Filescan.io

268 posts

Filescan.io banner
Filescan.io

Filescan.io

@filescan_itsec

https://t.co/7eeFPFSU7m is a next-gen sandbox and malware analysis service. Operating at 10x speed vs traditional, it is the best choice for in-depth malware assessment

Germany Katılım Ekim 2020
35 Takip Edilen1.6K Takipçiler
Filescan.io
Filescan.io@filescan_itsec·
🧵 Tweet 2/3: The full chain: BAT dropper > PowerShell with -ep bypass + hidden window + reversed API strings > reflective .NET assembly load, never touching disk. Packed with .NET Reactor 6.x (Anti-Tamper + Anti-ILDASM). 12 files extracted from a single 1.6 MB script.
Filescan.io tweet media
English
1
0
0
125
Filescan.io
Filescan.io@filescan_itsec·
Time to hunt with Filescan! 🔍 Malware config extraction turned recent samples into quick hunting leads: - #AsyncRAT masquerading as Netflix/Spotify/Copilot/Roblox - #Remcos using DuckDNS for C2 - #XWorm using portmap[.]host and *.ply.gg tunnels filescan.io/search-result?…
Filescan.io tweet mediaFilescan.io tweet media
English
0
3
7
696
Filescan.io
Filescan.io@filescan_itsec·
🎯 Emulation catches what static misses! New underdetected sample flagged as Confirmed Threat🚨 The execution chain mirrors #FairyWolf activity across Russian industries, deploying Unicorn Stealer HTA→VBS Script→Unicorn Report: filescan.io/uploads/699d22… #zeroday #sandbox
Filescan.io tweet mediaFilescan.io tweet media
English
0
0
5
477
Filescan.io
Filescan.io@filescan_itsec·
New malware sample spotted 🔍👀 Fresh JS dropper linked to an ongoing phishing campaign from October still delivering #Remcos #RAT. FileScan’s emulation decoded a reversed-Base64 payload, extracting dropped artefacts + Remcos config & C2 IoCs. Report: filescan.io/uploads/69673f…
Filescan.io tweet mediaFilescan.io tweet media
English
0
1
2
392
Filescan.io
Filescan.io@filescan_itsec·
Yesterday's Report of the Day showed a nice threat: JS > autoit > payload. Then similarity search quickly revealed it’s part of an active campaign, reported by SonicWall months ago. A reminder of how powerful is for hunting campaigns fast. #remcos #intel filescan.io/uploads/695fc9…
Filescan.io tweet mediaFilescan.io tweet media
English
1
0
1
275
Filescan.io
Filescan.io@filescan_itsec·
Vietnam gov #phishing campaign Attack chain: 📩eml->js->bat-> PowerShell☠️ 4 days ago, a malicious file disguised as a tax notice from Vietnam's Government was uploaded and detected as a threat by Filescan’s emulation. Check out how we flagged this! 🦉 filescan.io/uploads/691ad8…
Filescan.io tweet mediaFilescan.io tweet media
English
0
0
3
332
Filescan.io
Filescan.io@filescan_itsec·
Still malware in MP3s? 🎧 @TrendMicro uncovered Fake CAPTCHA campaigns abusing MP3s with obfuscated JS — and the audio still plays. Want to rip open the track, emulate hidden code, and expose this threat's insights — all in a single run? 🔍 filescan.io/uploads/6900d7… #sandbox #DFIR
Filescan.io tweet mediaFilescan.io tweet mediaFilescan.io tweet mediaFilescan.io tweet media
English
0
0
2
339
Filescan.io
Filescan.io@filescan_itsec·
Attackers abused Alibaba #AI brand to push fake #PyPI packages with malicious #Pickle stealer 😈🥒. Though online less than 24 hours, they were downloaded ~1,600 times. This shows how fast supply chain attacks can spread Check out sandbox's Pickle scan: filescan.io/uploads/68bf95…
Filescan.io tweet mediaFilescan.io tweet mediaFilescan.io tweet media
English
0
5
10
664