Visualização normal

Antes de ontemStream principal

Almost Half of Malware Samples Communicate Direct to IP

4 de Agosto de 2026, 09:50

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.

The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

  • ✇The DFIR Report
  • Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs editor
    Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion began in […] The post Blurring the Lines: Intrusion Shows Connection With Three Major Ra
     

Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs

Por:editor
8 de Setembro de 2025, 11:20

Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion began in […]

The post Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs appeared first on The DFIR Report.

  • ✇The DFIR Report
  • Fake Zoom Ends in BlackSuit Ransomware editor
    Key Takeaways Case Summary This case from May 2024 started with a malicious download from a website mimicking the teleconferencing application Zoom. When visiting the website and downloading a file that seems intended for installing Zoom, the user was, in fact, installing a malicious program created with Inno Setup. The malicious program was a d3f@ck […] The post Fake Zoom Ends in BlackSuit Ransomware appeared first on The DFIR Report.
     

Fake Zoom Ends in BlackSuit Ransomware

Por:editor
30 de Março de 2025, 21:01

Key Takeaways Case Summary This case from May 2024 started with a malicious download from a website mimicking the teleconferencing application Zoom. When visiting the website and downloading a file that seems intended for installing Zoom, the user was, in fact, installing a malicious program created with Inno Setup. The malicious program was a d3f@ck […]

The post Fake Zoom Ends in BlackSuit Ransomware appeared first on The DFIR Report.

❌
❌