home.social

#ursnif — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ursnif, aggregated by home.social.

fetched live
  1. Cybercriminals are using #Scalable_Vector_Graphics (#SVG) files to deliver malware because SVG is an XML-based vector image format for two-dimensional graphics that supports interactivity and animation. SVG files can natively contain #JavaScript code, which can be executed by browsers when the SVG is loaded.
    They do this by leveraging the #AutoSmuggle tool introduced in May 2022. This tool embeds malicious files into SVG/HTML content, bypassing security measures. Notably, SVG files were exploited to distribute #ransomware in 2015 and the #Ursnif malware in January 2017. A significant advancement occurred in 2022, with malware like #QakBot being delivered through SVG files containing embedded .zip archives. AutoSmuggle campaigns in December 2023 and January 2024 delivered the #XWorm #RAT and #Agent_Tesla #Keylogger, respectively, showcasing a shift towards embedding executable files directly within SVG files to evade detection by Secure Email Gateways (#SEGs). This evolution underscores the need for updated security measures to combat sophisticated malware delivery methods.
    The misuse of SVG files for malware distribution dates back to 2015, with ransomware being one of the first to be delivered through this vector.
    Original report: Cofense

  2. Cybercriminals are using #Scalable_Vector_Graphics (#SVG) files to deliver malware because SVG is an XML-based vector image format for two-dimensional graphics that supports interactivity and animation. SVG files can natively contain #JavaScript code, which can be executed by browsers when the SVG is loaded.
    They do this by leveraging the #AutoSmuggle tool introduced in May 2022. This tool embeds malicious files into SVG/HTML content, bypassing security measures. Notably, SVG files were exploited to distribute #ransomware in 2015 and the #Ursnif malware in January 2017. A significant advancement occurred in 2022, with malware like #QakBot being delivered through SVG files containing embedded .zip archives. AutoSmuggle campaigns in December 2023 and January 2024 delivered the #XWorm #RAT and #Agent_Tesla #Keylogger, respectively, showcasing a shift towards embedding executable files directly within SVG files to evade detection by Secure Email Gateways (#SEGs). This evolution underscores the need for updated security measures to combat sophisticated malware delivery methods.
    The misuse of SVG files for malware distribution dates back to 2015, with ransomware being one of the first to be delivered through this vector.
    Original report: Cofense

  3. Cybercriminals are using #Scalable_Vector_Graphics (#SVG) files to deliver malware because SVG is an XML-based vector image format for two-dimensional graphics that supports interactivity and animation. SVG files can natively contain #JavaScript code, which can be executed by browsers when the SVG is loaded.
    They do this by leveraging the #AutoSmuggle tool introduced in May 2022. This tool embeds malicious files into SVG/HTML content, bypassing security measures. Notably, SVG files were exploited to distribute #ransomware in 2015 and the #Ursnif malware in January 2017. A significant advancement occurred in 2022, with malware like #QakBot being delivered through SVG files containing embedded .zip archives. AutoSmuggle campaigns in December 2023 and January 2024 delivered the #XWorm #RAT and #Agent_Tesla #Keylogger, respectively, showcasing a shift towards embedding executable files directly within SVG files to evade detection by Secure Email Gateways (#SEGs). This evolution underscores the need for updated security measures to combat sophisticated malware delivery methods.
    The misuse of SVG files for malware distribution dates back to 2015, with ransomware being one of the first to be delivered through this vector.
    Original report: Cofense

  4. Cybercriminals are using #Scalable_Vector_Graphics (#SVG) files to deliver malware because SVG is an XML-based vector image format for two-dimensional graphics that supports interactivity and animation. SVG files can natively contain #JavaScript code, which can be executed by browsers when the SVG is loaded.
    They do this by leveraging the #AutoSmuggle tool introduced in May 2022. This tool embeds malicious files into SVG/HTML content, bypassing security measures. Notably, SVG files were exploited to distribute #ransomware in 2015 and the #Ursnif malware in January 2017. A significant advancement occurred in 2022, with malware like #QakBot being delivered through SVG files containing embedded .zip archives. AutoSmuggle campaigns in December 2023 and January 2024 delivered the #XWorm #RAT and #Agent_Tesla #Keylogger, respectively, showcasing a shift towards embedding executable files directly within SVG files to evade detection by Secure Email Gateways (#SEGs). This evolution underscores the need for updated security measures to combat sophisticated malware delivery methods.
    The misuse of SVG files for malware distribution dates back to 2015, with ransomware being one of the first to be delivered through this vector.
    Original report: Cofense

  5. Cybercriminals are using #Scalable_Vector_Graphics (#SVG) files to deliver malware because SVG is an XML-based vector image format for two-dimensional graphics that supports interactivity and animation. SVG files can natively contain #JavaScript code, which can be executed by browsers when the SVG is loaded.
    They do this by leveraging the #AutoSmuggle tool introduced in May 2022. This tool embeds malicious files into SVG/HTML content, bypassing security measures. Notably, SVG files were exploited to distribute #ransomware in 2015 and the #Ursnif malware in January 2017. A significant advancement occurred in 2022, with malware like #QakBot being delivered through SVG files containing embedded .zip archives. AutoSmuggle campaigns in December 2023 and January 2024 delivered the #XWorm #RAT and #Agent_Tesla #Keylogger, respectively, showcasing a shift towards embedding executable files directly within SVG files to evade detection by Secure Email Gateways (#SEGs). This evolution underscores the need for updated security measures to combat sophisticated malware delivery methods.
    The misuse of SVG files for malware distribution dates back to 2015, with ransomware being one of the first to be delivered through this vector.
    Original report: Cofense

  6. Cyber Security Updates
    Malware Loaders Responsible for 80% of Security Incidents
    Dealing with malware loaders poses intricate challenges for SOC teams.

