Dimanche 02 mars 2025

Un voyage en train de dix heures pour déposer des lettres rouges coquelicot devient une aventure pleine de réflexions sur l’inconnu.

Atypikal Life

There must be something about today. I received another alert from our EDR of a malicious file landing on an end user asset. After further investigation it was another phishing email, with the same TTP as previous... File has been removed, the asset has been quarantined and scanned.

Sample: baa9e6b2fa25f1a62a0e2704d7879054

YARA Signature Match - THOR APT Scanner

RULE: SUSP_ISO_In_ZIP_Small_May22_1
RULE_SET: Livehunt - Suspicious42 Indicators 🏹
RULE_TYPE: THOR APT Scanner's rule set only 🔨
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_ISO_In_ZIP_Small_May22_1
DESCRIPTION: Detects suspicious ISO file in small ZIP files

#security #phishing #yara #malware #HEUR #trojan #EDR #ISO #TTP

Rule Info SUSP_ISO_In_ZIP_Small_May22_1 - Valhalla