<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1029833275466591797</id><updated>2021-11-17T12:12:25.489-05:00</updated><category term="vulnerabilities"/><category term="Malware"/><category term="Talos"/><category term="vulnerability spotlight"/><category term="Snort"/><category term="Threat Roundup"/><category term="Rules"/><category term="Threat Source newsletter"/><category term="Threat Research"/><category term="Coverage"/><category term="Microsoft"/><category term="Vulnerability Research"/><category term="Features"/><category term="SecureX"/><category term="AMP"/><category term="beers with talos"/><category term="Microsoft Patch Tuesday"/><category term="CVE"/><category term="zero-day"/><category term="Umbrella"/><category term="Vulnerability"/><category term="threats"/><category term="podcast"/><category term="Cisco Talos"/><category term="ransomware"/><category term="Snort Rules"/><category term="ThreatGrid"/><category term="podcasts"/><category term="Adobe"/><category term="ClamAV"/><category term="Headlines"/><category term="Emotet"/><category term="Talos Threat Source"/><category term="cyber news"/><category term="java"/><category term="news"/><category term="vulnerability analysis"/><category term="Malware Analysis"/><category term="patch tuesday"/><category term="ActiveX"/><category term="Android"/><category term="spam"/><category term="Talos Takes"/><category term="Dridex"/><category term="APT"/><category term="Security"/><category term="Vulnerability Report"/><category term="cerber"/><category term="threat spotlight"/><category term="tofsee"/><category term="Apache"/><category term="Cyber Security Week in Review"/><category term="exploit kits"/><category term="Razy"/><category term="RAT"/><category term="Threat Source"/><category term="remote code execution"/><category term="apple"/><category term="IoT"/><category term="security news"/><category term="Gh0stRAT"/><category term="news roundup"/><category term="trickbot"/><category term="trojan"/><category term="DarkComet"/><category term="election security"/><category term="remcos"/><category term="reverse engineering"/><category term="COVID-19"/><category term="beers with talos podcast"/><category term="ms tuesday"/><category term="Vulnerability Discovery"/><category term="ZBot"/><category term="bugs"/><category term="njRat"/><category term="vulndev"/><category term="vuln dev"/><category term="vulnerability advisories"/><category term="DNS"/><category term="Lokibot"/><category term="analyst work"/><category term="incident response"/><category term="nymaim"/><category term="Kovter"/><category term="Windows"/><category term="Zeroaccess"/><category term="cryptocurrency"/><category term="patch"/><category term="Netwire"/><category term="VRT"/><category term="banking trojan"/><category term="newsletter"/><category term="upatre"/><category term="BWT"/><category term="Cisco Talos Incident Response"/><category term="Malware Research"/><category term="Office"/><category term="Talos Incident Response"/><category term="Zusy"/><category term="exploitation"/><category term="ICS"/><category term="Kuluoz"/><category term="CSWR"/><category term="DoJoSec"/><category term="IOCs"/><category term="Talos Threat Research Summit"/><category term="botnet"/><category term="detection"/><category term="qakbot"/><category term="ursnif"/><category term="Defcon"/><category term="Exploit"/><category term="Korea"/><category term="MalDoc"/><category term="VPNFilter"/><category term="Zegost"/><category term="cisco"/><category term="conferences"/><category term="phishing"/><category term="Bifrost"/><category term="Facebook"/><category term="HawkEye"/><category term="SCADA"/><category term="TeslaCrypt"/><category term="Threat Advisory"/><category term="Xpiro"/><category term="angler"/><category term="cryptomining"/><category term="google"/><category term="malvertising"/><category term="python"/><category term="research"/><category term="threat"/><category term="Adobe Acrobat"/><category term="Chthonic"/><category term="Exploiting"/><category term="Fareit"/><category term="IDA Pro"/><category term="Internet Explorer"/><category term="Linux"/><category term="Powershell"/><category term="SO Rules"/><category term="announcements"/><category term="cryptominers"/><category term="denial of service"/><category term="email"/><category term="threat intelligence"/><category term="vulnerabillity"/><category term="Accusoft"/><category term="Google Chrome"/><category term="RDP"/><category term="Razorback"/><category term="dga"/><category term="gandcrab"/><category term="iOS"/><category term="javascript"/><category term="windbg"/><category term="worm"/><category term="Acrobat"/><category term="Cisco Security"/><category term="Cryptowall"/><category term="Excel"/><category term="Firefox"/><category term="Flash"/><category term="Gamarue"/><category term="Locky"/><category term="Oracle"/><category term="Phorpiex"/><category term="Ramnit"/><category term="SSL"/><category term="Whitepaper"/><category term="awbo"/><category term="dcerpc"/><category term="latest threats"/><category term="monero"/><category term="news recap"/><category term="remote access tool"/><category term="AMD"/><category term="APTs"/><category term="Adobe Flash"/><category term="Autoit"/><category term="Barys"/><category term="Black Hat"/><category term="Buffer Overflow"/><category term="Byakugan"/><category term="Cisco Live"/><category term="Coinminer"/><category term="DoS"/><category term="Edge"/><category term="Expiro"/><category term="Foxit"/><category term="HWP"/><category term="IR"/><category term="RATs"/><category term="ROKRAT"/><category term="RSA"/><category term="RSA Conference"/><category term="Sea Turtle"/><category term="TinyBanker"/><category term="VMware"/><category term="Webkit"/><category term="Word"/><category term="antivirus"/><category term="iPhone"/><category term="malspam"/><category term="microsoft Office"/><category term="miners"/><category term="mobile"/><category term="patches"/><category term="reversing"/><category term="sextortion"/><category term="signatures"/><category term="spyware"/><category term="stealer"/><category term="vobfus"/><category term="zeus"/><category term="Banload"/><category term="Black Friday"/><category term="Brazil"/><category term="Bublik"/><category term="CTIR"/><category term="Cyber Monday"/><category term="DNS redirection"/><category term="Glupteba"/><category term="India"/><category term="MDM"/><category term="MS08-067"/><category term="Mac"/><category term="Middle East"/><category term="Necurs"/><category term="OSX"/><category term="PDF"/><category term="PLC"/><category term="Ponystealer"/><category term="Ruskill"/><category term="Sagent"/><category term="Snort Rule Options"/><category term="Talos tools"/><category term="Tor"/><category term="Ursu"/><category term="VBScript"/><category term="adware"/><category term="agenttesla"/><category term="arbitrary code execution"/><category term="bitcoin"/><category term="chrome"/><category term="credential stealer"/><category term="crimeware"/><category term="dns hijacking"/><category term="election"/><category term="exfiltration"/><category term="extortion"/><category term="fake news"/><category term="keylogger"/><category term="nvidia"/><category term="obfuscation"/><category term="rocket pig"/><category term="samsam"/><category term="security updates"/><category term="supply-chain attacks"/><category term="sweed"/><category term="talos podcast"/><category term="videos"/><category term=".NET"/><category term="AZORult"/><category term="Advanced Malware Protection"/><category term="Antenna House"/><category term="Automation"/><category term="Brushaloader"/><category term="CVE-2017-0199"/><category term="Citrix"/><category term="Click-fraud"/><category term="Cobalt Strike"/><category term="CobaltStrike"/><category term="Conficker"/><category term="Cybergate"/><category term="Dealply"/><category term="Disclosure"/><category term="Generickdz"/><category term="GlitchPOS"/><category term="Hangul"/><category term="Huawei"/><category term="Jobs"/><category term="KONNI"/><category term="MFA"/><category term="Mattland"/><category term="Metasploit"/><category term="Microsoft Media Foundation"/><category term="Mikey"/><category term="Moxa"/><category term="Nanocore"/><category term="Nuclear EK"/><category term="Nyetya"/><category term="ObliqueRAT"/><category term="Olympics"/><category term="OpenOffice"/><category term="POS"/><category term="Phish"/><category term="Rockwell Automation"/><category term="Safari"/><category term="Shiz"/><category term="Stories from the Field"/><category term="Talos GitHub"/><category term="Threat Actor"/><category term="Threat Research Summit"/><category term="XtremeRAT"/><category term="advisory"/><category term="backdoor"/><category term="campaign"/><category term="ciso advisory"/><category term="command injection"/><category term="cryptography"/><category term="cybercrime"/><category term="deep dive"/><category term="disinformation"/><category term="esa"/><category term="formbook"/><category term="gozi"/><category term="hacking"/><category term="infostealer"/><category term="intel"/><category term="kaspersky"/><category term="kernel mode"/><category term="malicious documents"/><category term="malware recap"/><category term="ntpd"/><category term="opsec"/><category term="plugin"/><category term="presentations"/><category term="qbot"/><category term="research spotlight"/><category term="rtf"/><category term="scam"/><category term="script"/><category term="social engineering"/><category term="spear phishing"/><category term="spotlight"/><category term="stealers"/><category term="telegram"/><category term="threat intel tools"/><category term="trojans"/><category term="video"/><category term="vuln spotlight"/><category term="web reputation"/><category term="word doc"/><category term="3dprinting"/><category term="7-Zip"/><category term="AMD Radeon"/><category term="APT28"/><category term="Adobe Reader"/><category term="Amish Hammers"/><category term="Anomaly Detection"/><category term="Aspose"/><category term="Attack"/><category term="Azerbajian"/><category term="BASS"/><category term="BazarLoader"/><category term="Blackshades"/><category term="Bunitu"/><category term="C2"/><category term="CCleaner"/><category term="CTA"/><category term="CVE-2014-6271"/><category term="CVE-2016-4329"/><category term="CWS"/><category term="China"/><category term="CleanMyMac"/><category term="Cujo"/><category term="DNSpionage"/><category term="Decryptor"/><category term="Divergent"/><category term="Dropper"/><category term="Elasticsearch"/><category term="Epignosis"/><category term="ExileRAT"/><category term="FIRST"/><category term="FTP"/><category term="Flash Player"/><category term="Foscam"/><category term="Foxit PDF Reader"/><category term="Framework"/><category term="Frankenstein"/><category term="Frankenstein malware"/><category term="Fun"/><category term="Fuzzing"/><category term="GOG Galaxy"/><category term="Gootkit"/><category term="Group123"/><category term="IDA"/><category term="IDA Pro plugin"/><category term="IE"/><category term="IIS"/><category term="ImageGear"/><category term="Incident Response trends"/><category term="Internet of Things"/><category term="Iran"/><category term="Italy"/><category term="JBoss"/><category term="JPEG 2000"/><category term="JasperLoader"/><category term="Johnnie"/><category term="Kaseya"/><category term="LEADTOOLS"/><category term="Living off the land"/><category term="LodaRAT"/><category term="LuckyCat"/><category term="MS08-078"/><category term="MS09-002"/><category term="Magic"/><category term="Matt Watchinski"/><category term="Microsoft Azure"/><category term="Microsoft Excel"/><category term="Microsoft Media Foundations"/><category term="NCSAM"/><category term="NETGEAR"/><category term="Neural Network"/><category term="Nitro"/><category term="NitroPDF"/><category term="NoSQL"/><category term="OMRON FINS"/><category term="Olympic Destroyer"/><category term="Operation SMN"/><category term="PDF reader"/><category term="PE-Sig"/><category term="Pidgin"/><category term="Pixar Renderman"/><category term="PoetRAT"/><category term="Portcullis"/><category term="Powerpoint"/><category term="Quarterly trends"/><category term="RIG"/><category term="Rainbow PDF"/><category term="Ranscam"/><category term="Reader"/><category term="Reconnaissance"/><category term="Redline"/><category term="Ryuk"/><category term="SMN"/><category term="Scar"/><category term="Schneider Electric"/><category term="Shade"/><category term="SharePoint"/><category term="Sload"/><category term="Snort.org"/><category term="Socks"/><category term="Sodinokibi"/><category term="SpamCop"/><category term="Swisyn"/><category term="TIFF"/><category term="TLS"/><category term="TTRS"/><category term="Talos Email Status Portal"/><category term="Talos IR"/><category term="Talos Intelligence"/><category term="Tortoiseshell"/><category term="Ubuntu"/><category term="Use-After-Free"/><category term="VBA"/><category term="VBA macros"/><category term="VMware Workstation"/><category term="VPNFilter malware"/><category term="Valyria"/><category term="Vendor Response"/><category term="VirusBulletin"/><category term="Vulnerability Disclosure Timeline"/><category term="WAGO"/><category term="Watchbog"/><category term="WebDAV"/><category term="Weblogic"/><category term="Windows 10"/><category term="Windows 7"/><category term="XLS"/><category term="Year in Malware"/><category term="Year in Review 2018"/><category term="Year in Review 2019"/><category term="Year in Review 2020"/><category term="awesome"/><category term="banker"/><category term="bash"/><category term="bec"/><category term="big-game hunting"/><category term="blockchain"/><category term="bots"/><category term="broswer exploitation"/><category term="camera"/><category term="categories"/><category term="cloud"/><category term="cnc"/><category term="coTURN"/><category term="conference registration"/><category term="controllers"/><category term="cyber insurance"/><category term="cybersecurity"/><category term="data science"/><category term="defense"/><category term="development"/><category term="dnsmessenger"/><category term="domain shadowing"/><category term="events"/><category term="exploits"/><category term="gplayed"/><category term="gustuff"/><category term="holiday"/><category term="holiday shopping"/><category term="iceni"/><category term="information disclosure"/><category term="information stealers"/><category term="kyle"/><category term="kyle and stan"/><category term="labview"/><category term="loader"/><category term="machine learning"/><category term="macros"/><category term="malicious activity"/><category term="malicious advertisment"/><category term="malware loader"/><category term="meraki"/><category term="methodology"/><category term="mimikatz"/><category term="mining"/><category term="mitigations"/><category term="mobile device management"/><category term="mobile espionage"/><category term="national instruments"/><category term="natus"/><category term="network scanner"/><category term="passwords"/><category term="patching"/><category term="pony"/><category term="prior coverage"/><category term="privacy"/><category term="privilege escalation"/><category term="proof-of-concept"/><category term="pyrebox"/><category term="rc4"/><category term="research papers"/><category term="retrospective"/><category term="scams"/><category term="shell shock"/><category term="stan"/><category term="state actors"/><category term="state-sponsored actors"/><category term="sundown"/><category term="talks"/><category term="talosintelligence.com"/><category term="taxes"/><category term="tools"/><category term="tp-link"/><category term="tplink"/><category term="upgrade"/><category term="virtual machines"/><category term="virus"/><category term="vulnerable routers"/><category term="webshell"/><category term="whatsapp"/><category term="wiper"/><category term="wireless routers"/><category term="working from home"/><category term="wsa"/><category term="zepto"/><category term="#SAVETHEINTERWEBZ"/><category term="2009"/><category term="3MF"/><category term="4CAN"/><category term="7ev3n"/><category term="ACD Systems"/><category term="ACDSee"/><category term="AI"/><category term="AMD ATI"/><category term="ARJ"/><category term="ASA"/><category term="ASIG"/><category term="ASUS"/><category term="AT&amp;T"/><category term="ATM malware"/><category term="Able2Extract"/><category term="Active Directory"/><category term="Advantech"/><category term="Adylkuzz"/><category