Quantcast
Channel: You searched for lazagne - The DFIR Report
Browsing latest articles
Browse All 5 View Live

GoGoogle Ransomware

An attacker logged into the honeypot from 93.174.95[.]73, disabled security tools, dropped their toolkit and started recon. Recon was quickly followed by an onslaught of password dumping tools such as...

View Article


Trickbot Brief: Creds and Beacons

Intro “TrickBot malware—first identified in 2016—is a Trojan developed and operated by a sophisticated group of cybercrime actors. The cybercrime group initially designed TrickBot as a banking trojan...

View Article

Cobalt Strike, a Defender’s Guide

Intro In our research, we expose adversarial Tactics, Techniques and Procedures (TTPs) as well as the tools they use to execute their mission objectives. In most of our cases, we … Read More The post...

View Article

SEO Poisoning – A Gootloader Story

In early February 2022, we witnessed an intrusion employing Gootloader (aka GootKit) as the initial access vector. The intrusion lasted two days and comprised discovery, persistence, lateral movement,...

View Article

2022 Year in Review

As we move into the new year, it’s important to reflect on some of the key changes and developments we observed and reported on in 2022. This year’s year-in-review report … Read More The post 2022 Year...

View Article

Browsing latest articles
Browse All 5 View Live