MalwareHunterTeam
@malwrhunterteam.bsky.social
https://x.com/malwrhunterteam | https://id-ransomware.malwarehunterteam.com/
🤷♂️
"CaseArchiveViewer.exe" signed with "Flagship Promotion s. r. o." EV cert. Flagged for deploying NetSupport RAT and Vidar 8099e85c4aa05f50ff299a130dc26a67b45aed519668e8b1ee1692e0034196c2 Certificate reported. https://tria[.]ge/260223-z2lj3abx8f/behavioral1 h/t MalwareHunterTeam
🤷♂️
a baby is sitting on a bed wearing a varsity shirt and crying .
ALT: a baby is sitting on a bed wearing a varsity shirt and crying .
media.tenor.com
"Purchase Agreement.pif" signed "HYPERBOLA TRADECOM LIMITED" a08293e23e09d53692aca4b20974f270e48c58c53532c6cc715993d24e928e35 Probably not a purchasing agreement and probably not a CrowdStrike Falcon sensor. Cert was reported for revocation h/t @malwrhunterteam
🤷♂️
#100DaysofYARA - Day 7 @malwrhunterteam identified a suspicious file signed by "Xiamen Jialan Guang Information Technology Service Co., Ltd." While we have a pretty good idea it'll be abused, it hasn't been yet. So, lets watch for it to be abused. Rule at end 1/5
Microsoft's support unintentionally infects people's machines with malware? 🤔
2025-01-08 (Wednesday): Alright, man! I could use a vacation! The final #phishing page at faernleys[.]com didn't work for me, though.