Загрузка...

Dead or Alive? An Emotet Story (THE DFIR REPORT)

Тема в разделе Безопасность создана пользователем cmd_32 22 сен 2022. 450 просмотров

Загрузка...
  1. cmd_32
    cmd_32 Автор темы 22 сен 2022 0 3 июн 2022
    This is a good document about Emotet malware
    ---------------------------------------------------------------------------
    In this intrusion from May 2022, we observed a domain-wide compromise that started from a malware ridden Excel document containing the never-dying malware, Emotet.

    The post-exploitation started very soon after the initial compromise. The threat actors began enumerating the network once Emotet deployed a Cobalt Strike beacon on the beachhead host. After three days of discovery and lateral movement, the threat actors exfiltrated sensitive data using Rclone before leaving the network.

    After a successful takedown thanks to Interpol and Eurojust efforts, Emotet was resurrected in November 2021 with the help of Trickbot malware. Since then, Emotet has been testing different initial access payloads while its developers were busy improving the core functionality of the actual malware. Since January 2022 we observed an increase in the activity of Cobalt Strike deployments following Emotet intrusions.

    In a few weeks, we’ll have another Emotet report out from June, where the intrusion used similar TTPs and ended in ransomware.

    https://thedfirreport.com/2022/09/12/dead-or-alive-an-emotet-story/
     
  2. God_likeGL
    God_likeGL Layer 1 22 сен 2022 ЛУЧШИЕ ВЕРИФИКАЦИИ - lolz.live/threads/4228395/ :+rep: 27 741 30 окт 2018
    что это такое
     
  3. cmd_32
    cmd_32 Автор темы 22 сен 2022 0 3 июн 2022
Top