term="Aerospike"/><category term="Aggah"/><category term="Allen-Bradley"/><category term="AlphaCrypt"/><category term="Amazon"/><category term="Anker"/><category term="Ansible"/><category term="AntennaHouse"/><category term="Apple bug"/><category term="Apple bugs"/><category term="Apple security update"/><category term="Apple update"/><category term="Arabic"/><category term="Arkei"/><category term="Aspis"/><category term="Aspose.PDF"/><category term="Aspxor"/><category term="Astaroth"/><category term="Atlantis"/><category term="Atlantis Word Processor"/><category term="Atlassian"/><category term="Atlassian Jira"/><category term="Attribution"/><category term="Australia"/><category term="BGP"/><category term="BLUE TEAM VILLAGE"/><category term="BRKSEC-2010"/><category term="Bahamut"/><category term="Bedep"/><category term="Beta site"/><category term="Bitdefender"/><category term="Bitdefender BOX"/><category term="Bitvote"/><category term="Black Hat 2019"/><category term="BlackWater"/><category term="Blacklisting"/><category term="Blandabindi"/><category term="Blue Team"/><category term="BlueKeep"/><category term="BlueStacks"/><category term="Blynk"/><category term="Boss-Hates-Me"/><category term="Brad Arkin"/><category term="Buffers"/><category term="Busy"/><category term="CANbus"/><category term="CASC"/><category term="CERT"/><category term="CRAT"/><category term="CSV"/><category term="CTB-Locker"/><category term="CTF"/><category term="CUPS"/><category term="CVE-2008-5457"/><category term="CVE-2008-5911"/><category term="CVE-2009-0045"/><category term="CVE-2009-0520"/><category term="CVE-2010-1885"/><category term="CVE-2012-0003"/><category term="CVE-2012-0158"/><category term="CVE-2012-4969"/><category term="CVE-2014-3566"/><category term="CVE-2014-4115"/><category term="CVE-2016-1547"/><category term="CVE-2016-1548"/><category term="CVE-2016-1549"/><category term="CVE-2016-1550"/><category term="CVE-2016-1551"/><category term="CVE-2016-1681"/><category term="CVE-2016-2347"/><category term="CVE-2016-3369"/><category term="CVE-2016-4304"/><category term="CVE-2016-4305"/><category term="CVE-2016-4306"/><category term="CVE-2016-4307"/><category term="CVE-2016-8332"/><category term="CVE-2016-8610"/><category term="CVE-2016-8732"/><category term="CVE-2016-9038"/><category term="CVE-2017-12106"/><category term="CVE-2017-12607"/><category term="CVE-2017-12608"/><category term="CVE-2017-2775"/><category term="CVE-2017-2779"/><category term="CVE-2017-2802"/><category term="CVE-2017-2806"/><category term="CVE-2017-2809"/><category term="CVE-2017-2810"/><category term="CVE-2017-2817"/><category term="CVE-2017-2819"/><category term="CVE-2017-2823"/><category term="CVE-2017-2834"/><category term="CVE-2017-2835"/><category term="CVE-2017-2836"/><category term="CVE-2017-2837"/><category term="CVE-2017-2838"/><category term="CVE-2017-2839"/><category term="CVE-2017-2862"/><category term="CVE-2017-2870"/><category term="CVE-2017-2880"/><category term="CVE-2017-2891"/><category term="CVE-2017-2892"/><category term="CVE-2017-2893"/><category term="CVE-2017-2894"/><category term="CVE-2017-2895"/><category term="CVE-2017-2909"/><category term="CVE-2017-2920"/><category term="CVE-2017-2921"/><category term="CVE-2017-2922"/><category term="CVE-2017-2923"/><category term="CVE-2017-2924"/><category term="CVE-2017-5638"/><category term="CVE-2017-9806"/><category term="CVE-2018-3857"/><category term="CVE-2018-3858"/><category term="CVE-2018-3859"/><category term="CVE-2018-3860"/><category term="CVE-2018-3870"/><category term="CVE-2018-3871"/><category term="CVE-2018-8506"/><category term="CVE-2018-8653"/><category term="CVE-2019-5063"/><category term="CVE-2019-5064"/><category term="CVE-2020-1472"/><category term="Canvas Draw 5"/><category term="Cesanta"/><category term="China Chopper"/><category term="Circle with Disney"/><category term="Cisco Incident Response"/><category term="Clipboard trojan"/><category term="Clustering"/><category term="Cobalt group"/><category term="Conti"/><category term="CopperStealer"/><category term="Corel"/><category term="Covenant"/><category term="CrimsonRAT"/><category term="Cryptbot"/><category term="CyberVets"/><category term="Cyberwar"/><category term="DDE"/><category term="DDNS"/><category term="DDoS"/><category term="DDoS-as-a-Service"/><category term="DEFCON 2019"/><category term="DEFCON 27"/><category term="DEFCON BADGE"/><category term="DEP"/><category term="DIGISPARK"/><category term="DOC"/><category term="Danabot"/><category term="DarkComet HawkEye"/><category term="Decept Proxy"/><category term="DejaBlue"/><category term="Dial-up"/><category term="DiamondFox"/><category term="DoJoCon"/><category term="Docker"/><category term="Donot"/><category term="DoppelPaymer"/><category term="Drupal"/><category term="Duo"/><category term="E2f"/><category term="E2fsprogs"/><category term="EITest"/><category term="ELECTRONIC BADGE"/><category term="Education"/><category term="EmbedThis"/><category term="Equation"/><category term="Equifax"/><category term="Esfury"/><category term="EternalBlue"/><category term="EternalRocks"/><category term="Ethernet/IP"/><category term="Evasions"/><category term="Event Mapping"/><category term="Exhibitor Web UI"/><category term="EyePyramid"/><category term="FBI"/><category term="FIN7"/><category term="FNC"/><category term="FTC"/><category term="FTR"/><category term="FaceApp"/><category term="Fat32"/><category term="FickerStealer"/><category term="Firepower"/><category term="Forma"/><category term="Forma LMS"/><category term="FreeImage"/><category term="FreeXLS"/><category term="Functional Not Elegant"/><category term="GBDT"/><category term="GDI+"/><category term="GDK"/><category term="GOG Galaxy Games"/><category term="GRIZZLY STEPPE"/><category term="GStreamer"/><category term="Garage Band"/><category term="Genkryptik"/><category term="Ghidra"/><category term="GitLab"/><category term="Gmail"/><category term="GoScanSSH"/><category term="Google V8"/><category term="Graftor"/><category term="GravityRAT"/><category term="Green Curtain"/><category term="Group 72"/><category term="Group 93"/><category term="Gumblar"/><category term="H2H"/><category term="HAFNIUM"/><category term="HDF5"/><category term="Hancom"/><category term="Heaven&#39;s Gate"/><category term="Honeygain"/><category term="Hopper"/><category term="Howard County"/><category term="Hupigon"/><category term="Hyland"/><category term="IDAPython"/><category term="IEC 104"/><category term="IMAP"/><category term="IPv6"/><category term="IR training"/><category term="IRC"/><category term="ISO"/><category term="ISO image"/><category term="IT"/><category term="IceHRM"/><category term="IcedID"/><category term="Impress"/><category term="Innovation"/><category term="Intel Raid Web Console 3"/><category term="Intel graphics driver"/><category term="Internet of Everything"/><category term="Investintech"/><category term="Iraq"/><category term="JScript"/><category term="Jaff"/><category term="Jenkins"/><category term="JhoneRAT"/><category term="Jira"/><category term="KCodes"/><category term="KVM"/><category term="Kakadu"/><category term="Kakadu Software"/><category term="Kashmir"/><category term="KevDroid"/><category term="LSASS"/><category term="Lantronix"/><category term="Lebanon"/><category term="LibTIFF"/><category term="LibreOffice"/><category term="Linksys"/><category term="Liz Centoni"/><category term="LoLBins"/><category term="LockBit"/><category term="LockerGoga"/><category term="MIDI"/><category term="MS03-039"/><category term="MS08-068"/><category term="MS09-001"/><category term="MS09-003"/><category term="MS09-004"/><category term="MS09-005"/><category term="MS09-006"/><category term="MS09-008"/><category term="MS09-009"/><category term="MS09-010"/><category term="MS09-011"/><category term="MS09-012"/><category term="MS09-013"/><category term="MS09-014"/><category term="MS09-015"/><category term="MS09-016"/><category term="MS09-017"/><category term="MS09-018"/><category term="MS09-019"/><category term="MS09-020"/><category term="MS09-021"/><category term="MS09-022"/><category term="MS09-023"/><category term="MS09-024"/><category term="MS09-027"/><category term="MS09-028"/><category term="MS09-029"/><category term="MS09-030"/><category term="MS09-031"/><category term="MS09-032"/><category term="MS09-034"/><category term="MS09-036"/><category term="MS09-037"/><category term="MS09-038"/><category term="MS09-039"/><category term="MS09-041"/><category term="MS09-042"/><category term="MS09-043"/><category term="MS09-044"/><category term="MS09-045"/><category term="MS09-046"/><category term="MS09-047"/><category term="MS09-048"/><category term="MS12-004"/><category term="MS14-063"/><category term="MS17-010"/><category term="MSBuild"/><category term="Macpaw"/><category term="Magic Hound"/><category term="Malicious Office Document"/><category term="Marketing"/><category term="Maryland"/><category term="Masslogger"/><category term="Matroska"/><category term="Matryoshka"/><category term="McAfee"/><category term="MedusaLocker"/><category term="Memcached"/><category term="Meterpreter"/><category term="Microsof Windows"/><category term="Microsoft Exchange"/><category term="Mini-SNMPD"/><category term="MiniUPnP"/><category term="Mirai"/><category term="Modbus"/><category term="Mongoose"/><category term="Moxa AWK-3131A"/><category term="MuPDF"/><category term="MuddyWater"/><category term="Mussels"/><category term="Mutiny Fuzzing Framework"/><category term="NATO"/><category term="NIST"/><category term="NSA"/><category term="NX-OS"/><category term="NZXT"/><category term="NavRAT"/><category term="Necro"/><category term="Nemty"/><category term="Neshta"/><category term="Nessun dorma"/><category term="Nest"/><category term="NetUSB"/><category term="Netgate"/><category term="Netlogon"/><category term="Neurevt"/><category term="Nibiru"/><category term="NordVPN"/><category term="North Korea"/><category term="NotPetya"/><category term="Novatek"/><category term="O:DTLWWOT"/><category term="ODT"/><category term="OFX"/><category term="OS X"/><category term="OT"/><category term="OfficeCat"/><category term="Olney&#39;s Horrible DB"/><category term="Open Financial Exchange"/><category term="OpenClinic"/><category term="OpenSIS"/><category term="OpenSSH"/><category term="Opera"/><category term="Orcus"/><category term="Osiris"/><category term="PCAPs"/><category term="PCX"/><category term="PDFs"/><category term="PLC controllers"/><category term="PNGs"/><category term="POODLE"/><category term="PTEX"/><category term="PUP"/><category term="Pakistan"/><category term="Palestine"/><category term="Passwordstealera"/><category term="Perl"/><category term="Petya"/><category term="Phorphiex"/><category term="PhotoLine"/><category term="Piotr Bania"/><category term="Pirate Bay"/><category term="Pixar"/><category term="Pixbuf"/><category term="PoE"/><category term="PoisonIvy"/><category term="Pop-up"/><category term="PowerISO"/><category term="PrintNightmare"/><category term="Project Zero"/><category term="ProntoVPN"/><category term="PubNub"/><category term="PubNubRAT"/><category term="Pyeongchang"/><category term="QQ"/><category term="Qatar"/><category term="Qjwmonkey"/><category term="QuickTime"/><category term="RDP8"/><category term="RE2PCAP"/><category term="ROP"/><category term="ROPMEMU"/><category term="RaaS"/><category term="Radeon"/><category term="Rawbytes"/><category term="Redis"/><category term="Regin"/><category term="Remote Desktop Protocol"/><category term="Renderman"/><category term="RevengeRAT"/><category term="ReversingLabs"/><category term="Rocke"/><category term="Rombertik"/><category term="Russia"/><category term="SANS"/><category term="SCBL"/><category term="SDL"/><category term="SMB DoS"/><category term="SMB Malware Energy"/><category term="SMBGhost"/><category term="SMBv1"/><category term="SMBv2"/><category term="SNMP"/><category term="SOLAT IN THE SWEN"/><category term="SQLite"/><category term="SSHPsychos"/><category term="Scareware"/><category term="Scarlett Widow"/><category term="Schneider"/><category term="Scriptlets"/><category term="SeaTurtle"/><category term="Secure-X"/><category term="SecureX&#xa;TrickBot"/><category term="Shadow Brokers"/><category term="ShadowHammer"/><category term="Shimo VPN"/><category term="SideCopy"/><category term="Sierra"/><category term="Sierra Wireless"/><category term="Silent Trinity"/><category term="Simple DirectMedia Layer"/><category term="SimpleDirect Media Layer"/><category term="Singapore"/><category term="Slack"/><category term="Slic3r"/><category term="Smoke Loader"/><category term="SmokeLoader"/><category term="Snort 3"/><category term="Snort User Groups"/><category term="SoftMaker"/><category term="Sony"/><category term="Soothsaying"/><category term="South Korea"/><category term="Spelevo"/><category term="Spoof"/><category term="Stack Group OpENer"/><category term="SubSeven"/><category term="Swarm"/><category term="Symantec"/><category term="Synology"/><category term="TA505"/><category term="TALOS-2016-0193"/><category term="TALOS-2017-0273"/><category term="TALOS-2017-0507"/><category term="TALOS-2018-0643"/><category term="TALOS-2019-0852"/><category term="TALOS-2019-0853"/><category term="TDoS"/><category term="THC"/><category term="TLD"/><category term="Talos IR Cyber Range"/><category term="Talos Web Reputation"/><category term="Talos conferences"/><category term="Tarantool"/><category term="TeamViewer"/><category term="Tenda"/><category term="Tetrane"/><category term="Thanatos"/><category term="ThanatosDecryptor"/><category term="Threat Assessment Report"/><category term="Threat report"/><category term="Ticketbleed"/><category term="TikTok"/><category term="TileGX"/><category term="TinyPOS"/><category term="Total Commander"/><category term="Tovkater"/><category term="Trane"/><category term="Translation"/><category term="Trojan.Rincux"/><category term="Truffle"/><category term="Trump"/><category term="Turla"/><category term="UAE"/><category term="UPnP"/><category term="URLs"/><category term="USB"/><category term="Uiwix"/><category term="Updating software"/><category term="V8"/><category term="VE-2017-12107"/><category term="VFEmail"/><category term="VI file"/><category term="VMI"/><category term="VPN"/><category term="Valak"/><category term="Videolabs"/><category term="Virut"/><category term="Vivin"/><category term="W1fi"/><category term="WAGO PFC"/><category term="WAGO PFC200"/><category term="WFH"/><category term="Wacom"/><category term="Wacom Update Helper"/><category term="WannaCry"/><category term="WastedLocker"/><category term="We&#39;re all going to die"/><category term="White Paper"/><category term="Whitefly"/><category term="WinPot"/><category term="Windows 10 kernel"/><category term="Windows Media Player"/><category term="Windows XP"/><category term="Windows kernel"/><category term="WindowsCodecs.dll"/><category term="Winwebsec"/><category term="Wordpress"/><category term="XML"/><category term="XMP"/><category term="XSS"/><category term="Xcftools"/><category term="Xcnfe"/><category term="XpertRAT"/><category term="Yi Technology"/><category term="YouPHPTube"/><category term="YouTube"/><category term="ZTE"/><category term="Zoom"/><category term="Zyklon"/><category term="advertisement"/><category term="adwind"/><category term="ahcache.sys"/><category term="anniversary"/><category term="anonpop"/><category term="ansible vault"/><category term="anti-analysis"/><category term="anti-sandbox"/><category term="anti-spam"/><category term="antimalware"/><category term="arduino"/><category term="argus"/><category term="artificial intelligence"/><category term="ask the VRT"/><category term="aslr bypass"/><category term="asyncRAT"/><category term="attachments"/><category term="audio"/><category term="authencation"/><category term="awards"/><category term="badrabbit"/><category term="binaries"/><category term="breaking news"/><category term="business email compromise"/><category term="capture the flag"/><category term="car hacking"/><category term="carding"/><category term="cars"/><category term="cheap domains"/><category term="code injection"/><category term="code re-use"/><category term="coinhive"/><category term="config extractor"/><category term="credit card"/><category term="critical infrastructure"/><category term="cryptocurrency mining."