    A recent exploration by ReliaQuest has unveiled a multitude of disruptive loader instances. Notably, the trio comprised of “QakBot” (also recognized as QBot, QuackBot, Pinkslipbot), “SocGholish,” and “Raspberry Robin” emerged as the predominant culprits.

    #QakBot #Gootloader #Guloader #Ursnif #Chromeloader #ACCESSYSTEM

  7. New blog post! In this one I look at a #BATLoader MSI sample referenced by @malwrhunterteam which resulted in #Ursnif and #Redline execution. Some fun twists and turns in this. forensicitguy.github.io/batloa

    #malware

  8. New blog post! In this one I look at a #BATLoader MSI sample referenced by @malwrhunterteam which resulted in #Ursnif and #Redline execution. Some fun twists and turns in this. forensicitguy.github.io/batloa

    #malware

  9. New blog post! In this one I look at a #BATLoader MSI sample referenced by @malwrhunterteam which resulted in #Ursnif and #Redline execution. Some fun twists and turns in this. forensicitguy.github.io/batloa

    #malware

  10. New blog post! In this one I look at a #BATLoader MSI sample referenced by @malwrhunterteam which resulted in #Ursnif and #Redline execution. Some fun twists and turns in this. forensicitguy.github.io/batloa

    #malware

  11. للمره المليون لا تحميل او تدخل رابط من اعلان من بحث في قوقل
    ---
    RT @1ZRR4H
    1/ DEV-0569, current distribution via #GoogleAds.

    1.- #Gozi aka #Ursnif (bot) ↓
    2.- #RedLine (stealer) ↓
    And if the conditions are right, possibly:
    3.- #CobaltStrike (C2) ↓
    4.- #Royal Ransomware 💥

    (No more BatLoader in the infection chain)
    twitter.com/1ZRR4H/status/1616

  12. للمره المليون لا تحميل او تدخل رابط من اعلان من بحث في قوقل
    ---
    RT @1ZRR4H
    1/ DEV-0569, current distribution via .

    1.- aka (bot) ↓
    2.- (stealer) ↓
    And if the conditions are right, possibly:
    3.- (C2) ↓
    4.- Ransomware 💥

    (No more BatLoader in the infection chain)
    twitter.com/1ZRR4H/status/1616

  13. @th3_protoCOL

    Current #payloads:

    -ZipCosdaz.exe (#RedLine)
    C2: 193.56.146.114:44271
    Botnet: NewBuild

    - ZipCosdaz1.exe (#Ursnif aka #Gozi)
    C2 servers:
    45.11.182.97
    79.132.128.108
    91.241.93.98
    79.132.128.109
    91.242.217.28
    91.241.93.111
    Botnet: 2503

    - ConsoleDWS.exe (Destroy Windows 10 Spying)
    GitHub repo: github.com/spinda/Destroy-Wind

    + And another download URL: archiverportal[.]space/porn.php

  14. @th3_protoCOL

    Current #payloads:

    -ZipCosdaz.exe (#RedLine)
    C2: 193.56.146.114:44271
    Botnet: NewBuild

    - ZipCosdaz1.exe (#Ursnif aka #Gozi)
    C2 servers:
    45.11.182.97
    79.132.128.108
    91.241.93.98
    79.132.128.109
    91.242.217.28
    91.241.93.111
    Botnet: 2503

    - ConsoleDWS.exe (Destroy Windows 10 Spying)
    GitHub repo: github.com/spinda/Destroy-Wind

    + And another download URL: archiverportal[.]space/porn.php

  15. @th3_protoCOL

    Current #payloads:

    -ZipCosdaz.exe (#RedLine)
    C2: 193.56.146.114:44271
    Botnet: NewBuild

    - ZipCosdaz1.exe (#Ursnif aka #Gozi)
    C2 servers:
    45.11.182.97
    79.132.128.108
    91.241.93.98
    79.132.128.109
    91.242.217.28
    91.241.93.111
    Botnet: 2503

    - ConsoleDWS.exe (Destroy Windows 10 Spying)
    GitHub repo: github.com/spinda/Destroy-Wind

    + And another download URL: archiverportal[.]space/porn.php

  16. @th3_protoCOL

    Current #payloads:

    -ZipCosdaz.exe (#RedLine)
    C2: 193.56.146.114:44271
    Botnet: NewBuild

    - ZipCosdaz1.exe (#Ursnif aka #Gozi)
    C2 servers:
    45.11.182.97
    79.132.128.108
    91.241.93.98
    79.132.128.109
    91.242.217.28
    91.241.93.111
    Botnet: 2503

    - ConsoleDWS.exe (Destroy Windows 10 Spying)
    GitHub repo: github.com/spinda/Destroy-Wind

    + And another download URL: archiverportal[.]space/porn.php

  17. Ongoing #Ursnif campaign loads DLL that claims to be txt file into memory. Follow on activity from both #tvrat and #cobaltstrike

    C2 8.208.90.2, 47.241.106.208, various domains usually starting with f1[.]pipen[.]at

    IOC's in @MISPProject Priv.

    #DFIR

    thedfirreport.com/2020/04/24/u …pic.twitter.com/0OoRNLWZBO

  18. Malicious #URSNIF campaign uses hacked email accounts to send malware to its victim via an existing email thread (opportunistic approach). This is both evil and genius, victims know the sender and trust the message to be innocuous..💥 blog.trendmicro.com/trendlabs- #malware #threatintel t.co/Xn2uIOFWqF