mathanrajtk's profile picture. Malware Researcher | APT Hunter

Mathanraj TK

@mathanrajtk

Malware Researcher | APT Hunter

Mathanraj TK reposted

#Latrodectus Nasty Obfuscation #TTPs & #IOCs🕷️ [+] JS T1059.007 [+] Command Obfuscation T1027.010 5 forward slashes contain malicious code; abuse 'WindowsInstaller.Installer' to install MSI from remote IP p://193.203.203[.]40/vfs[.]msi Thank you @k3dg3 bazaar.abuse.ch/sample/6ed4c0b…

Max_Mal_'s tweet image. #Latrodectus Nasty Obfuscation #TTPs & #IOCs🕷️

[+] JS T1059.007
[+] Command Obfuscation T1027.010

5 forward slashes contain malicious code; abuse 'WindowsInstaller.Installer' to install MSI from remote IP p://193.203.203[.]40/vfs[.]msi

Thank you @k3dg3
bazaar.abuse.ch/sample/6ed4c0b…
Max_Mal_'s tweet image. #Latrodectus Nasty Obfuscation #TTPs & #IOCs🕷️

[+] JS T1059.007
[+] Command Obfuscation T1027.010

5 forward slashes contain malicious code; abuse 'WindowsInstaller.Installer' to install MSI from remote IP p://193.203.203[.]40/vfs[.]msi

Thank you @k3dg3
bazaar.abuse.ch/sample/6ed4c0b…

Mathanraj TK reposted

New blog with more advanced cyberchef tricks! 🔥 Looking at Flow Control, Subsections and how you can deal with alternating math operations. embeeresearch.io/advanced-cyber… #malware #Cyberchef


The Handala Hacking Team, targeting Israeli entities with a destructive wiper malware designed to obliterate files. #wiper #Handala #israeli #Malware

Handala preys on the CrowdStrike outage chaos via phishing, using an AutoIT script to launch the wiper, collect system information, and exfiltrate it via Telegram’s API. Learn from @mathanrajtk, @libranalysis, and Tomer Shloman. bit.ly/4d0ri2A

TrellixARC's tweet image. Handala preys on the CrowdStrike outage chaos via phishing, using an AutoIT script to launch the wiper, collect system information, and exfiltrate it via Telegram’s API.  Learn from @mathanrajtk, @libranalysis, and Tomer Shloman. bit.ly/4d0ri2A


mathanrajtk's tweet image.
mathanrajtk's tweet image.
mathanrajtk's tweet image.
mathanrajtk's tweet image.

New malware campaign targets CrowdStrike Customers Email -> PDF -> URL -> Zip -> CrowdStrike.exe -> AutoIt Execution -> telegram



Mathanraj TK reposted

A variant of ViperSoftX leverages CLR to create a PowerShell environment within AutoIT and adapts existing components from offensive security scripts so threat actors can focus on improving evasion tactics. Learn more from @mathanrajtk and @sijojacob1111. bit.ly/3S0toap

TrellixARC's tweet image. A variant of ViperSoftX leverages CLR to create a PowerShell environment within AutoIT and adapts existing components from offensive security scripts so threat actors can focus on improving evasion tactics. Learn more from @mathanrajtk and @sijojacob1111. bit.ly/3S0toap

My blog with @sijojacob1111 about "New ViperSoftX Malware Variant" demonstrates sophisticated evasion tactics, such as using CLR to run PowerShell commands within AutoIt and patching AMSI to avoid detection trellix.com/blogs/research…


Loading...

Something went wrong.


Something went wrong.