/><category term="cryptolocker"/><category term="cve-2016-2334"/><category term="cve-2016-4303"/><category term="cve-2016-7193"/><category term="cve-2017-11882"/><category term="cve-2017-9244"/><category term="cve-2019-19781"/><category term="cyber attack"/><category term="cyber attacks"/><category term="cyber range"/><category term="cyber security"/><category term="cyber security insurance"/><category term="cybershockwave"/><category term="cyrptomining"/><category term="dark cloud"/><category term="decision trees"/><category term="deep learning"/><category term="dell"/><category term="delphi"/><category term="dependency"/><category term="dhclient"/><category term="discount domains"/><category term="discovery"/><category term="dispute"/><category term="dnssnarf"/><category term="docs"/><category term="documentation"/><category term="dsniff"/><category term="dumbpig"/><category term="dynamic DNS"/><category term="dyre"/><category term="e-learning"/><category term="eFront"/><category term="ePO"/><category term="edbitss"/><category term="engineering"/><category term="esnet"/><category term="espionage"/><category term="false news"/><category term="fast flux"/><category term="file2pcap"/><category term="filleless"/><category term="financial"/><category term="fingerprint"/><category term="firestarter"/><category term="fix"/><category term="floki bot"/><category term="flowbits"/><category term="four way handshake"/><category term="fraud"/><category term="freakshow"/><category term="freerdp"/><category term="gTLD"/><category term="gamaredon"/><category term="gamma-ray"/><category term="gate"/><category term="geopolitics"/><category term="governance"/><category term="governments"/><category term="goznym"/><category term="group 74"/><category term="hacking back"/><category term="hailstorm"/><category term="hardware"/><category term="hardware hacking"/><category term="healthcare"/><category term="heartbleed"/><category term="hijack"/><category term="hiring"/><category term="holidays"/><category term="honeypots"/><category term="http_inspect"/><category term="iTunes"/><category term="immunet"/><category term="immunity"/><category term="in the wild"/><category term="incident response training"/><category term="inesap"/><category term="infrastructure"/><category term="instagram"/><category term="insurance"/><category term="intelligence"/><category term="introduction"/><category term="invincea"/><category term="iot malware"/><category term="isfb"/><category term="jRAT"/><category term="jailbreak"/><category term="jigsaw"/><category term="jnlp"/><category term="json"/><category term="karkoff"/><category term="kimsuky"/><category term="labs"/><category term="law"/><category term="lemon duck"/><category term="lexmark"/><category term="libarchive"/><category term="local code execution"/><category term="lua"/><category term="macOS"/><category term="malicious actor"/><category term="malicious email"/><category term="malware roundup"/><category term="matrixssl"/><category term="md5"/><category term="meltdown"/><category term="memory corruption"/><category term="mitigating risk"/><category term="moonshot"/><category term="multi-factor authentication"/><category term="neutrino"/><category term="new router malware"/><category term="newsletters"/><category term="notification"/><category term="odin"/><category term="office router attack"/><category term="omg"/><category term="online scams"/><category term="online shopping"/><category term="open source"/><category term="opencv"/><category term="opinion"/><category term="out-of-band"/><category term="packer"/><category term="pandemic"/><category term="password management"/><category term="password stealer"/><category term="pen testing"/><category term="penetration testing"/><category term="pentesting"/><category term="pfSense"/><category term="physics"/><category term="planning"/><category term="plugins"/><category term="point of sale malware"/><category term="politics"/><category term="polymorphic"/><category term="prediction"/><category term="predictions"/><category term="preprocessor"/><category term="preprocessor options"/><category term="privateer"/><category term="proxyware"/><category term="publisher"/><category term="pulled pork"/><category term="py2exe"/><category term="ranswomare"/><category term="releases"/><category term="reputation disputes"/><category term="response"/><category term="reven"/><category term="risk"/><category term="risk management"/><category term="rogye antivirus"/><category term="rootkit"/><category term="rsplug"/><category term="ruby"/><category term="ryptoShuffler"/><category term="samba"/><category term="samsung"/><category term="sandbox"/><category term="secure instant messaging"/><category term="security architecture"/><category term="security insurance"/><category term="sennoma"/><category term="separ"/><category term="server"/><category term="shared object rules"/><category term="shopping"/><category term="signal"/><category term="sinkholing"/><category term="smartthings"/><category term="snowshoe"/><category term="social media"/><category term="sophos"/><category term="spacetime"/><category term="speakers"/><category term="spectre"/><category term="spyeye"/><category term="ssh"/><category term="stalkerware"/><category term="stance detection"/><category term="state-related"/><category term="stbl"/><category term="steam"/><category term="stimulus"/><category term="strcpy"/><category term="streaming"/><category term="struts"/><category term="support"/><category term="synful"/><category term="tablib"/><category term="tcp/ip"/><category term="telegrab"/><category term="threat levels"/><category term="threat traps"/><category term="threats."/><category term="toknowall.com"/><category term="top threats"/><category term="torrents"/><category term="tuning"/><category term="twitter"/><category term="typosquat"/><category term="unpacker"/><category term="unwanted software"/><category term="vawtrak"/><category term="vehicle vulnerabilities"/><category term="visibility"/><category term="volatility"/><category term="vpn filter attack"/><category term="web categories"/><category term="web services"/><category term="whois"/><category term="wibu"/><category term="winamp"/><category term="wipers"/><category term="wireshark"/><category term="working remote"/><category term="workshop"/><category term="wormholes"/><category term="wubikey"/><category term="xamarin"/><category term="yaml"/><category term="zero-trust"/><category term="zeus panda"/><title type='text'>Cisco Talos Intelligence Group - Comprehensive Threat Intelligence</title><subtitle type='html'>Talos Group, by Cisco</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.talosintelligence.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default?max-results=5&amp;redirect=false'/><link rel='alternate' type='text/html' href='http://blog.talosintelligence.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default?start-index=6&amp;max-results=5&amp;redirect=false'/><author><name>Nick Biasini</name><uri>http://www.blogger.com/profile/11420644688145888259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='//4.bp.blogspot.com/-UW8oaWU9JdA/VhfNw5b7TyI/AAAAAAAAAto/_NpPpmwiNQ8/s113/HiRes-Nicholas_Biasini-5305-Edit.jpeg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1788</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>5</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-4443717675169030276</id><published>2021-11-17T09:26:00.004-05:00</published><updated>2021-11-17T10:52:13.645-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Black Friday"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Monday"/><category scheme="http://www.blogger.com/atom/ns#" term="Features"/><title type='text'>Talos’ tips for staying safe while shopping online this holiday season </title><content type='html'>&lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://lh3.googleusercontent.com/-sazDyDesP8M/YZUPeHaWxtI/AAAAAAAAAek/cG_SwD1gYb022EJTYQw4-483_tuEak52wCNcBGAsYHQ/112420%2Bonline%2Bshopping%2Bscams.png&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img data-original-height=&quot;1000&quot; data-original-width=&quot;2000&quot; src=&quot;https://lh3.googleusercontent.com/-sazDyDesP8M/YZUPeHaWxtI/AAAAAAAAAek/cG_SwD1gYb022EJTYQw4-483_tuEak52wCNcBGAsYHQ/s16000/112420%2Bonline%2Bshopping%2Bscams.png&quot; /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;i&gt;&lt;br /&gt;&lt;br /&gt;&lt;/i&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;By Jon Munshaw.&amp;nbsp;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;Attackers will resort to all tactics to trick users into downloading malware, handing over credit card data or completing compromising their machine.&amp;nbsp;&lt;/p&gt;&lt;p&gt;No topic is off-limits, and threat actors have resorted to using everything from &lt;a href=&quot;https://blog.talosintelligence.com/2021/06/business-email-compromise.html&quot; target=&quot;_blank&quot;&gt;PlayStation 5 sales&lt;/a&gt;, to &lt;a href=&quot;https://open.spotify.com/episode/4CHd9OUzHaENXRFTCW9ph1?si=bE6HwTNdTmeUBtmJhW0zKw&quot; target=&quot;_blank&quot;&gt;COVID-19 cures&lt;/a&gt; and &lt;a href=&quot;https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html&quot; target=&quot;_blank&quot;&gt;news on nuclear weapons&lt;/a&gt; as part of their lures over the past year. And these spam attacks will only ramp up over the next month as consumers across the globe shop online for the holidays.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Adobe Insight’s recent &lt;a href=&quot;https://www.adobe.com/marketing/pdf-page.html?pdfTarget=aHR0cHM6Ly9idXNpbmVzcy5hZG9iZS5jb20vY29udGVudC9kYW0vZHgvdXMvZW4vcmVzb3VyY2VzL2RpZ2l0YWwtaW5zaWdodHMvcGRmL2Fkb2JlLWhvbGlkYXktc2hvcHBpbmctcmVwb3J0LTIwMjEucGRm&quot; target=&quot;_blank&quot;&gt;“Holiday Shopping Forecast”&lt;/a&gt; predicts that spending for e-commerce will top $200 billion during the holiday season for the first time ever. The report also specifically warned that there will be supply chain shortages this year due to the pandemic, which is likely to force online shoppers into long virtual queues or push them to shop even earlier than usual. &lt;span&gt;&lt;/span&gt;&lt;/p&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;While consumers always need to be diligent during the holiday season, supply chain issues this year linked to the COVID-19 pandemic could create even greater challenges and inspiring new cyber scams, especially with &lt;a href=&quot;https://www.ign.com/articles/ps5-production-cut-supply-issues&quot; target=&quot;_blank&quot;&gt;popular video game consoles&lt;/a&gt; and &lt;a href=&quot;https://www.pcgamer.com/nvidias-ceo-doesnt-see-an-end-to-the-chip-shortage-anytime-soon/&quot; target=&quot;_blank&quot;&gt;other electronic products in short supply&lt;/a&gt;.&amp;nbsp;&lt;p&gt;&lt;/p&gt;&lt;p&gt;News is likely to move quickly around online shopping scams and cyber attacks starting the week of Thanksgiving, so this should serve as a hub for all of Talos’ advice to stay safe while shopping online this holiday season.&amp;nbsp;&lt;/p&gt;&lt;p&gt;For some quick-and-dirty tips, listen to the Talos Takes episode we recorded last year around this time where we provide a general overview of how to stay safe when shopping online. This is advice that applies any time you are shopping online, not just during the holidays.&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;iframe allow=&quot;autoplay *; encrypted-media *; fullscreen *&quot; frameborder=&quot;0&quot; height=&quot;175&quot; sandbox=&quot;allow-forms allow-popups allow-same-origin allow-scripts allow-storage-access-by-user-activation allow-top-navigation-by-user-activation&quot; src=&quot;https://embed.podcasts.apple.com/us/podcast/talos-takes-ep-1-how-to-avoid-common-holiday-shopping-scams/id1497572268?i=1000464744822&quot; style=&quot;background: transparent; max-width: 660px; overflow: hidden; width: 100%;&quot;&gt;&lt;/iframe&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;We’ll also have a new Talos Takes episode releasing the week of Thanksgiving and Black Friday that covers specific threats shoppers could see this year with additional complications around the supply chain and the pandemic.&lt;/p&gt;&lt;p&gt;In the meantime, you can watch Nick Biasini’s appearance on a local CBS station in North Carolina. The head of Talos Outreach discussed how supply chain shortages are fueling scams this holiday season.&amp;nbsp;&lt;/p&gt;&lt;iframe allow=&quot;autoplay; fullscreen&quot; allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;360&quot; mozallowfullscreen=&quot;&quot; scrolling=&quot;no&quot; src=&quot;https://w3.mp.lura.live/player/prod/v3/anvload.html?key=eyJtIjoiTElOIiwidiI6IjcxNTQzNjUiLCJhbnZhY2siOiI3MFgzNVFiODU1T09VbVZlV2NZYmgwdzlsTjRrMlIxdyIsInNoYXJlTGluayI6Imh0dHBzOi8vd3d3LmNiczE3LmNvbS9uZXdzL2ludmVzdGlnYXRvcnMvc3VwcGx5LWNoYWluLXNob3J0YWdlcy1vcGVuLWEtbmV3LXdvcmxkLW9mLXNjYW1zLWFzLW1hbnktc2NyYW1ibGUtdG8tZmluZC1ob2xpZGF5LWdpZnRzLyIsInBsdWdpbnMiOnsiY29tc2NvcmUiOnsiY2xpZW50SWQiOiI2MDM2NDM5IiwiYzMiOiJDQlMxNy5jb20iLCJzY3JpcHQiOiIvL3czLm1wLmx1cmEubGl2ZS9wbGF5ZXIvcHJvZC92My9wbHVnaW5zL2NvbXNjb3JlL2NvbXNjb3JlcGx1Z2luLm1pbi5qcyIsInVzZURlcml2ZWRNZXRhZGF0YSI6dHJ1ZSwibWFwcGluZyI6eyJ2aWRlbyI6eyJjMyI6IkNCUzE3LmNvbSIsIm5zX3N0X3N0Ijoid25jbiIsIm5zX3N0X3B1IjoiTmV4c3RhciIsIm5zX3N0X2dlIjoiVmlkZW8iLCJjc191Y2ZyIjoiIn0sImFkIjp7ImMzIjoiQ0JTMTcuY29tIiwibnNfc3Rfc3QiOiJ3bmNuIiwibnNfc3RfcHUiOiJOZXhzdGFyIiwibnNfc3RfZ2UiOiJWaWRlbyIsImNzX3VjZnIiOiIifX19LCJkZnAiOnsiY2xpZW50U2lkZSI6eyJhZFRhZ1VybCI6Imh0dHBzOi8vcHViYWRzLmcuZG91YmxlY2xpY2submV0L2dhbXBhZC9hZHM%2Fc3o9MXgxMDAwJml1PSUyRjU2NzglMkZtZy53bmNuJTJGbmV3cyUyRmludmVzdGlnYXRvcnMmaW1wbD1zJmdkZnBfcmVxPTEmZW52PXZwJm91dHB1dD12bWFwJnVudmlld2VkX3Bvc2l0aW9uX3N0YXJ0PTEmYWRfcnVsZT0xJmRlc2NyaXB0aW9uX3VybD1odHRwcyUzQSUyRiUyRnd3dy5jYnMxNy5jb20lMkZuZXdzJTJGaW52ZXN0aWdhdG9ycyUyRnN1cHBseS1jaGFpbi1zaG9ydGFnZXMtb3Blbi1hLW5ldy13b3JsZC1vZi1zY2Ftcy1hcy1tYW55LXNjcmFtYmxlLXRvLWZpbmQtaG9saWRheS1naWZ0cyUyRiZ2Y29ucD0yJmN1c3RfcGFyYW1zPXZpZCUzRDcxNTQzNjUlMjZjbXNpZCUzRDEwMDQxNjElMjZwaWQlM0QxMDA0MTYxJTI2dmlkY2F0JTNEJTJGbmV3cyUyRmludmVzdGlnYXRvcnMlMjZib2JfY2slM0QlNUJib2JfY2tfdmFsJTVEJTI2ZF9jb2RlJTNEbmEwMDMlMjZwbGF5ZXJ3aWR0aCUzRDg3NiUyNnBsYXllcmhlaWdodCUzRDQ5MyZwcGlkPTQzNDEwZjAyLTU2YTQtNDAwNi05NjhhLTdlYWU5NTU2ZDM2NyJ9fSwibmllbHNlbiI6eyJhcGlkIjoiUDNERUMwQ0IxLTlDQjEtNEQzNS1CMzlCLTBFMUYzRDY5RUQyRiIsInNmY29kZSI6ImRjciIsInR5cGUiOiJkY3IiLCJhcG4iOiJBbnZhdG8iLCJlbnZpcm9ubWVudCI6InByb2R1Y3Rpb24iLCJ1c2VEZXJpdmVkTWV0YWRhdGEiOnRydWUsIm1hcHBpbmciOnsiYWRsb2FkdHlwZSI6MiwiYWRNb2RlbCI6Mn0sIm9wdE91dCI6ZmFsc2V9LCJzZWdtZW50Q3VzdG9tIjp7InNjcmlwdCI6Imh0dHBzOi8vc2VnbWVudC5wc2cubmV4c3RhcmRpZ2l0YWwubmV0L2FudmF0by5qcyIsIndyaXRlS2V5IjoiNnhWWjBkbnd2a0dtVUhtYjhPcGR3MWF1WUpISWdOOG8iLCJwbHVnaW5zTG9hZGluZ1RpbWVvdXQiOjEyfSwiZ29vZ2xlQW5hbHl0aWNzIjp7InRyYWNraW5nSWQiOiJVQS02MDA4ODk1Mi00IiwiZXZlbnRzIjp7IkFEX1NUQVJURUQiOnsiYWxpYXMiOiJWaWRlby1BZCIsImNhdGVnb3J5IjoiVmlkZW8iLCJsYWJlbCI6IltbVElUTEVdXSJ9LCJWSURFT19TVEFSVEVEIjp7ImFsaWFzIjoiVmlkZW8tUGxheSIsImNhdGVnb3J5IjoiVmlkZW8iLCJsYWJlbCI6IltbVElUTEVdXSJ9LCJWSURFT19GSVJTVF9RVUFSVElMRSI6eyJhbGlhcyI6IlZpZGVvLTI1JSIsImNhdGVnb3J5IjoiVmlkZW8iLCJsYWJlbCI6IltbVElUTEVdXSJ9LCJWSURFT19NSURfUE9JTlQiOnsiYWxpYXMiOiJWaWRlby01MCUiLCJjYXRlZ29yeSI6IlZpZGVvIiwibGFiZWwiOiJbW1RJVExFXV0ifSwiVklERU9fVEhJUkRfUVVBUlRJTEUiOnsiYWxpYXMiOiJWaWRlby03NSUiLCJjYXRlZ29yeSI6IlZpZGVvIiwibGFiZWwiOiJbW1RJVExFXV0ifSwiVklERU9fQ09NUExFVEVEIjp7ImFsaWFzIjoiVmlkZW8tMTAwJSIsImNhdGVnb3J5IjoiVmlkZW8iLCJsYWJlbCI6IltbVElUTEVdXSJ9LCJVU0VSX1BBVVNFIjp7ImFsaWFzIjoiUGF1c2UiLCJjYXRlZ29yeSI6IlZpZGVvIiwibGFiZWwiOiJbW1RJVExFXV0ifSwiVVNFUl9SRVNVTUUiOnsiYWxpYXMiOiJSZXN1bWUiLCJjYXRlZ29yeSI6IlZpZGVvIiwibGFiZWwiOiJbW1RJVExFXV0ifX19LCJoZWFsdGhBbmFseXRpY3MiOnt9fSwiaHRtbDUiOnRydWUsInRva2VuIjoiZXlKMGVYQWlPaUpLVjFRaUxDSmhiR2NpT2lKSVV6STFOaUo5LmV5SjJhV1FpT2lJM01UVTBNelkxSWl3aWFYTnpJam9pTnpCWU16VlJZamcxTlU5UFZXMVdaVmRqV1dKb01IYzViRTQwYXpKU01YY2lMQ0psZUhBaU9qRTJNemN4TmpJMk1EUjkub1hJQUtVOERGdnByTWVCUmkwanp3cnVKa3FfUXJaeHJBMVFQMXA0TS1PTSJ9&quot; webkitallowfullscreen=&quot;&quot; width=&quot;640&quot;&gt;&lt;/iframe&gt;&lt;p&gt;For defenders, be on the lookout for top-level domains like .top, .stream, .trade and .bid, which are &lt;a href=&quot;https://blog.talosintelligence.com/2018/11/what-scams-shoppers-should-look-out-for.html&quot; target=&quot;_blank&quot;&gt;traditionally responsible for the majority of spam emails&lt;/a&gt; Talos sees during this period.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here are some other important tips for avoiding holiday shopping scams:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Only download apps from trusted and official app stores like the Google Play store and iOS App Store.