Daniel

163 posts

Daniel banner
Daniel

Daniel

@dansomware

threat research @proofpoint // tweets are probably someone else's

Katılım Ağustos 2010
694 Takip Edilen338 Takipçiler
Daniel retweetledi
Threat Insight
Threat Insight@threatinsight·
Proofpoint has tracked this technique since August 2024, and call it “brooxml”. Our researchers do not consider this a zero-day or vulnerability in general. We’ve released Emerging Threats and YARA signatures at the end of this thread.
ANY.RUN@anyrun_app

🚨ALERT: Potential ZERO-DAY, Attackers Use Corrupted Files to Evade Detection 🧵 (1/3) ⚠️ The ongoing attack evades #antivirus software, prevents uploads to sandboxes, and bypasses Outlook's spam filters, allowing the malicious emails to reach your inbox The #ANYRUN team discovered that as part of this #zeroday attack, threat actors attempt to conceal the file type by deliberately corrupting it, making it difficult for certain security tools to detect 📌 Our sandbox solves this problem thanks to interactivity. It launches these broken files in their corresponding programs, which allows it to identify #malicious behavior See example: app.any.run/tasks/6839e806… 🚫 Although these files operate successfully within the OS, they remain undetected by most security solutions due to the failure to apply proper procedures for their file types They were uploaded to VirusTotal, but all antivirus solutions returned "clean" or “Item Not Found” as they couldn't analyze the file properly

English
4
65
179
39.6K
Daniel
Daniel@dansomware·
@ImposeCost And further, that when the time of useful observance has run its course, that justice is served.
English
0
0
2
49
Daniel
Daniel@dansomware·
@ImposeCost I don't necessarily think you're implying this, but it kind of sounds like "well, it's more valuable to provide access and watch what's done with it", which I can't necessarily fault, provided the ability to do real damage is mitigated.
English
1
0
2
65
Daniel
Daniel@dansomware·
@ex_raritas @TheGamblingBird Since no one has mentioned, we have some great vegetarian/vegan options too. Would check out Apteka and Onion Maiden.
English
0
0
1
53
Daniel retweetledi
Threat Insight
Threat Insight@threatinsight·
In this special holiday edition of DISCARDED, Mindy Semling joins as guest host for a 2nd annual "Ask Me Anything" episode. In this lively discussion, Selena & Crista answer questions from the audience and bid farewell to the 2023 cybersecurity landscape. ow.ly/9LRB50QmsIV
Threat Insight tweet media
English
0
4
11
1.5K
Daniel retweetledi
randy@infosec.exchange
[email protected]@rpargman·
Great blog just published on an interesting cluster of #DarkGate malware distribution activity that used high-volume email campaigns, compromised websites with fake browser updates, steganography in CSS, and TDS filtering deliver DarkGate: proofpoint.com/us/blog/threat…
English
0
17
50
8.6K
Daniel retweetledi
Greg Lesnewich
Greg Lesnewich@greglesnewich·
proofpoint.com/us/blog/threat… confused by the fake browser landscape? me too - thats why I'm glad my teammates track this come for the clarity, stay for the inject examples to show the differences between the kits!
English
0
4
23
3.1K
Daniel
Daniel@dansomware·
@ex_raritas Yeah, sex is cool, but have you tried roasting friends and family for violation of flag code? Looking at you, thin blue line.
English
1
0
3
199
Andrew Northern 𓅓
Andrew Northern 𓅓@ex_raritas·
The American flag 🇺🇸 towel really is the country pashmina.
English
1
0
1
449
Daniel retweetledi
Andrew Northern 𓅓
Andrew Northern 𓅓@ex_raritas·
Want to see something new and exciting? Are you a blue teamer and want to see a novel new way threat actors have been observed exploiting LNK files in the wild? Are you a red teamer and want to see how this exploit works on a technical level and how I recreated it? Are you a CTI professional who evangelizes about the benefits of attribution? Are you an infosec professional or enthusiast who loves video game humor? This talk is for you! Join us in person or online here: na.eventscloud.com/website/58627/ I’ll be sharing the stage with @aRtAGGI from Google Cloud (Mandiant). This promises to be a very fun and informative talk. I hope to see you. @MITREattack
Andrew Northern 𓅓 tweet media
English
0
3
17
4.4K
Daniel
Daniel@dansomware·
@sherrod_im @ImposeCost I fundamentally agree but also have empathy for "don't rock the boat" because in an industry that is fraught with burnout, finding a sustainable operational tempo is imperative. It's easy for transformation to feel like "no matter how hard you work you can never be comfortable".
English
1
0
1
117
Daniel
Daniel@dansomware·
@wesdrone Do detainees at Guantanamo have TTPs? What's the ID for hunger strike?
English
0
0
1
105
Daniel
Daniel@dansomware·
We're like 5 social media layers deep now.
English
0
0
0
59
Daniel
Daniel@dansomware·
So Twitter -> Reddit is a really common occurrence ... I feel like there is a disparity in the amount of amazing comments highlighted in reverse. Especially ones that roast @elonmusk
Daniel tweet media
English
1
0
1
153
Daniel
Daniel@dansomware·
@ImposeCost Was it the browser, or were they functionally your ISP?
English
0
0
1
48
Daniel retweetledi
Threat Insight
Threat Insight@threatinsight·
Like forensic scientists, threat analysts are always on the hunt for digital fingerprints. 🔎 In this DISCARDED #podcast episode, we discuss the China #cybercrime threat landscape and the importance of staying aware of past trends. Stream now at ow.ly/P7hP50PFFi4.
English
0
6
20
5.6K
Daniel retweetledi
Greg Lesnewich
Greg Lesnewich@greglesnewich·
🚨 Job Openings! Our team is looking to hire for 2 positions on our APT tracking team. Primary responsibilities & day-to-day will be disrupting state-aligned or state-sponsored actors trying to deliver malware, phish, or otherwise engage with our customers, in email data.
English
3
52
130
38K
Lina
Lina@d0rkph0enix·
My boss had these commissioned for the team, hand painted and adorned with our names and company logo, we’re going to wear them as a team tomorrow to the general session!! So, so dope. Well done, @kickswithatwist!! #PaloAltoNetworks
Lina tweet mediaLina tweet mediaLina tweet media
English
15
2
164
9.5K