Tim Brown

Results 258 issues of Tim Brown

### Area Malware reports ### Parent threat Defense Evasion ### Finding https://unfinished.bike/fun-with-the-new-bpfdoor-2023 ### Industry reference attack:T1205.002:Socket Filters attack:T1205:Traffic Signaling uses:BPF uses:Non-persistentStorage attack:T1070.006:Timestomp attack:T1070.004:File Deletion ### Malware reference BPFDoor [/malware/binaries/BPFDoor](../tree/main/malware/binaries/BPFDoor) wltm...

confirmed

### Area Supply chain attacks ### Parent threat Initial Access, Discovery, Command and Control ### Finding https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/ ### Industry reference delivery:NPM attack:T1195.001:Compromise Software Dependencies and Development Tools attack:T1082:System Information Discovery...

confirmed

### Area Malware PoCs ### Parent threat Persistence, Privilege Escalation, Defense Evasion, Command and Control ### Finding https://github.com/R3tr074/brokepkg ### Industry reference uses:ProcessTreeSpoofing uses:AbnormalSignal uses:TamperCredStruct uses:PortHiding attack:T1547.006:Kernel Modules and Extensions attack:T1564.001:Hidden...

new
missing:tag:T1005
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1567
missing:tag:T1573
missing:tag:T1548.003

### Area Malware reports ### Parent threat Impact ### Finding https://twitter.com/Unit42_Intel/status/1653760405792014336 ### Industry reference attack:T1486:Data Encrypted for Impact ### Malware reference wltm BlackSuite ### Actor reference _No response_ ### Component...

confirmed

### Area Malware reports ### Parent threat Initial Access, Discovery, Lateral Movement, Collection, Impact ### Finding https://blog.sygnia.co/revealing-emperor-dragonfly-a-chinese-ransomware-group ### Industry reference attack:T1486:Data Encrypted for Impact ### Malware reference Cheerscrypt Night Sky...

new
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.002
missing:tag:T1021.001

### Area Malware reports ### Parent threat _No response_ ### Finding https://cybersecurity.att.com/blogs/labs-research/botenago-strike-again-malware-source-code-uploaded-to-github ### Industry reference Botenago ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1518

### Area Malware reports ### Parent threat _No response_ ### Finding http://it.rising.com.cn/fanglesuo/19851.html ### Industry reference SFile ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.001

### Area Malware reports ### Parent threat _No response_ ### Finding https://tolisec.com/ssh-backdoor-botnet-with-research-infection-technique/ ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.002
missing:tag:Non-persistentStorage
missing:tag:T1222
missing:tag:T1548.001
missing:tag:RedirectionToNull
missing:tag:T1518
missing:tag:T1070.002
missing:tag:T1021.004
missing:tag:T1558
missing:tag:T1037

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.netlab.360.com/threat-alert-log4j-vulnerability-has-been-adopted-by-two-linux-botnets/ ### Industry reference Muhstik ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1027.002
missing:tag:T1560
missing:tag:T1098.004
missing:tag:T1037
missing:tag:T1552.004
missing:tag:T1037.004

### Area Malware reports ### Parent threat _No response_ ### Finding https://pastebin.com/Z3sXqDCA ### Industry reference Mozi (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1053.003
missing:tag:Non-persistentStorage
missing:tag:T1222
missing:tag:T1548.001
missing:tag:T1059.006
missing:tag:T1071.004
missing:tag:RedirectionToNull
missing:tag:JavaScript
missing:tag:T1070.002
missing:tag:T1071.002
missing:tag:T1046
missing:tag:T1037
missing:tag:T1562.004
missing:tag:T1037.004