&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Look out for apps that ask for suspicious permissions, such as access to your text messages, contacts, stored passwords and administrative features.&amp;nbsp;&lt;/li&gt;&lt;li&gt;Some malicious apps will try to masquerade as a legitimate version of the one you could be searching for. Signs of these apps include poor spelling and grammar in app descriptions and interfaces, lack of high-quality performance and a developer contact that uses a free email service (such as @gmail.com).&amp;nbsp;&lt;/li&gt;&lt;li&gt;Avoid clicking on unsolicited emails. Make sure you purposefully subscribed to any marketing emails you receive from retailers before opening it.&amp;nbsp;&lt;/li&gt;&lt;li&gt;Use an ad blocker locally on your browser. These will often block any malvertising campaigns that aim to capitalize on shoppers looking for deals.&amp;nbsp;&lt;/li&gt;&lt;li&gt;Try to use payment services such as Google Pay, Samsung Pay and Apple Pay. These services use tokenization instead of the “Primary Account Number” (your credit card number), making your transaction more secure.&amp;nbsp;&lt;/li&gt;&lt;li&gt;Use complex passwords that are unique, per site. Attackers commonly reuse passwords to compromise multiple accounts with the same username. Use a password locker if you have a hard time creating and remembering secure passwords.&amp;nbsp;&lt;/li&gt;&lt;li&gt;Manually type in URLs to sites you want to visit rather than clicking on links.&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Use multi-factor authentication, such as Cisco Duo, to log into your email account to avoid unauthorized access.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.talosintelligence.com/feeds/4443717675169030276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.talosintelligence.com/2021/11/talos-tips-for-staying-safe-while.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/4443717675169030276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/4443717675169030276'/><link rel='alternate' type='text/html' href='http://blog.talosintelligence.com/2021/11/talos-tips-for-staying-safe-while.html' title='Talos’ tips for staying safe while shopping online this holiday season '/><author><name>Jon Munshaw</name><uri>http://www.blogger.com/profile/13414456218583234191</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://lh3.googleusercontent.com/-sazDyDesP8M/YZUPeHaWxtI/AAAAAAAAAek/cG_SwD1gYb022EJTYQw4-483_tuEak52wCNcBGAsYHQ/s72-c/112420%2Bonline%2Bshopping%2Bscams.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-5574847157809310038</id><published>2021-11-16T07:00:00.000-05:00</published><updated>2021-11-16T07:00:22.332-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cobalt Strike"/><category scheme="http://www.blogger.com/atom/ns#" term="SecureX"/><category scheme="http://www.blogger.com/atom/ns#" term="trojan"/><title type='text'>Attackers use domain fronting technique to target Myanmar with Cobalt Strike</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;1000&quot; data-original-width=&quot;2000&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjWDIZ5vILZaLdh5CH6rPbmyWIOxvRGslln9nb_qtmvpnpaCrKzwYj9g0pO2CRuS8plA5oL2pHy-6FgL2_dlO4isxK3o562DU0yBRtBZl4tLDEbyPDh3xNeYWD9f_1gm-EN3O6mAkRXr4sZ6xMnDHvvv39xBzve7w6oSipyOdRGvXH9aeQ0-TXvo_AWAw&quot;/&gt;&lt;/div&gt;By &lt;a href=&quot;https://twitter.com/cRaghuprasad&quot;&gt;Chetan Raghuprasad&lt;/a&gt;, &lt;a href=&quot;https://twitter.com/vanjasvajcer&quot;&gt;Vanja Svajcer&lt;/a&gt; and &lt;a href=&quot;https://twitter.com/asheermalhotra&quot;&gt;Asheer Malhotra&lt;/a&gt;.&lt;br /&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;News Summary&lt;/h3&gt; &lt;ul&gt;&lt;li&gt;Cisco Talos discovered a new malicious campaign using a leaked version of Cobalt Strike in September 2021. &lt;/li&gt;&lt;li&gt;This shows that Cobalt Strike, although it was originally created as a legitimate tool, continues to be something defenders need to monitor, as attackers are using it to set up attacks.&lt;/li&gt;&lt;li&gt;The threat actor in this case uses domain fronting with the Cloudflare Content Delivery Network, redirecting a Myanmar government owned-domain to an attacker-controlled server.&lt;/li&gt;&lt;li&gt;The threat actor employed the tactic of re-registering reputed domains in their attack chains to evade detections.&lt;/li&gt;&lt;li&gt;This threat demonstrates several techniques of the MITRE ATT&amp;amp;CK framework, most notably &lt;a href=&quot;https://attack.mitre.org/techniques/T1202/&quot;&gt;T1202&lt;/a&gt; - Indirect Command Execution , &lt;a href=&quot;https://attack.mitre.org/techniques/T1027/&quot;&gt;T1027 &lt;/a&gt;- Obfuscated Files or Information, &lt;a href=&quot;https://attack.mitre.org/techniques/T1105/&quot;&gt;T1105&lt;/a&gt; - Ingress Tool Transfer, &lt;a href=&quot;https://attack.mitre.org/techniques/T1071/001/&quot;&gt;T1071.001&lt;/a&gt; - Application Layer Protocols:Web Protocols.&lt;/li&gt;&lt;/ul&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;What&#39;s New?&lt;/h3&gt;&lt;p&gt;Cisco Talos discovered a malicious campaign using an obfuscated Meterpreter stager to deploy Cobalt Strike beacons in September 2021. The actor used a domain owned and operated by the Myanmar government, the &lt;a href=&quot;https://www.mdn.gov.mm/en/home&quot;&gt;Myanmar Digital News&lt;/a&gt; network, as a &lt;a href=&quot;https://blog.cobaltstrike.com/2017/02/06/high-reputation-redirectors-and-domain-fronting/&quot;&gt;domain front&lt;/a&gt; for their beacons.&lt;/p&gt;&lt;p&gt;The evolution of this threat indicates that the attackers have been active since at least August 2021 using a combination of Meterpreter stagers and Cobalt Strike beacons to establish presence on victim&#39;s endpoints.&lt;/p&gt; &lt;a name=&#39;more&#39;&gt;&lt;/a&gt;   &lt;h3 style=&quot;text-align: left;&quot;&gt;How did it work?&lt;/h3&gt;&lt;p&gt;The malware is typically a loader that runs on a victim machine, decodes and executes the Cobalt Strike beacon DLL via reflective injection. It loads several libraries during the runtime and generates the beacon traffic according to the embedded configuration file. The configuration file contains the information related to the command and control (C2) server which instructs the victim&#39;s machine to send the initial DNS request attempting to connect to the host of the Myanmar government-owned domain www[.]mdn[.]gov[.]mm. The site is hosted behind the Cloudflare content delivery network and the actual C2 traffic is redirected to an attacker controlled server test[.]softlemon[.]net based on the HTTP host header information specified in the beacon&#39;s configuration data.&lt;/p&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;So what? &lt;/h3&gt;&lt;p&gt;Cobalt Strike has been used by many actors in the past and is a de-facto standard tool for post-exploitation activities and pivoting. Attackers use it to deploy a wide range of payloads, from commodity malware, to sophisticated state-sponsored activities.  &lt;/p&gt;&lt;p&gt;Cobalt Strike allows actors to shape the traffic of beacons to mimic legitimate traffic patterns. One of the techniques to conceal the traffic from DNS-based filtering is &lt;a href=&quot;https://blog.cobaltstrike.com/2017/02/06/high-reputation-redirectors-and-domain-fronting/&quot;&gt;Domain Fronting&lt;/a&gt;. Domain fronting uses legitimate or high-reputation domains to remain undetected by defenders. The attacker&#39;s choice of Myanmar-specific domains for domain fronting may indicate an interest in the geopolitics of this area of the world.&lt;/p&gt;&lt;p&gt;In this campaign, the actor used staged payloads using the Meterpreter stager, which gives an indication that the beacon will be used for further attacks. The defenders should be constantly vigilant and monitor network traffic to &lt;a href=&quot;https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html&quot;&gt;detect Cobalt Strike activities&lt;/a&gt;, since it is one of the most commonly used offensive tools by crimeware and APT operators. &lt;/p&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Evolution of the campaign&lt;/h3&gt;&lt;p&gt;A study of the evolution of the campaign shows the actor experimenting with different combinations of hosts with the intent of perfecting the domain fronting technique. &lt;/p&gt;&lt;p&gt;The earliest beacon discovered around the middle of August 2021 contains the C2 URI set to test[.]softlemon[.]net while the HTTP Get and Post requests headers are pointing to dark-forest-002[.]president[.]workers[.]dev which is a Cloudflare &lt;a href=&quot;https://blog.cloudflare.com/announcing-workers-dev/&quot;&gt;serverless workers domain&lt;/a&gt;. The default host header configuration for request contains the host name test[.]softlemon[.]net, which is also used by more recent samples. &lt;/p&gt;&lt;p&gt;Another sample discovered in late August 2021 consisted of the C2 host URI xxx[.]xxxx[.]tk and the host header setting configured to point to test[.]softlemon[.]net. &lt;/p&gt;&lt;p&gt;Beginning September 2021, the attackers started using the Myanmar Digital News domain for fronting their beacons. While the default C2 domain was specified as www[.]mdn[.]gov[.]mm, the beacon&#39;s traffic was redirected to the de-facto C2 test[.]softlemon[.]net via HTTP Get and POST metadata specified in the beacon&#39;s configuration. &lt;/p&gt;&lt;p&gt;The actor likely changed the configuration to test their infrastructure and the domain fronting functionality before launching the attack. Based on the beacon configuration template and the real C2 host test[.]softlemon[.]net, we assess with moderate confidence that the samples are created by a single actor. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgaaAMAl4KyzZKuaYOHuSVtPtoCsnnfjggEKDJuljmpQMwc75qjH-SoCd70JsbYdOPxzYuizASu6Ge5XVVmARUt9drw5N1tMH0Cjrsb_qKnx72FjH2YLED7_yIa-mPVZjRLgrPw8Whl3-0w26NRVblGvTHzfu1ttlE9s05oy6EyG2okkEEzfdcCzHzeTA&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;1479&quot; data-original-width=&quot;1956&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgaaAMAl4KyzZKuaYOHuSVtPtoCsnnfjggEKDJuljmpQMwc75qjH-SoCd70JsbYdOPxzYuizASu6Ge5XVVmARUt9drw5N1tMH0Cjrsb_qKnx72FjH2YLED7_yIa-mPVZjRLgrPw8Whl3-0w26NRVblGvTHzfu1ttlE9s05oy6EyG2okkEEzfdcCzHzeTA&quot;/&gt;&lt;/a&gt;&lt;i&gt;Timeline of malware samples first seen in the wild.&lt;/i&gt;&lt;/div&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Cobalt Strike beacon configurations&lt;/h3&gt; &lt;p&gt;We extracted the beacon config from the payload that showed us the actor has used different values for the User Agent, C2-Server and Host-header in different malwares of this campaign.&lt;/p&gt;&lt;p&gt;The beacon configuration of samples usually has a User Agent, which is Mozilla compatible and of Windows 7. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjuAPZP5vL9TU1SwOzsAzH_WIozpkrPi39QpnUTLYo05IHMJICay3so-N0kZu4aEl9GAVNXztsu05Nq6PS29wbE7G-EQ1qPTR3SBhCqJxerqqNozoQx-14npbZMewo-qswLQ2Kl68-hetv0Q-8GYHDHDD7rKjm8Q3FJ-U7OLypYW9hFC34taIaDvwTz-g&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;196&quot; data-original-width=&quot;1408&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjuAPZP5vL9TU1SwOzsAzH_WIozpkrPi39QpnUTLYo05IHMJICay3so-N0kZu4aEl9GAVNXztsu05Nq6PS29wbE7G-EQ1qPTR3SBhCqJxerqqNozoQx-14npbZMewo-qswLQ2Kl68-hetv0Q-8GYHDHDD7rKjm8Q3FJ-U7OLypYW9hFC34taIaDvwTz-g&quot;/&gt;&lt;/a&gt; &lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj0HjYRU-y9ZrbhmR7sQQCqtYJ1zU9wrpuwEt9Adr5FQMaOJ9iD4eJ5MXF5KIfeN4a2W-qErWJ5YoYYTGHI6OGZBoyNQIMt8cmRTNeDSu0b5vxGW2H9zbccz_aIj1c4w2hUKj5g3yGwTn5roJIhW79n1OvuGklg_2bMg5pT-hm7hXNK6oZ0fZ4r6QyTBw&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;206&quot; data-original-width=&quot;1454&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj0HjYRU-y9ZrbhmR7sQQCqtYJ1zU9wrpuwEt9Adr5FQMaOJ9iD4eJ5MXF5KIfeN4a2W-qErWJ5YoYYTGHI6OGZBoyNQIMt8cmRTNeDSu0b5vxGW2H9zbccz_aIj1c4w2hUKj5g3yGwTn5roJIhW79n1OvuGklg_2bMg5pT-hm7hXNK6oZ0fZ4r6QyTBw&quot;/&gt;&lt;/a&gt;&lt;i&gt;C2 server, UserAgent and de-facto C2 variations in the beacons.&lt;/i&gt;&lt;/div&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Watermark&lt;/h3&gt;&lt;p&gt;The Cobalt Strike watermark is a number generated from the license file and is unique to a Cobalt Strike license. The watermark on the beacons used in this campaign was 305419896 (hex: 0x12345678).&lt;/p&gt;&lt;p&gt;This particular watermark has previously been attributed to a leaked Cobalt Strike version and is unsurprisingly used by other malicious actors, such as &lt;a href=&quot;https://www.sentinelone.com/labs/enter-the-maze-demystifying-an-affiliate-involved-in-maze-snow/&quot;&gt;Maze ransomware&lt;/a&gt; and &lt;a href=&quot;https://www.zscaler.com/blogs/security-research/targeted-attack-leverages-india-china-border-dispute-lure-victims&quot;&gt;Trickbot groups&lt;/a&gt;, making attribution based on the watermark number impossible. It is difficult to assess if the usage of the previously registered expired domain for C2 server and the leaked Cobalt Strike point to an increased operational security awareness of the actor or to limited resources available to them. &lt;/p&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Domain fronting &lt;/h3&gt;&lt;p&gt;The actor in this campaign has used domain fronting, which is a technique which can use high reputation domains to conceal the Cobalt Strike command and control traffic. A government domain of Myanmar www[.]mdn[.]gov[.]mm was used in this particular instance. &lt;/p&gt;&lt;p&gt;The fronted domain mdn[.]gov[.]mm is a legitimate domain of Myanmar Digital News, a state-owned digital newspaper. This website has previously been compromised in February by the Brotherhood of Myanmar group, a collection of militia groups. Although there are no indications that the previous defacement of the domain by the Brotherhood of Myanmar and the campaign described in this post are related, the domain itself is clearly of interest to various actors. &lt;/p&gt;&lt;p&gt;Domain fronting can be achieved with a redirect between the malicious server and the target. Malicious actors may misuse various content delivery networks (CDNs) to set up redirects of serving content to the content served by attacker-controlled C2 hosts. Cloudflare is one of the CDN services that provides its users with a globally distributed cache for files hosted on their servers. Cloudflare identifies distributions by the FQDN used to request resources. Cloudflare users have the option to use their own subdomain and create a DNS record that points to Cloudflare. This subdomain tells Cloudflare to associate that DNS record with a specific distribution. &lt;/p&gt;&lt;p&gt;The beacon calls home www[.]mdn[.]gov[.]mm,/api/3 and has set the Host header to the actual C2 server test[.]softlemon[.]net. The beacon traffic resolves to a Cloudflare IP address. The DNS request that led them there will be lost and relies on other parts of the HTTP request, including the Host header and the actual C2 test[.]softlemon[.]net. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjEynimvn-fKJerUudRw8zTgvZ4gw8YU8KeVGUkuPrFvFl42fT2yTz4ZQuzbyx08tewWrF-WTK_rVDrxvyzOpqecaXtItPH40nxKgGVcNZgwarcTSDfUwmwy7X8EKdzewpiAW4V_DPk_c5Hnbi73Q7o4_xzT0CEarZDBNmwG9nhH_ymd1IvoVHn_fqqSw&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;1827&quot; data-original-width=&quot;1999&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjEynimvn-fKJerUudRw8zTgvZ4gw8YU8KeVGUkuPrFvFl42fT2yTz4ZQuzbyx08tewWrF-WTK_rVDrxvyzOpqecaXtItPH40nxKgGVcNZgwarcTSDfUwmwy7X8EKdzewpiAW4V_DPk_c5Hnbi73Q7o4_xzT0CEarZDBNmwG9nhH_ymd1IvoVHn_fqqSw&quot;/&gt;&lt;/a&gt;&lt;i&gt;Summary of domain fronting of Myanmar government&#39;s domain.&lt;/i&gt;&lt;/div&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Cobalt Strike payload&lt;/h3&gt;&lt;p&gt;The beacons are of particular interest due to the domain fronting technique using a government host as the initial DNS lure. The MITRE ATT&amp;amp;CK framework techniques used by this malware are:&lt;/p&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://attack.mitre.org/techniques/T1202/&quot;&gt;T1202&lt;/a&gt; - Indirect Command Execution &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://attack.mitre.org/techniques/T1027/&quot;&gt;T1027&lt;/a&gt; - Obfuscated Files or Information&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://attack.mitre.org/techniques/T1105/&quot;&gt;T1105&lt;/a&gt; - Ingress Tool Transfer&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://attack.mitre.org/techniques/T1071/001/&quot;&gt;T1071.001&lt;/a&gt; - Application Layer Protocols:Web Protocols&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;We also analysed the loader binary to find specifics of its memory loading and functionality. &lt;/p&gt;&lt;p&gt;We spotted a suspicious section .kxrt with the packed and encoded malicious code. The malware links several functions at runtime and has the Meterpreter staging code. &lt;/p&gt;&lt;p&gt;When the malware runs, the .tls section runs first, loads the libraries and starts the execution of the malicious code at the entry point in the .kxrt section. The entry point code calls a function to allocate virtual memory in its own process space.&lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjYlRj6A_xY1hLlBaeM-npjJRslNX1tPssdRn31sbE3u-iyHS1BUX7tFXicdUXJ8mmy9Rl9G2VXb0KkrC_nI66MZ5wP55Oj6zb9FlU-SOsP7jHs9HIVzid_dksJ-tatG4bn1A5z8fDv95I1wyNGNmLIZyeWyqyFWwxf00VFzj69nBzBcn3p8i_ZyCLt7Q&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;563&quot; data-original-width=&quot;631&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjYlRj6A_xY1hLlBaeM-npjJRslNX1tPssdRn31sbE3u-iyHS1BUX7tFXicdUXJ8mmy9Rl9G2VXb0KkrC_nI66MZ5wP55Oj6zb9FlU-SOsP7jHs9HIVzid_dksJ-tatG4bn1A5z8fDv95I1wyNGNmLIZyeWyqyFWwxf00VFzj69nBzBcn3p8i_ZyCLt7Q&quot;/&gt;&lt;/a&gt;  &lt;i&gt;Function at address 00401550 shows the allocation of virtual memory.&lt;/i&gt;&lt;/div&gt;&lt;p&gt;The loader next calls the VirtualProtect function to set the virtual memory page permissions to Read-Write-Execute and writes the image base of the Cobalt Strike beacon which will be executed in a new thread. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEijDybLftBRmdQ12VRSPFoRo5fmOPPpjv0Ebo3xS56_D2lcwsCYucGnKcxaD4Utc-6akFAvBIiyMfE3BL1ustXytyYZ5Y8wZCC_kXyc19R9_qJzHfSG9rNWPjqmkYfbUS6VXmGJV1Mh484X29t6QW3T2LwbX2B3QDorkrAux0kepyZVX4sTsYALsU0ftw&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;287&quot; data-original-width=&quot;519&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEijDybLftBRmdQ12VRSPFoRo5fmOPPpjv0Ebo3xS56_D2lcwsCYucGnKcxaD4Utc-6akFAvBIiyMfE3BL1ustXytyYZ5Y8wZCC_kXyc19R9_qJzHfSG9rNWPjqmkYfbUS6VXmGJV1Mh484X29t6QW3T2LwbX2B3QDorkrAux0kepyZVX4sTsYALsU0ftw&quot;/&gt;&lt;/a&gt;  &lt;i&gt;Function sets the  virtual memory page permission to Read-Write-Execute.&lt;/i&gt;&lt;/div&gt;&lt;p&gt;We spotted two libraries linking during runtime. Aside from this, there are several other standard libraries the malware links during the runtime. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhEmi_2vSzI1b-ujPSZk9EsuE-WBTgQfWKVV2tnCnKWVgZPYu6YrrIko-sqAmbPCryvUNz4Iq7HgPaRwAJmdkV_KWksK0XOi-oNCngFrkVtuJAZv8koU4Tqr25yMv7zzCSLysYiuCkMkskJqFKNrVTUrFxXjoqm722gs9MOTwDxEzIFadvsRmrr1Tk1EQ&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;419&quot; data-original-width=&quot;691&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhEmi_2vSzI1b-ujPSZk9EsuE-WBTgQfWKVV2tnCnKWVgZPYu6YrrIko-sqAmbPCryvUNz4Iq7HgPaRwAJmdkV_KWksK0XOi-oNCngFrkVtuJAZv8koU4Tqr25yMv7zzCSLysYiuCkMkskJqFKNrVTUrFxXjoqm722gs9MOTwDxEzIFadvsRmrr1Tk1EQ&quot;/&gt;&lt;/a&gt;&lt;i&gt;Function that loads library during the runtime. &lt;/i&gt;&lt;/div&gt;&lt;p&gt;After allocating the virtual memory and setting the page permissions to Read-Write-Execute, a decryption routine is executed that decrypts the remaining malicious code in the .kxrt section and writes it to the virtual memory. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi5mvcEP3MbamotbXVqveKmltvVX2s3pK09IBROV3ebVr777TME_g0zqTGkSQ7pA99J63ggTAWVvRhyKN0xXntQvT3bLT1rD46BMnWyv9HItF3D1AcZ8x4gfiuN_vo4OyFtV7eyGe7negfFjZNXYjWgbtIm1odLuT-6Q0AggX_q_8OJrHEfKb2O_FSMuw&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;371&quot; data-original-width=&quot;853&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi5mvcEP3MbamotbXVqveKmltvVX2s3pK09IBROV3ebVr777TME_g0zqTGkSQ7pA99J63ggTAWVvRhyKN0xXntQvT3bLT1rD46BMnWyv9HItF3D1AcZ8x4gfiuN_vo4OyFtV7eyGe7negfFjZNXYjWgbtIm1odLuT-6Q0AggX_q_8OJrHEfKb2O_FSMuw&quot;/&gt;&lt;/a&gt;&lt;i&gt;Decoder routine to decrypt the beacon DLL.&lt;/i&gt;&lt;/div&gt;&lt;p&gt;The decrypted malicious code is the actual Cobalt Strike beacon. Once decoded, the loader&#39;s execution jumps to the beginning of the DLL resulting in a reflective-load of the beacon into the loader process memory. This beacon is now responsible for decoding the configuration.  &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEju19ng_8ZRMizrF6PwAKcqAHNERQV08caJRotlJ4w-tCzvfk2DIe-UCY-KedpbGKpN2QZCWdgnfsP7vj1J0vtkg1bl9Fi5on5UuKNw2Yj0F1G4Wg7Wj_Do7VVXylfZpC0Z6NrfsJb4vSxibeQMwIl2xd8MWcTxQ1fXJDwYLNFe0snqqNF6bz9rP20YQw&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;317&quot; data-original-width=&quot;1329&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEju19ng_8ZRMizrF6PwAKcqAHNERQV08caJRotlJ4w-tCzvfk2DIe-UCY-KedpbGKpN2QZCWdgnfsP7vj1J0vtkg1bl9Fi5on5UuKNw2Yj0F1G4Wg7Wj_Do7VVXylfZpC0Z6NrfsJb4vSxibeQMwIl2xd8MWcTxQ1fXJDwYLNFe0snqqNF6bz9rP20YQw&quot;/&gt;&lt;/a&gt;&lt;i&gt;Stack view of info loaded from the beacon config.&lt;/i&gt;&lt;/div&gt;&lt;p&gt;The beacon resolves the proxy by calling WinHTTPGetProxyForUrlEx and WinHTTPCreateProxyResolver to bypass the proxy for the URL. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi4qWCJjqcSuHM-fsUx9zhSyNz8If35hKhccMJqN7GtDykGNWF8Xzwyxx9sIDhIp7xGP1ysytzxUBvMEtaTJfIvhPgyO2ZEUwSNQD3n44dz4ns5LEOP9XKfOiX8jVRnGSHAaVESTklOMwZJAHvMfcdi_Qj-BdOkqQ7pzjGULwgbgJ_SBB_pUdOcKPuLqw&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;860&quot; data-original-width=&quot;1999&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEi4qWCJjqcSuHM-fsUx9zhSyNz8If35hKhccMJqN7GtDykGNWF8Xzwyxx9sIDhIp7xGP1ysytzxUBvMEtaTJfIvhPgyO2ZEUwSNQD3n44dz4ns5LEOP9XKfOiX8jVRnGSHAaVESTklOMwZJAHvMfcdi_Qj-BdOkqQ7pzjGULwgbgJ_SBB_pUdOcKPuLqw&quot;/&gt;&lt;/a&gt;&lt;i&gt;Function that resolves the victim&#39;s system proxy for the URL. &lt;/i&gt;&lt;/div&gt;&lt;p&gt;Soon after that, the beacon initiates the Cobalt Strike beacon traffic to the C2 server. The DNS request for the initial host resolves to a Cloudflare-owned IP address that allows the attacker to employ domain fronting and send the traffic to the actual C2 host test[.]softlemon[.]net, also proxied by Cloudflare. &lt;/p&gt;&lt;p&gt;At the time of analysis, the sample C2 host infrastructure was not online and we received a 404 error. &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgz12h0NWK2gWv8eciglGIxMyytLYCFmoK2A7hWYCN9V69uoHUAtUceUzI-PlYLtVqG39WZtXIFDIxLP6obm5J2R1vgvC9k-9-Tt_-fhYFt04e7MZc2LxJ75Z_lsv-gmVHMzjzRR1lcPvB2OJf3mBUr49X3ckFHJVMQ_DHAZQnhhmBWPNltd70vy60tuA&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;659&quot; data-original-width=&quot;1022&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgz12h0NWK2gWv8eciglGIxMyytLYCFmoK2A7hWYCN9V69uoHUAtUceUzI-PlYLtVqG39WZtXIFDIxLP6obm5J2R1vgvC9k-9-Tt_-fhYFt04e7MZc2LxJ75Z_lsv-gmVHMzjzRR1lcPvB2OJf3mBUr49X3ckFHJVMQ_DHAZQnhhmBWPNltd70vy60tuA&quot;/&gt;&lt;/a&gt;&lt;i&gt;Cobalt Strike beacon traffic. &lt;/i&gt;&lt;/div&gt;&lt;p&gt;The beacon contains techniques to detect debuggers using GetTickCount, IsDebuggerPresent and the NtDelayExecution call to delay the execution of the malware for evading sandbox-based dynamic analysis systems. The beacon can also manage the system power policies registry keys to set the minimum and maximum sleep times and the lid open and close action policy. &lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiJpTjCcThzQCluiIpufawMstsBwD3wTALrCGDV5e_hDmNY_LeLrnsA8xBDb0DD5BuQnEUd9ZXxf5tOooQeygdN1zorwZ6y1mCs5s9VyjizkUGQOG4NHeAOI-Cj9dcxq5U_pHPWAHwUuKFRq9OSmZWDuiwkdTFX4IZ0cYEYxnubD3ipxlW-Fwy72WmdTQ=s877&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; width=&quot;400&quot; data-original-height=&quot;593&quot; data-original-width=&quot;877&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiJpTjCcThzQCluiIpufawMstsBwD3wTALrCGDV5e_hDmNY_LeLrnsA8xBDb0DD5BuQnEUd9ZXxf5tOooQeygdN1zorwZ6y1mCs5s9VyjizkUGQOG4NHeAOI-Cj9dcxq5U_pHPWAHwUuKFRq9OSmZWDuiwkdTFX4IZ0cYEYxnubD3ipxlW-Fwy72WmdTQ=s400&quot;/&gt;&lt;/a&gt;&lt;i&gt;The beacon modifies the victim&#39;s system power and lid open/close policies in the registry.&lt;/i&gt;&lt;/div&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Command and control&lt;/h3&gt;&lt;p&gt;The C2 server - test[.]softlemon[.]net is the subdomain of softlemon[.]net. The domain softlemon[.]net was registered under Google domains until August 2019 and likely expired since then. The malicious actor re-registered this domain on Aug. 5, 2021. The  SSL certificate for the domain softlemon[.]net with the serial number 4aa6af6d719bfdd1c6dff3d7b640aed7ee3was issued by Let&#39;s Encrypt, a free SSL certificate provider. &lt;/p&gt;&lt;p&gt;The Talos reputation engine has classified it as an untrusted domain and &lt;a href=&quot;https://umbrella.cisco.com/&quot;&gt;Cisco Umbrella&lt;/a&gt; shows a spike in the DNS queries in September 2021. This activity is consistent with the evolution of the Cobalt Strike beacons illustrated earlier the attackers started instrumenting beacons fronted with the Digital News domain at the beginning of September.&lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNfQBvIuef8b_SQAIM5kJfeoGC9OgUoJu-2WYO-epWIchT45rdE4XAZF9HQ_kMzt0MJg9VLSQP-1zO8U-G_XqK7l-_XEW6s76ixJzB2is39NpXYPbHD0ZkfcfFpz0lojBfTfBtvJlg8PsnfBbIo3Iu0lGSw37nphDeCwZogYWkhNVVhEc97hUmrwEKFQ&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; data-original-height=&quot;776&quot; data-original-width=&quot;1999&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjNfQBvIuef8b_SQAIM5kJfeoGC9OgUoJu-2WYO-epWIchT45rdE4XAZF9HQ_kMzt0MJg9VLSQP-1zO8U-G_XqK7l-_XEW6s76ixJzB2is39NpXYPbHD0ZkfcfFpz0lojBfTfBtvJlg8PsnfBbIo3Iu0lGSw37nphDeCwZogYWkhNVVhEc97hUmrwEKFQ&quot;/&gt;&lt;/a&gt;  &lt;i&gt;DNS spike for test[.]softlemon[.]net queries vs dates.&lt;/i&gt;&lt;/div&gt;&lt;p&gt;Our research uncovered that the C2 test[.]softlemon[.]net is a Windows server running Internet Information Services (IIS). &lt;/p&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEinC8reS539Z0TN9WgrNqdJ5xJUd7UmCTUX2_kL3JWSwPEsrDLyDxrYcaf-l39FHkriKTq7LnOgQ5Qa8_9lH1-3UeLv-t5KDHCZFqTp1jelEXJCemzSw3rHzVVR3SpedtPUwf1dx14wYa5NDj9vwJebtVpbNoCllY8sk4R6073k_2108gB1bHEnxhFhjQ=s1996&quot; style=&quot;display: block; padding: 1em 0; text-align: center; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; width=&quot;400&quot; data-original-height=&quot;1472&quot; data-original-width=&quot;1996&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEinC8reS539Z0TN9WgrNqdJ5xJUd7UmCTUX2_kL3JWSwPEsrDLyDxrYcaf-l39FHkriKTq7LnOgQ5Qa8_9lH1-3UeLv-t5KDHCZFqTp1jelEXJCemzSw3rHzVVR3SpedtPUwf1dx14wYa5NDj9vwJebtVpbNoCllY8sk4R6073k_2108gB1bHEnxhFhjQ=s400&quot;/&gt;&lt;/a&gt;  &lt;i&gt;IIS service response rendered from the host  test[.]softlemon[.]net.&lt;/i&gt;&lt;/div&gt;&lt;p&gt;According to Shodan, the IP address 193[.]135[.]134[.]124 hosted by a Russian provider may be the real C2 IP address protected by the Cloudflare infrastructure as the SSL certificate served on port 8443 belongs to Cloudflare and lists the X509v3 Subject Alternative Name as DNS:*.softlemon.net.   &lt;/p&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Conclusion&lt;/h3&gt;&lt;p&gt;Domain fronting is a technique used by attackers to circumvent protection based on DNS filtering. In this campaign, a malicious Cobalt Strike beacon is configured to take advantage of a mechanism used by Cloudflare and other content distribution networks to instruct the proxy about the host to be used for serving the content. &lt;/p&gt;&lt;p&gt;When the beacon is launched, it will submit a DNS request for a legitimate high-reputation domain hosted behind Cloudflare infrastructure and modify the subsequent HTTPs requests header to instruct the CDN to direct the traffic to an attacker-controlled host.   &lt;/p&gt;&lt;p&gt;Defenders should monitor their network traffic even to high reputation domains in order to identify the potential domain fronting attacks with Cobalt Strike and other offensive tools. XDR tools should be deployed to endpoints in order to detect behavior of Cobalt Strike loaders and Meterpreter stagers as they are frequently used by a wide range of actors. &lt;/p&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Coverage&lt;/h3&gt; Ways our customers can detect and block this threat are listed below.&lt;br /&gt; &lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjX5v_3h0HFdlWD-yzZZg_l_QrW98Wlxj0QBd0V6xNukgAwHoesvdalxkeeRWojAaMmTYBlcF8_cYynqy4f8861f6qH44yqoBtYwKi9MseGhh-FkDVqow6uu8vn9YkaOlII1IX12GBluNeMnnpNstwJDyoJRF1WUUxF4lWGcUty34O31pzIFjh7AsblFw=s1999&quot; style=&quot;display: block; padding: 1em 0; text-align: left; &quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; height=&quot;400&quot; data-original-height=&quot;1999&quot; data-original-width=&quot;1688&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjX5v_3h0HFdlWD-yzZZg_l_QrW98Wlxj0QBd0V6xNukgAwHoesvdalxkeeRWojAaMmTYBlcF8_cYynqy4f8861f6qH44yqoBtYwKi9MseGhh-FkDVqow6uu8vn9YkaOlII1IX12GBluNeMnnpNstwJDyoJRF1WUUxF4lWGcUty34O31pzIFjh7AsblFw=s400&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href=&quot;https://www.cisco.com/c/en/us/products/security/amp-for-endpoints/index.html&quot;&gt;Cisco Secure Endpoint&lt;/a&gt; (formerly AMP for Endpoints) is ideally suited to prevent the execution of the malware detailed in this post. Try Secure Endpoint for free &lt;a href=&quot;https://www.cisco.com/c/en/us/products/security/amp-for-endpoints/free-trial.html?utm_medium%3Dweb-referral?utm_source%3Dcisco%26utm_campaign%3Damp-free-trial%26utm_term%3Dpgm-talos-trial%26utm_content%3Damp-free-trial&quot;&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://www.cisco.com/c/en/us/products/security/firewalls/index.html&quot;&gt;Cisco Secure Firewall&lt;/a&gt; (formerly Next-Generation Firewall and Firepower NGFW) appliances such as&lt;a href=&quot;https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw-virtual/datasheet-c78-742858.html&quot;&gt; &lt;/a&gt;&lt;a href=&quot;https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw-virtual/datasheet-c78-742858.html&quot;&gt;Threat Defense Virtual&lt;/a&gt;,&lt;a href=&quot;https://www.cisco.com/c/en/us/products/security/adaptive-security-appliance-asa-software/index.html&quot;&gt; &lt;/a&gt;&lt;a href=&quot;https://www.cisco.com/c/en/us/products/security/adaptive-security-appliance-asa-software/index.html&quot;&gt;Adaptive Security Appliance&lt;/a&gt; and&lt;a href=&quot;https://meraki.cisco.com/products/appliances&quot;&gt; &lt;/a&gt;&lt;a href=&quot;https://meraki.cisco.com/products/appliances&quot;&gt;Meraki MX&lt;/a&gt; can detect malicious activity associated with this threat.&lt;br /&gt;&lt;a href=&quot;https://www.cisco.com/c/en/us/products/security/threat-grid/index.html&quot;&gt;Cisco Secure Malware Analytics&lt;/a&gt; (formerly Threat Grid) identifies malicious binaries and builds protection into all Cisco Secure products.