tarnkappeinfo, to random German
@tarnkappeinfo@social.tchncs.de avatar

📬 Foxit PDF Exploit: Ein unbedachter Klick löst Angriffskette aus
#ITSicherheit #AgentTesla #DoNotTeam #Exploid #FOXITPDF #FoxitReader #pdf https://sc.tarnkappe.info/17d3b6

simontsui, to Discord

Trellix: Threat actors, including APTs, are abusing the Discord application for payload delivery, information stealing and data exfiltration. Trellix identified several malware families leveraging Discord's capabilities to conduct their operations, uncovering when they started abusing them. IOC provided.
Link: https://www.trellix.com/en-us/about/newsroom/stories/research/discord-i-want-to-play-a-game.html

Tags:

malware_traffic, to random

2023-09-21 (Thursday) thru 09-25 (Monday): I collected examples of from my honeypot email accounts, and thought I'd share, since this is an ongoing threat.

Although it's something I consider a "low-hanging fruit," AgentTesla remains part of our threat landscape, with compromised accounts used for data exfiltration active for months at a time.

IOCs are available at https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2023-09-21-thru-09-25-IOCs-for-AgentTesla-activity.txt

Email/malware samples and from one of the infections are available at: https://www.malware-traffic-analysis.net/2023/09/25/index.html

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • provamag3
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • Leos
  • anitta
  • cisconetworking
  • megavids
  • lostlight
  • All magazines