Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, be
FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness FishMonger’s arsenal upgraded: SprySOCKS for Windows Award-winning news, views, and insight f
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. an
2608-volatility-interlock <p>Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists</p> Categories: Threat Research Interlock ransomware gang creates volatile situation | SOPHOS Skip to Content Open search Get started Experiencing a cyberattack? Get
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever New Abuse of the ClickOnce Technology: Part 2 | CrowdStrike Blog Featured New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying For
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment New Abuse of the ClickOnce Technology: Part 1 | CrowdStrike Blog Featured New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Foreve
Deduped connector weight from graph context.