&lt;br /&gt;&lt;a href=&quot;https://umbrella.cisco.com/&quot;&gt;Umbrella&lt;/a&gt;, Cisco&amp;#39;s secure internet gateway (SIG), blocks users from connecting to malicious domains, IPs and URLs, whether users are on or off the corporate network. Sign up for a free trial of Umbrella &lt;a href=&quot;https://signup.umbrella.com/?utm_medium%3Dweb-referral?utm_source%3Dcisco%26utm_campaign%3Dumbrella-free-trial%26utm_term%3Dpgm-talos-trial%26utm_content%3Dautomated-free-trial&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The following ClamAV signatures have been released to detect this threat:&lt;br /&gt;Win.Backdoor.CobaltStrike-9909816-0&lt;br /&gt;&lt;br /&gt;Open Source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on&lt;a href=&quot;http://snort.org&quot;&gt; &lt;/a&gt;&lt;a href=&quot;http://snort.org&quot;&gt;Snort.org&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;IOCs&lt;/h3&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Hashes&lt;/h3&gt; 658d550322cefa6efc51fbfd1a3e02839d1e519a20f8f17f01c534c0eaf36f27&lt;br /&gt;e806e55713b9e46dc7896521ffb9a8b3abaa597147ea387ff2e93a2469546ba9&lt;br /&gt;a0aec3e9cb3572a71c59144e9088d190b4978056c5c72d07cb458480213f2964&lt;br /&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Network IOCs&lt;/h3&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;Hosts&lt;/h3&gt; test[.]softlemon[.]net&lt;br /&gt;dark-forest-002.president[.]workers[.]dev&lt;br /&gt; &lt;h3 style=&quot;text-align: left;&quot;&gt;IP addresses&lt;/h3&gt;193[.]135[.]134[.]124 &lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;URLs&lt;/h3&gt;hxxp://test[.]softlemon[.]net:8081/api/3&lt;br /&gt;hxxp://test[.]softlemon[.]net/&lt;br /&gt;tcp://test[.]softlemon[.]net:8080/ &lt;br /&gt;hxxps://193[.]135[.]134[.]124:8443&lt;br /&gt;hxxp://193[.]135[.]134[.]124:8080&lt;br /&gt;hxxp://193[.]135[.]134[.]124:8081&lt;br /&gt; </content><link rel='replies' type='application/atom+xml' href='http://blog.talosintelligence.com/feeds/5574847157809310038/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/5574847157809310038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/5574847157809310038'/><link rel='alternate' type='text/html' href='http://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html' title='Attackers use domain fronting technique to target Myanmar with Cobalt Strike'/><author><name>Chetan Raghuprasad</name><uri>http://www.blogger.com/profile/10925469445918950644</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEjWDIZ5vILZaLdh5CH6rPbmyWIOxvRGslln9nb_qtmvpnpaCrKzwYj9g0pO2CRuS8plA5oL2pHy-6FgL2_dlO4isxK3o562DU0yBRtBZl4tLDEbyPDh3xNeYWD9f_1gm-EN3O6mAkRXr4sZ6xMnDHvvv39xBzve7w6oSipyOdRGvXH9aeQ0-TXvo_AWAw=s72-c" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-6072869143326961896</id><published>2021-11-15T14:19:00.008-05:00</published><updated>2021-11-16T11:20:39.286-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CVE"/><category scheme="http://www.blogger.com/atom/ns#" term="SecureX"/><category scheme="http://www.blogger.com/atom/ns#" term="vulnerabilities"/><title type='text'>Vulnerability Spotlight: Vulnerabilities in Lantronix PremierWave 2050 could lead to code execution, file deletion </title><content type='html'>&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh4nR3Zraixt4Qf-AHQD2YWbD6oY-j331BD8PpgOG8lQdKqH5sS_YTdlgqkG47PTU9c9g7-okI8DQQgMBN6vnwl5aOtk6HWXtOxhYIbhvhaIo9OUb9CVXxkAOwKfjsN4T3ohzyAdqy6nNO3K7cAi9j4zW1lgoJkzkYC1x9Uajl0GjptdTwbqRkfFMVu=s1001&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;501&quot; data-original-width=&quot;1001&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh4nR3Zraixt4Qf-AHQD2YWbD6oY-j331BD8PpgOG8lQdKqH5sS_YTdlgqkG47PTU9c9g7-okI8DQQgMBN6vnwl5aOtk6HWXtOxhYIbhvhaIo9OUb9CVXxkAOwKfjsN4T3ohzyAdqy6nNO3K7cAi9j4zW1lgoJkzkYC1x9Uajl0GjptdTwbqRkfFMVu=s16000&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Matt Wiseman discovered these vulnerabilities. Blog by Jon Munshaw.&amp;nbsp;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;Cisco Talos recently discovered multiple vulnerabilities in Lantronix’s PremierWave 2050, an embedded Wi-Fi module.&amp;nbsp;&lt;/p&gt;&lt;p&gt;There are several vulnerabilities in PremierWave 2050’s Web Manager, a web-accessible application that allows users to configure settings for the 2050 gateway. An attacker could exploit some of these vulnerabilities to carry out a range of malicious actions, including executing arbitrary code and deleting or replacing files on the targeted device.&amp;nbsp; &lt;span&gt;&lt;/span&gt;&lt;/p&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;Twelve of these vulnerabilities could allow a malicious user to manipulate the Web Manager in a way — for example, overflowing a fixed-size buffer — that would allow them to execute arbitrary code. These vulnerabilities all require the attacker to authenticate to the Web Manager first:&amp;nbsp;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1312&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1312&lt;/a&gt; (CVE-2021-21872)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1314&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1314&lt;/a&gt; (CVE-2021-21873 - CVE-2021-21875)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1315&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1315&lt;/a&gt; (CVE-2021-21876 and CVE-2021-21877)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1325&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1325&lt;/a&gt; (CVE-2021-21881)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1326&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1326&lt;/a&gt; (CVE-2021-21882)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1327&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1327&lt;/a&gt; (CVE-2021-21883)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1328&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1328&lt;/a&gt; (CVE-2021-21884)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1331&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1331&lt;/a&gt; (CVE-2021-21887)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1332&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1332&lt;/a&gt; (CVE-2021-21888)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1333&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1333&lt;/a&gt; (CVE-2021-21889)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1335&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1335&lt;/a&gt; (CVE-2021-21892)&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;There are also four directory traversal vulnerabilities that could lead to local file inclusion or overwrite:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1323&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1323&lt;/a&gt; (CVE-2021-21879)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1324&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1324&lt;/a&gt; (CVE-2021-21880)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1329&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1329&lt;/a&gt; (CVE-2021-21885)&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1337&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1337&lt;/a&gt; (CVE-2021-21894 and CVE-2021-21895)&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;There is another directory traversal vulnerability in the Web Manager’s FsBrowseCleanr function (&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1338&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1338&lt;/a&gt;/CVE-2021-21896), though in this case, an attacker could delete files on the targeted device. And a sixth directory traversal vulnerability (&lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1330&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1330&lt;/a&gt;/CVE-2021-21886) could lead to the adversary viewing certain file and directory names after sending the targeted device a specially crafted HTTP request.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Lastly, we also discovered &lt;a href=&quot;https://talosintelligence.com/vulnerability_reports/TALOS-2021-1322&quot; target=&quot;_blank&quot;&gt;TALOS-2021-1322&lt;/a&gt; (CVE-2021-21878), a local file inclusion vulnerability. An attacker could exploit this vulnerability to bypass certain restrictions and disclose contents of previously inaccessible files through the creation of an intermediate symlink.&amp;nbsp;&lt;/p&gt;&lt;p&gt;In adherence to &lt;a href=&quot;https://tools.cisco.com/security/center/resources/vendor_vulnerability_policy.html&quot; target=&quot;_blank&quot;&gt;Cisco’s vulnerability disclosure policy&lt;/a&gt;, Talos is disclosing these issues, although no formal fix is currently available. Talos tested and confirmed Lantronix PremierWave 2050, version 8.9.0.0R4 could be exploited by these vulnerabilities.&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhQwLKquJr3d3s7CS4g9L_Bfbbt4vrLFhrrBYKbwDfgdZKarpq3eMtXpDtqs1Cnq7waIANSrwJ3rJ79x-vbx7NXQ-_hffCOCUgBwLLoXgch5n1bY94Uq-clapyaqMpFHcJpwV6EVATHqKm3-QCG2Dsz2QsMU2hfFigoG5lQFmIYv7WHypcKfCDBWU_u=s1250&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;219&quot; data-original-width=&quot;1250&quot; height=&quot;35&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhQwLKquJr3d3s7CS4g9L_Bfbbt4vrLFhrrBYKbwDfgdZKarpq3eMtXpDtqs1Cnq7waIANSrwJ3rJ79x-vbx7NXQ-_hffCOCUgBwLLoXgch5n1bY94Uq-clapyaqMpFHcJpwV6EVATHqKm3-QCG2Dsz2QsMU2hfFigoG5lQFmIYv7WHypcKfCDBWU_u=w200-h35&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The following SNORTⓇ rules will detect exploitation attempts against this vulnerability: 57753 - 57759, 57764 - 57769, 57777 - 57779, 57783, 57784, 57796, 57800, 57801, 57805, 57806, 57792 - 57795. Additional rules may be released in the future and current rules are subject to change, pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org.&amp;nbsp;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.talosintelligence.com/feeds/6072869143326961896/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.talosintelligence.com/2021/11/lantronix-premier-wave-vuln-spotlight.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/6072869143326961896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/6072869143326961896'/><link rel='alternate' type='text/html' href='http://blog.talosintelligence.com/2021/11/lantronix-premier-wave-vuln-spotlight.html' title='Vulnerability Spotlight: Vulnerabilities in Lantronix PremierWave 2050 could lead to code execution, file deletion '/><author><name>Jon Munshaw</name><uri>http://www.blogger.com/profile/13414456218583234191</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEh4nR3Zraixt4Qf-AHQD2YWbD6oY-j331BD8PpgOG8lQdKqH5sS_YTdlgqkG47PTU9c9g7-okI8DQQgMBN6vnwl5aOtk6HWXtOxhYIbhvhaIo9OUb9CVXxkAOwKfjsN4T3ohzyAdqy6nNO3K7cAi9j4zW1lgoJkzkYC1x9Uajl0GjptdTwbqRkfFMVu=s72-c" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-8138324693781507974</id><published>2021-11-12T14:33:00.000-05:00</published><updated>2021-11-12T14:33:21.570-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Headlines"/><category scheme="http://www.blogger.com/atom/ns#" term="SecureX"/><category scheme="http://www.blogger.com/atom/ns#" term="Threat Roundup"/><category scheme="http://www.blogger.com/atom/ns#" term="threats"/><category scheme="http://www.blogger.com/atom/ns#" term="vulnerabilities"/><title type='text'>Threat Roundup for November 5 to November 12</title><content type='html'>&lt;div class=&quot;threat-roundup-content&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-NKUlpGEjBF4/XysV8o-5eKI/AAAAAAAAEXI/dPnA1tgXnNAlMZrArPMPpydaWKiZLbgrACLcBGAsYHQ/s1001/recurring%2Bblog%2Bimages_threat%2Broundup%25281%2529.jpg&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;501&quot; data-original-width=&quot;1001&quot; src=&quot;https://1.bp.blogspot.com/-NKUlpGEjBF4/XysV8o-5eKI/AAAAAAAAEXI/dPnA1tgXnNAlMZrArPMPpydaWKiZLbgrACLcBGAsYHQ/d/recurring%2Bblog%2Bimages_threat%2Broundup%25281%2529.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;    &lt;/div&gt;&lt;/div&gt;&lt;div cla12ss=&quot;threat-roundup-content&quot;&gt;&lt;p&gt;Today, Talos is publishing a glimpse into the most prevalent threats we&#39;ve observed between Nov. 5 and Nov. 12. As with previous roundups, this post isn&#39;t meant to be an in-depth analysis. Instead, this post will summarize the threats we&#39;ve observed by highlighting key behavioral characteristics, indicators of compromise, and discussing how our customers are automatically protected from these threats. &lt;/p&gt;&lt;p&gt;As a reminder, the information provided for the following threats in this post is non-exhaustive and current as of the date of publication. Additionally, please keep in mind that IOC searching is only one part of threat hunting. Spotting a single IOC does not necessarily indicate maliciousness. Detection and coverage for the following threats is subject to updates, pending additional threat or vulnerability analysis. For the most current information, please refer to your Firepower Management Center, &lt;a href=&quot;https://www.snort.org&quot;&gt;Snort.org&lt;/a&gt;, or &lt;a href=&quot;https://www.clamav.net&quot;&gt;ClamAV.net&lt;/a&gt;. &lt;/p&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;p&gt;For each threat described below, this blog post only lists 25 of the associated file hashes and up to 25 IOCs for each category. An accompanying JSON file can be found &lt;a href=&quot;https://talosintelligence.com/resources/322&quot; id=&quot;tru-report-json&quot;&gt;here&lt;/a&gt;that includes the complete list of file hashes, as well as all other IOCs from this post. A visual depiction of the MITRE ATT&amp;amp;CK techniques associated with each threat is also shown. In these images, the brightness of the technique indicates how prevalent it is across all threat files where dynamic analysis was conducted.  There are five distinct shades that are used, with the darkest indicating that no files exhibited technique behavior and the brightest indicating that technique behavior was observed from 75 percent or more of the files. &lt;/p&gt;&lt;p&gt;The most prevalent threats highlighted in this roundup are: &lt;/p&gt; &lt;table class=&quot;threats-table&quot;&gt;&lt;thead&gt;&lt;tr&gt;    &lt;th width=&quot;160px&quot;&gt;Threat Name&lt;/th&gt;    &lt;th width=&quot;80px&quot;&gt;Type&lt;/th&gt;    &lt;th&gt;Description&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt; &lt;tr&gt;&lt;td class=&quot;threat-name-col&quot;&gt;  Win.Dropper.Kuluoz-9906192-0 &lt;/td&gt;&lt;td&gt;    Dropper &lt;/td&gt;&lt;td&gt;    Kuluoz, sometimes known as &quot;Asprox,&quot; is a modular remote access trojan that is also known to download and execute follow-on malware, such as fake antivirus software. Kuluoz is often delivered via spam emails pretending to be shipment delivery notifications or flight booking confirmations. &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class=&quot;threat-name-col&quot;&gt;  Win.Trojan.Tofsee-9906687-1 &lt;/td&gt;&lt;td&gt;    Trojan &lt;/td&gt;&lt;td&gt;    Tofsee is multi-purpose malware that features a number of modules used to carry out various activities such as sending spam messages, conducting click-fraud, mining cryptocurrency, and more. Infected systems become part of the Tofsee spam botnet and are used to send large volumes of spam messages to infect additional systems and increase the size of the botnet under the operator&#39;s control. &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class=&quot;threat-name-col&quot;&gt;  Win.Dropper.Fareit-9906313-1 &lt;/td&gt;&lt;td&gt;    Dropper &lt;/td&gt;&lt;td&gt;    The Fareit trojan is primarily an information stealer that can download and install other malware. &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class=&quot;threat-name-col&quot;&gt;  Win.Dropper.Nymaim-9906679-0 &lt;/td&gt;&lt;td&gt;    Dropper &lt;/td&gt;&lt;td&gt;    Nymaim is malware that can be used to deliver ransomware and other malicious payloads. It uses a domain-generation algorithm to generate potential command and control (C2) domains to connect to additional payloads. &lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td class=&quot;threat-name-col&quot;&gt;  Win.Dropper.TrickBot-9906689-0 &lt;/td&gt;&lt;td&gt;    Dropper &lt;/td&gt;&lt;td&gt;    Trickbot is a banking trojan targeting sensitive information for certain financial institutions. This malware is frequently distributed through malicious spam campaigns. Many of these campaigns rely on downloaders for distribution, such as VBScripts. &lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt; &lt;hr class=&quot;thin&quot; /&gt; &lt;h2&gt;Threat Breakdown&lt;/h2&gt;         &lt;h3&gt;Win.Dropper.Kuluoz-9906192-0&lt;/h3&gt;     &lt;h4&gt;Indicators of Compromise&lt;/h4&gt;    &lt;ul&gt;&lt;li&gt;IOCs collected from dynamic analysis of 69 samples&lt;/li&gt;&lt;/ul&gt;              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Registry Keys&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCR&amp;gt;\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\SHELL\BAGS\159             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;69&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\&amp;lt;random, matching &#39;[a-zA-Z0-9]{5,9}&#39;&amp;gt;             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;69&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\XNDQWFAL                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: saalmdpq&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: vrdsuanh&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\UBKDDXHX                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: mdjrdtlb&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: dekjtufv&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\SXLEVULR                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: kmaxhebd&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: rhexocwd&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\CPLFEVDG                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: srslhwbv&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: oawidcqj&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\CPAGQABV                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: