Tim Brown

Results 258 issues of Tim Brown

### Area Malware reports ### Parent threat _No response_ ### Finding https://imgur.com/a/4YxuSfV ### Industry reference Cayosin (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics

### Area Malware reports ### Parent threat Defense Evasion, Discovery, Command and Control ### Finding https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html ### Industry reference attack:T1090:Proxy uses:ProcessTreeSpoofing attack:T1027:Obfuscated Files or Information attack:T1082:System Information Discovery ### Malware...

missing:tag:T1005
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1083
missing:tag:T1552.003
missing:tag:T1027.002
missing:tag:T1007
missing:tag:T1053.006
missing:tag:T1543.002
missing:tag:wltm

### Area Malware PoCs ### Parent threat Defense Evasion ### Finding https://github.com/SilentVoid13/Silent_Packer ### Industry reference attack:T1027.002:Software Packing ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tag:T1005
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1567
missing:tag:T1573

### Area Malware PoCs ### Parent threat Execution, Persistence ### Finding https://github.com/sad0p/d0zer ### Industry reference uses:Go attack:T1625:Hijack Execution Flow attack:T1204:Malicious File ### Malware reference _No response_ ### Actor reference _No...

new
missing:tag:T1048
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:Non-persistentStorage
missing:tag:T1574.006
missing:tag:T1574.007
missing:tag:T1027.004
missing:tag:Go

### Area Offensive tools ### Parent threat Credential Access, Collection ### Finding https://github.com/SkyperTHC/bpf-keylogger ### Industry reference uses:eBPF attack:T1417.001:Keylogging ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tag:T1005
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1567
missing:tag:T1573

### Area Malware reports ### Parent threat _No response_ ### Finding https://imgur.com/a/lAQ1tMQ ### Industry reference HelloBot (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics

### Area Defensive tools ### Parent threat Defense Evasion ### Finding https://github.com/Achiefs/fim ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tag:T1005
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590

### Area Malware source ### Parent threat Defense Evasion ### Finding https://github.com/gianlucaborello/libprocesshider ### Industry reference uses:ProcessTreeSpoofing attack:T1574.006:Dynamic Linker Hijacking ### Malware reference libprocesshider ### Actor reference _No response_ ### Component...

new
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1071.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
missing:tag:T1548.003
missing:tag:T1027.004
missing:tag:T1046

### Area Malware source ### Parent threat Defense Evasion ### Finding https://github.com/chenkaie/junkcode/blob/master/xhide.c ### Industry reference uses:ProcessTreeSpoofing ### Malware reference XHide ### Actor reference _No response_ ### Component Linux ### Scenario...

new
missing:submodule

### Area Defensive techniques ### Parent threat Defense Evasion ### Finding https://blog.virustotal.com/2023/12/sigma-rules-for-linux-and-macos_20.html ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

missing:malware
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1053.003
missing:tag:wltm