Tim Brown

Results 258 issues of Tim Brown

### Area Malware reports ### Parent threat _No response_ ### Finding https://github.com/blackberry/threat-research-and-intelligence/raw/main/Talks/2023-01-30%20-%20SANS%20Cyber%20Threat%20Intelligence%20Summit%20%26%20Training%202023/Pedro%20Drimel%2C%20Jose%20Luis%20Sanchez%20Martinez%20-%20Practical%20CTI%20Analysis%20Over%202022%20ITW%20Linux%20Implants.pdf ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No...

missing:tactics
ignore:submodule

### Area Malware reports ### Parent threat _No response_ ### Finding https://imgur.com/a/53f29O9 ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics

### Area Malware reports ### Parent threat _No response_ ### Finding https://imgur.com/a/qqgfFXf ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics

### Area Offensive tools ### Parent threat Defense Evasion ### Finding https://github.com/guitmz/memrun ### Industry reference attack:T1620:Reflective Code Loading uses:Non-persistentStorage ### Malware reference _No response_ ### Actor reference _No response_ ###...

missing:tag:T1057
missing:tag:Non-persistentStorage
missing:tag:T1620

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.malwaremustdie.org/2020/02/mmd-0065-2021-linuxmirai-fbot-re.html ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1059.006
missing:tag:T1574.006
missing:tag:T1003.008
missing:tag:T1205
missing:tag:IRC

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.malwaremustdie.org/2020/01/mmd-0065-2020-linuxmirai-fbot.html ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1574.006
missing:tag:T1003.008
missing:tag:T1071.002
missing:tag:IRC

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.malwaremustdie.org/2016/08/mmd-0056-2016-linuxmirai-just.html ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1574.006
missing:tag:T1003.008
missing:tag:RedirectionToNull
missing:tag:T1205
missing:tag:ProcessTreeSpoofing
missing:tag:T1046
missing:tag:ProcessTreeSpoofingForking
missing:tag:IRC

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.microsoft.com/security/blog/2021/07/22/when-coin-miners-evolve-part-1-exposing-lemonduck-and-lemoncat-modern-mining-malware-infrastructure/ ### Industry reference LemonDuck ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:JavaScript
missing:tag:T1069

### Area Press/academia ### Parent threat _No response_ ### Finding https://securelist.com/top-10-unattributed-apt-mysteries/107676/ ### Industry reference _No response_ ### Malware reference Metador Plexing Eagle wltm ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1027.002
missing:tag:T1560
missing:tag:T1205

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.trendmicro.com/en_gb/research/19/f/cryptocurrency-mining-botnet-arrives-through-adb-and-spreads-through-ssh.html ### Industry reference CoinMiner ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:Non-persistentStorage
missing:tag:T1222
missing:tag:T1548.001
missing:tag:wltm