imlvmnbi&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: joocbsdq&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\BNTIPEWG                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: ueangwke&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: jgpdveiv&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\QTTISAMA                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: rnvaxhxh&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: qfhrdtpr&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\GNBKNCFN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: jnrqktqb&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: fwhpibmc&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\PQTDJSEE                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: rbcxmjse&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: tfoxxhqg&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\JRMMRSGV                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: bemwgapm&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: xrjbjxre&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\GWKSMKND                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: sdkabnue&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: wmrdbsbk&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\FVCPXDNG                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: cebigupq&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;        &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                    &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Mutexes&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;aaAdministrator&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;69&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;abAdministrator&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;69&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                             &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;IP Addresses contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;37[.]59[.]24[.]98&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;51&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;96[.]30[.]22[.]96&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;50&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;74[.]221[.]221[.]58&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;46&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;195[.]28[.]181[.]184&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;46&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;110[.]77[.]220[.]66&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;45&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;85[.]12[.]29[.]254&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;44&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;82[.]165[.]155[.]77&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;44&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;69[.]64[.]32[.]247&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;43&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                                     &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Files and or directories created&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%LOCALAPPDATA%\&amp;lt;random, matching &#39;[a-z]{8}&#39;&amp;gt;.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;69&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%HOMEPATH%\Local Settings\Application Data\efcggqxj.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                     &lt;h4&gt;File Hashes&lt;/h4&gt;    &lt;div class=&quot;code&quot;&gt;    &lt;code&gt;             000bea950f66052cf937547d1f18bc47a1c6ff6d2d7d03bc09d60aa9c9b1c770              00e8fa17d90f77afadd8f255dca53b15d7f4c91719452d616b0cf663f9aeea99              033755fcc85dad80db7a94ea2dc178dc2cc823fe7b46084fd0ed20645b593290              037e90d5a83ea1360c1c74b34e3d648ba8645b32d9de456756e8ba6acac86d6d              04c74fa81fdd718c985fde6a502f1ed93a0d34255dc21b546fcc25425da9f31e              086985abecc0ee9c6b4caa28e74d3190994dbddae40524eb955526ad5be9f067              08de3a669a95eab65d9b95ecf7ed4085e162badd7b11b3ad126be4d9836d33e4              1ba2d5d15ede307fa5a969eb66654f4d485fc144e370531451c43dc6409737d9              1f18d7fcd14fa41d8256a373437ccfd3e0d0d4f80c41daeda99cfd493735acc8              1fb1390e6f86cc5eb108a6a38484fa91baf867622e7384d4777b7b12215cab8c              27862adbd6ba16a82915102b7cfbf36f25c7be6b7e0464a7bcd731c9c5c67316              36971d72adc866b317be68ddf5b3471825049a81231b53c5cfdacb292d49b4d6              39781b0d4b88226ae7cc4711c9d4724ee9010e9f543be7fbd3d31564d89546dd              3a36245e815538d2f84d05af6b1d71f81dd9c284cac1c0ceb2145d9f1bb9a7e9              3ca7c310670af06b7e57e5317283e03c2aa630b72f2d99f93734d960bf19040b              40023d8e643d0c49199f1d34beb4c79856f30cc155ff8f93300b9cca70affb0c              410c8127cf6d7bac2cb13d84dd8415aabc5831bdb617b49e8d28d024db906c51              42ca7b17fa816bf7dfdee073fd077f2327e31ae15f386c087912757894e2ac0a              44837ce7705a1c03338d220d186564930bcb1e739af90f04cd415b37b5719b90              48179cd3f777d239fb1f14ac8ed1472dd8c9dec65414b92953b5d67faad4f9b7              50fd2544836d5623d86f94307583fe7a4c88b11cdaa84f3f6b5a03a8631e8c0a              64d3d27a53d3cde1729f8897a09aac19557121ede477e4a1d18a86ef33b2d675              656ee6200af32f34de24c591ebb45d5652f30a435ce84abb6c8c04cd91e07500              696629d6b4f9965ec8cf1cc9cefe973f907731e8c6fadd1189413d63f4390b30              6a338dd0339ab184d2fa547e4a05b6cf94632dc3a03fb351ca703cea3f7f2262          &lt;/code&gt;    &lt;/div&gt;             &lt;div class=&quot;threat-table-note&quot;&gt;*See JSON for more IOCs&lt;/div&gt;           &lt;h4&gt;Coverage&lt;/h4&gt;     &lt;table class=&quot;threat-coverage-table&quot;&gt;    &lt;thead&gt;        &lt;tr&gt;            &lt;th&gt;Product&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Protection&lt;/th&gt;        &lt;/tr&gt;    &lt;/thead&gt;    &lt;tbody&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Endpoint&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Cloudlock&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;CWS&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Email Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Network Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch Cloud&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Malware Analytics&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Umbrella&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;WSA&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;             &lt;/tbody&gt;    &lt;/table&gt;               &lt;h4&gt;Screenshots of Detection&lt;/h4&gt;              &lt;h4&gt;Secure Endpoint&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-oWnYh_5RNlI/YY65a5oHfNI/AAAAAAAAHaQ/SkBZAcKCVr4sY0WiXAcXGjGfGZ6bdo3bwCLcBGAsYHQ/s702/amp_656ee6200af32f34de24c591ebb45d5652f30a435ce84abb6c8c04cd91e07500_20211104.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;480&quot; data-original-width=&quot;702&quot; height=&quot;274&quot; src=&quot;https://1.bp.blogspot.com/-oWnYh_5RNlI/YY65a5oHfNI/AAAAAAAAHaQ/SkBZAcKCVr4sY0WiXAcXGjGfGZ6bdo3bwCLcBGAsYHQ/w400-h274/amp_656ee6200af32f34de24c591ebb45d5652f30a435ce84abb6c8c04cd91e07500_20211104.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;Secure Malware Analytics&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-V78RuMddVe0/YY65frmCW_I/AAAAAAAAHaU/2JO1ltqDhJ8iyobKyvHdJxAuFOG9PRPCQCLcBGAsYHQ/s962/tg_656ee6200af32f34de24c591ebb45d5652f30a435ce84abb6c8c04cd91e07500_20211104.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;499&quot; data-original-width=&quot;962&quot; height=&quot;332&quot; src=&quot;https://1.bp.blogspot.com/-V78RuMddVe0/YY65frmCW_I/AAAAAAAAHaU/2JO1ltqDhJ8iyobKyvHdJxAuFOG9PRPCQCLcBGAsYHQ/w640-h332/tg_656ee6200af32f34de24c591ebb45d5652f30a435ce84abb6c8c04cd91e07500_20211104.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;MITRE ATT&amp;amp;CK&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-kO2DBCKmpM4/YY65kXDF3kI/AAAAAAAAHaY/QmtOGUfFSHQL5tRQ9gXdklt0XbxJGM_JQCLcBGAsYHQ/s2020/mitre_attack_26771.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1259&quot; data-original-width=&quot;2020&quot; height=&quot;398&quot; src=&quot;https://1.bp.blogspot.com/-kO2DBCKmpM4/YY65kXDF3kI/AAAAAAAAHaY/QmtOGUfFSHQL5tRQ9gXdklt0XbxJGM_JQCLcBGAsYHQ/w640-h398/mitre_attack_26771.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;     &lt;hr class=&quot;thin&quot; /&gt;        &lt;h3&gt;Win.Trojan.Tofsee-9906687-1&lt;/h3&gt;     &lt;h4&gt;Indicators of Compromise&lt;/h4&gt;    &lt;ul&gt;&lt;li&gt;IOCs collected from dynamic analysis of 56 samples&lt;/li&gt;&lt;/ul&gt;              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Registry Keys&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKU&amp;gt;\.DEFAULT\CONTROL PANEL\BUSES                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Config4&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKU&amp;gt;\.DEFAULT\CONTROL PANEL\BUSES             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCR&amp;gt;\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\SHELL\BAGS\159             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Type&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Start&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: ErrorControl&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: DisplayName&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: WOW64&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: ObjectName&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Description&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKU&amp;gt;\.DEFAULT\CONTROL PANEL\BUSES                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Config0&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKU&amp;gt;\.DEFAULT\CONTROL PANEL\BUSES                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Config1&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKU&amp;gt;\.DEFAULT\CONTROL PANEL\BUSES                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Config2&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKU&amp;gt;\.DEFAULT\CONTROL PANEL\BUSES                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Config3&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\&amp;lt;random, matching &#39;[A-Z0-9]{8}&#39;&amp;gt;                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: ImagePath&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;35&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\ffbmdows&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;4&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\ccyjaltp&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;4&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\bbxizkso&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;4&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\vvrctemi&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;4&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\eealcnvr&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;3&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\qqmxozhd&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;3&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\ttparckg&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;3&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\xxtevgok&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;3&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\MICROSOFT\WINDOWS DEFENDER\EXCLUSIONS\PATHS                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: C:\Windows\SysWOW64\hhdofqyu&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;3&lt;/td&gt;        &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                           &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;IP Addresses contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;185[.]7[.]214[.]171&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;185[.]7[.]214[.]210&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;185[.]7[.]214[.]212&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;45[.]9[.]20[.]187&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;45[.]9[.]20[.]178/31&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;85[.]143[.]175[.]153&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;193[.]56[.]146[.]146&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;192[.]0[.]47[.]59&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;54&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;157[.]240[.]229[.]174&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;53&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;144[.]160[.]235[.]143&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;50&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;103[.]224[.]212[.]34&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;49&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;125[.]209[.]238[.]100&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;49&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;211[.]231[.]108[.]46&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;48&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;74[.]208[.]5[.]20&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;47&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;117[.]53[.]116[.]15&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;46&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;96[.]114[.]157[.]80&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;45&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;212[.]77[.]101[.]4&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;45&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;64[.]98[.]36[.]4&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;44&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;67[.]231[.]149[.]140&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;44&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;64[.]136[.]44[.]37&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;43&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;51[.]81[.]57[.]58&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;43&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;216[.]146[.]35[.]35&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;36&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;67[.]231[.]144[.]94&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;35&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;172[.]65[.]252[.]97&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;35&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;193[.]222[.]135[.]150&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;34&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                      &lt;div class=&quot;threat-table-note&quot;&gt;*See JSON for more IOCs&lt;/div&gt;                             &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Domain Names contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;249[.]5[.]55[.]69[.]bl[.]spamcop[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;249[.]5[.]55[.]69[.]cbl[.]abuseat[.]org&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;249[.]5[.]55[.]69[.]dnsbl[.]sorbs[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;249[.]5[.]55[.]69[.]in-addr[.]arpa&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;249[.]5[.]55[.]69[.]sbl-xbl[.]spamhaus[.]org&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;249[.]5[.]55[.]69[.]zen[.]spamhaus[.]org&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;microsoft-com[.]mail[.]protection[.]outlook[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;microsoft[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;www[.]google[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;quadoil[.]ru&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;aspmx[.]l[.]google[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;55&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;whois[.]arin[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;54&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;whois[.]iana[.]org&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;54&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;www[.]instagram[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;53&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;mail[.]h-email[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;50&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;al-ip4-mx-vip1[.]prodigy[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;50&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;mx1[.]naver[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;49&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;park-mx[.]above[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;49&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;mx1[.]hanmail[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;49&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;mx-aol[.]mail[.]gm0[.]yahoodns[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;48&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;naver[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;48&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;hanmail[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;47&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;mx00[.]mail[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;47&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;www[.]youtube[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;46&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;nate[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;46&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                      &lt;div class=&quot;threat-table-note&quot;&gt;*See JSON for more IOCs&lt;/div&gt;                             &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Files and or directories created&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%SystemRoot%\SysWOW64\config\systemprofile&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%SystemRoot%\SysWOW64\config\systemprofile:.repos&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%SystemRoot%\SysWOW64\&amp;lt;random, matching &#39;[a-z]{8}&#39;&amp;gt;&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;56&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\&amp;lt;random, matching &#39;[a-z]{8}&#39;&amp;gt;.