for malware distribution dates back to 2015, with ransomware being one of the first to be delivered through this vector.
    Original report: Cofense

  2. New blog post! In this one I look at a #BATLoader MSI sample referenced by @malwrhunterteam which resulted in #Ursnif and #Redline execution. Some fun twists and turns in this. forensicitguy.github.io/batloa

    #malware

  3. @th3_protoCOL

    Current #payloads:

    -ZipCosdaz.exe (#RedLine)
    C2: 193.56.146.114:44271
    Botnet: NewBuild

    - ZipCosdaz1.exe (#Ursnif aka #Gozi)
    C2 servers:
    45.11.182.97
    79.132.128.108
    91.241.93.98
    79.132.128.109
    91.242.217.28
    91.241.93.111
    Botnet: 2503

    - ConsoleDWS.exe (Destroy Windows 10 Spying)
    GitHub repo: github.com/spinda/Destroy-Wind

    + And another download URL: archiverportal[.]space/porn.php

  4. Ongoing #Ursnif campaign loads DLL that claims to be txt file into memory. Follow on activity from both #tvrat and #cobaltstrike

    C2 8.208.90.2, 47.241.106.208, various domains usually starting with f1[.]pipen[.]at

    IOC's in @MISPProject Priv.

    #DFIR

    thedfirreport.com/2020/04/24/u …pic.twitter.com/0OoRNLWZBO

  5. Malicious #URSNIF campaign uses hacked email accounts to send malware to its victim via an existing email thread (opportunistic approach). This is both evil and genius, victims know the sender and trust the message to be innocuous..💥 blog.trendmicro.com/trendlabs- #malware #threatintel t.co/Xn2uIOFWqF