MSI:
www.virustotal.com/gui/file/f5c...
Components all with 0 VT detections. DLLs are legitimate ones that were modified.
MSI:
www.virustotal.com/gui/file/f5c...
Components all with 0 VT detections. DLLs are legitimate ones that were modified.
0 VT detections on any component of the malware loader.
Proofpoint rules detect the outbound C2 traffic.
My Yara rule detects the installer.
0 VT detections on any component of the malware loader.
Proofpoint rules detect the outbound C2 traffic.
My Yara rule detects the installer.
eu.community.samsung.com/t5/samsung-s...
eu.community.samsung.com/t5/samsung-s...
With a code editor and validation, this should make submitting to the project much easier!
Link: www.jaiminton.com/tools/hijack...
Direct: hijacklibs-assistant.streamlit.app
With a code editor and validation, this should make submitting to the project much easier!
Link: www.jaiminton.com/tools/hijack...
Direct: hijacklibs-assistant.streamlit.app
Despite this contributing can be time consuming. That's why I've created HijackLibs Helper!👇
Despite this contributing can be time consuming. That's why I've created HijackLibs Helper!👇
security.samsungtv.com/securityUpda...
security.samsungtv.com/securityUpda...
ssd-disclosure.com/ssd-advisory...
The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
ssd-disclosure.com/ssd-advisory...
The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
DLL1: www.virustotal.com/gui/file/888...
DLL2: www.virustotal.com/gui/file/ea3...
DLL3: www.virustotal.com/gui/file/0c6...
Malicious WAV Stego: www.virustotal.com/gui/file/93c...
DLL1: www.virustotal.com/gui/file/888...
DLL2: www.virustotal.com/gui/file/ea3...
DLL3: www.virustotal.com/gui/file/0c6...
Malicious WAV Stego: www.virustotal.com/gui/file/93c...
At the time of scanning 1 vendor detected it, still only 3 at the moment. Deploying LummaC2 unsurprisingly.
This time a binary signed by 'ONE UP LTD' from the Nuclear Coffee VideoGet application used to load into memory.👇
At the time of scanning 1 vendor detected it, still only 3 at the moment. Deploying LummaC2 unsurprisingly.
This time a binary signed by 'ONE UP LTD' from the Nuclear Coffee VideoGet application used to load into memory.👇
DLL1: www.virustotal.com/gui/file/dd9...
DLL2: www.virustotal.com/gui/file/ccf...
DLL3: www.virustotal.com/gui/file/3d7...
DLL4: www.virustotal.com/gui/file/d0f...
Deploys LummaC2 into memory which is now using both Telegram channel and Steam Community names for C2 fallback.
👇
Deploys LummaC2 into memory which is now using both Telegram channel and Steam Community names for C2 fallback.
👇
Installs itself as 'Directory Converter' in the user LocalAppData 'Programs' directory.
👇
Installs itself as 'Directory Converter' in the user LocalAppData 'Programs' directory.
👇
This is an org that helps couples have a family.
🤬😡
www.genea.com.au/pages/import...
www.genea.com.au/sfsites/c/cm...
This is an org that helps couples have a family.
🤬😡
www.genea.com.au/pages/import...
www.genea.com.au/sfsites/c/cm...
www.virustotal.com/gui/file/f9d...
www.virustotal.com/gui/file/847...
www.virustotal.com/gui/file/f9d...
www.virustotal.com/gui/file/847...
urlscan.io/search/#saaa...
urlscan.io/search/#saaa...
Celestial Stealer is checking for my name or online handle and it won't execute if it's found, but my RE machine is using the name Barry so this check will fail.
Who do I reach out to about this? 😅
www.trellix.com/blogs/resear...
Celestial Stealer is checking for my name or online handle and it won't execute if it's found, but my RE machine is using the name Barry so this check will fail.
Who do I reach out to about this? 😅
www.trellix.com/blogs/resear...