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;52&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\wfowkckt.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;2&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\zsnzdsd.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\afpfty.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\atoaete.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\cvqcgvg.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\hdssxekb.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\gzkalibu.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\hzryxozg.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\cumtsjub.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\xtiinuar.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\fsbyzeqd.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\xhmzgbap.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\pqoybuzk.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\jwfcdiuh.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\lqaqej.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\msnqziid.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\uniuyny.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\xqbrczsl.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\vocogacp.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\uzjzns.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\yvgljtqn.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                      &lt;div class=&quot;threat-table-note&quot;&gt;*See JSON for more IOCs&lt;/div&gt;                    &lt;h4&gt;File Hashes&lt;/h4&gt;    &lt;div class=&quot;code&quot;&gt;    &lt;code&gt;             0116e2cc42cc67d4ee0fbd26b113a2883c9ef920dc84bb7ab622d1bf8851763f              02c7359dcb84754d1582eab7ef5f16938ee9cf88a83d150c1470a6b3b24bf31c              03fb15b85a5b40369f8e392427ea5f004447c90273b01ccbcbdff27d0fd5620b              0c4c84401bc57951c1add588817d96cae70469c0ad699b2c154855a730cf8afa              11bb33bf6c4dcf920e28a36b061353e87e314236faebe4563c3fa5c877230404              158001d30d5d3768e6fe0f1a1d7bf1ad0da65241a6f01196150b5cf8a52b9623              1d5f62d3687343709946d1bf46ed5e91b4659e376261a499722cf071d14a2e32              20db1c12886f165778eaabff78196c7166b43b18767d802373150408870b7d99              2a6ff1d92b275b5479f724cacbef20a3757227d7bf7f943c5a91609a370cf006              2aa24f0c26531e9222de7e2ce6f0453e0465a6545ac7accb5f9ffc1983fa4f9d              2ee90707f21676ebaf7e821bf02f24d56d1a7be273c8aa129eb60cacd09f19df              2fbb49dd038c61306b7c32663dcf6f6f5545b1538c90464c148980c69f4331b3              322f25513dc717ec609771e4988d5a962dd5b980bc4bf372d206ab991c092382              345af13820aaefd07456b97821b597c8c020c907541e25c32f304c4a1a3f324a              348d21e49e7bad86d434423c8052dd72bb27d9a9f43d6b2471a1063261c69c35              354f4a167b2bbdbdd1e8d36f26c4524f1454abb79e745c1a0a3945e9bb1ddeef              35b7bbf1581e93fad329c50307ae2f68964bf8866e437d308c56eda819acb8d7              40bfcd3518b19ded7d92a6930ab6e410002c333fe327044800599a95ee67e225              41f7a9f6f6ec0cd336288c833ba746c5d40dc7d49f3f5717e89d8dc74714d478              4de8148701b1fe0a054b13829fb3763a8645b6468463de3e38f33526307f9e8b              5d21753e0586d127c06cde17551bd702e449dfa8a4aca6ff1116251ff1fe7177              5e6fb10b614e5ea6832ca853f3c43c4943499ac63097fd57c980babf7e707cd4              5f5b0da28419c1a133e4949a129f2ae17db34fb3e64ce2c9dc84d91239c50082              5faa85eae77192413b213ae22e30a68a6e0b20e1c1d78a2663ed0c70a713be67              61cbe9585ff80a96da97ce3afcaccce268b72d089ba88abc417642aa3365dddf          &lt;/code&gt;    &lt;/div&gt;             &lt;div class=&quot;threat-table-note&quot;&gt;*See JSON for more IOCs&lt;/div&gt;           &lt;h4&gt;Coverage&lt;/h4&gt;     &lt;table class=&quot;threat-coverage-table&quot;&gt;    &lt;thead&gt;        &lt;tr&gt;            &lt;th&gt;Product&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Protection&lt;/th&gt;        &lt;/tr&gt;    &lt;/thead&gt;    &lt;tbody&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Endpoint&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Cloudlock&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;CWS&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Email Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Network Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch Cloud&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Malware Analytics&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Umbrella&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;WSA&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;             &lt;/tbody&gt;    &lt;/table&gt;               &lt;h4&gt;Screenshots of Detection&lt;/h4&gt;             &lt;h4&gt;Secure Endpoint&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-tMdGkQTbPbg/YY65y3YpTtI/AAAAAAAAHag/be4zXhCVZ-UFRCnDBcuJE3FszLle8WvUwCLcBGAsYHQ/s702/amp_f0d9e9883f20d6164924842460e44d8624a0ab0b7c33195f4da955fc97e20751_20211107.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;480&quot; data-original-width=&quot;702&quot; height=&quot;274&quot; src=&quot;https://1.bp.blogspot.com/-tMdGkQTbPbg/YY65y3YpTtI/AAAAAAAAHag/be4zXhCVZ-UFRCnDBcuJE3FszLle8WvUwCLcBGAsYHQ/w400-h274/amp_f0d9e9883f20d6164924842460e44d8624a0ab0b7c33195f4da955fc97e20751_20211107.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;Secure Malware Analytics&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-wtt8FqbcPTw/YY6559c0QuI/AAAAAAAAHao/RumgmXBRmL88Aofla7DB22yfBhdeykSbwCLcBGAsYHQ/s962/tg_f0d9e9883f20d6164924842460e44d8624a0ab0b7c33195f4da955fc97e20751_20211109.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;800&quot; data-original-width=&quot;962&quot; height=&quot;532&quot; src=&quot;https://1.bp.blogspot.com/-wtt8FqbcPTw/YY6559c0QuI/AAAAAAAAHao/RumgmXBRmL88Aofla7DB22yfBhdeykSbwCLcBGAsYHQ/w640-h532/tg_f0d9e9883f20d6164924842460e44d8624a0ab0b7c33195f4da955fc97e20751_20211109.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;MITRE ATT&amp;amp;CK&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-E_4renLoK8w/YY65_VQdwAI/AAAAAAAAHas/PwZrAx9juNMP5pojVxoNInuJm6oyhGJcwCLcBGAsYHQ/s2020/mitre_attack_26773.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1259&quot; data-original-width=&quot;2020&quot; height=&quot;398&quot; src=&quot;https://1.bp.blogspot.com/-E_4renLoK8w/YY65_VQdwAI/AAAAAAAAHas/PwZrAx9juNMP5pojVxoNInuJm6oyhGJcwCLcBGAsYHQ/w640-h398/mitre_attack_26773.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;          &lt;hr class=&quot;thin&quot; /&gt;        &lt;h3&gt;Win.Dropper.Fareit-9906313-1&lt;/h3&gt;     &lt;h4&gt;Indicators of Compromise&lt;/h4&gt;    &lt;ul&gt;&lt;li&gt;IOCs collected from dynamic analysis of 17 samples&lt;/li&gt;&lt;/ul&gt;              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Registry Keys&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\WINRAR             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCR&amp;gt;\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\SHELL\BAGS\159             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\WINRAR                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: HWID&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SAM\SAM\DOMAINS\ACCOUNT\USERS\000003E9                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: F&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SAM\SAM\DOMAINS\ACCOUNT\USERS\000001F5                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: F&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SAM\SAM\DOMAINS\ACCOUNT\USERS\000003EC                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: F&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;        &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                           &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;IP Addresses contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;192[.]187[.]111[.]219&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;7&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;63[.]141[.]242[.]46&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;4&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;81[.]17[.]18[.]194&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;3&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;81[.]17[.]29[.]146&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;3&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;209[.]85[.]201[.]94&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;173[.]194[.]204[.]94&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;101[.]99[.]75[.]152&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;74[.]125[.]192[.]138&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;173[.]194[.]206[.]100&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;209[.]85[.]144[.]99&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;173[.]194[.]205[.]84&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Domain Names contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;ru[.]agulino[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;wpad[.]example[.]org&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;2&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;computer[.]example[.]org&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;vmss-prod-weu[.]westeurope[.]cloudapp[.]azure[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;clientconfig[.]passport[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Files and or directories created&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\subfolder&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\subfolder\filename.bat&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\-&amp;lt;random, matching &#39;[0-9]{9}&#39;&amp;gt;.bat&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;17&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%HOMEPATH%\Start Menu\Programs\Startup\filename.vbe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\748562.bat&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\CrashDumps\506825654.exe.2384.dmp&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\WAXBDBC.tmp&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\WERBF82.tmp.appcompat.txt&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\WERBFB2.tmp.WERInternalMetadata.xml&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\WERCABC.tmp.WERInternalMetadata.xml&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\CrashDumps\506825708.exe.3876.dmp&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\WAX3C1E.tmp&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\WER3F0D.tmp.appcompat.txt&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\WER3F6C.tmp.WERInternalMetadata.xml&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                     &lt;h4&gt;File Hashes&lt;/h4&gt;    &lt;div class=&quot;code&quot;&gt;    &lt;code&gt;             03eee9c470a2987fe0a045530c2efd0bbbab9eeb5b91a893e682cf144e252107              18e5a593d4a89648b43f86383568469612c4f61d4b8361df299e1fdbe9ac42f5              34c862548b46506e25df6187be15486a2bc0de85b7e2b02b12745df7145faf5d              56d50fb071eb481a83ae011eb7a31fd6bee268fba1b0fe7aa880f6a108f9f682              5bdaafdaeb1ad0f8455de525022d95d40362d2766e78bd9eeecf7acf3426564e              666fdac0254a22535178f4cc056de7c43372359a1a9fc83c9b558770d278bc84              6be0f0991eebcdd021444994c3c812a89924b04b8ed27282e18b747305f27bf7              71ca1ab8c327e81b97f9b93684f6a2f8de7b194f4d20b65bad89660fdb04982c              94c9c78a6d2e0b1808bbbde2a69f32464c74c8ad0f902b0a7aea75d443db1866              9523e53935a018bbe2a297ba95578a7e988a0a402eed2a97cf46a41f797de971              9edb3091593479d03685b13b2eaa0104fb84bdc785c46cf70bb8e105e6589620              b46d16b74e5c430126372a5027108704074ebf5a87b1dc0634f41bc119b460dc              c94368d73c897f193f7dd20d749d2348fa80f818d19b27888c28bc8e41ccd262              d3873c324768de351219c9e50a33cecc3d15ab568064591ff9857fff86780c76              e0e0854a4bcd7bb49292b001954e76ea3aaa8639839073e35a72adf88e3a25cc              e1a572394b381e7ae7cca254ab171eb975f9e4e0be7480b01fb751be14712fe0              ea1c77d4d703fe6825dfa9e406b84375384719f21f3250b93cd3e7550c685bec          &lt;/code&gt;    &lt;/div&gt;           &lt;h4&gt;Coverage&lt;/h4&gt;     &lt;table class=&quot;threat-coverage-table&quot;&gt;    &lt;thead&gt;        &lt;tr&gt;            &lt;th&gt;Product&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Protection&lt;/th&gt;        &lt;/tr&gt;    &lt;/thead&gt;    &lt;tbody&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Endpoint&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Cloudlock&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;CWS&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Email Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Network Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch Cloud&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Malware Analytics&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Umbrella&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;WSA&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;             &lt;/tbody&gt;    &lt;/table&gt;               &lt;h4&gt;Screenshots of Detection&lt;/h4&gt;              &lt;h4&gt;Secure Endpoint&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-HbXjgb0XDEk/YY66TrnCvOI/AAAAAAAAHa4/cHOErPz3NqUs87Aeqo4zyPQi-QaH9BnTQCLcBGAsYHQ/s702/amp_56d50fb071eb481a83ae011eb7a31fd6bee268fba1b0fe7aa880f6a108f9f682_20211107.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;480&quot; data-original-width=&quot;702&quot; height=&quot;274&quot; src=&quot;https://1.bp.blogspot.com/-HbXjgb0XDEk/YY66TrnCvOI/AAAAAAAAHa4/cHOErPz3NqUs87Aeqo4zyPQi-QaH9BnTQCLcBGAsYHQ/w400-h274/amp_56d50fb071eb481a83ae011eb7a31fd6bee268fba1b0fe7aa880f6a108f9f682_20211107.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;Secure Malware Analytics&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-YIagyC5cATg/YY66YzHg2EI/AAAAAAAAHa8/UaNcj1MMgvQo91b6EsYg9Pgl3i-yp1zfwCLcBGAsYHQ/s962/tg_ea1c77d4d703fe6825dfa9e406b84375384719f21f3250b93cd3e7550c685bec_20211107.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;800&quot; data-original-width=&quot;962&quot; height=&quot;532&quot; src=&quot;https://1.bp.blogspot.com/-YIagyC5cATg/YY66YzHg2EI/AAAAAAAAHa8/UaNcj1MMgvQo91b6EsYg9Pgl3i-yp1zfwCLcBGAsYHQ/w640-h532/tg_ea1c77d4d703fe6825dfa9e406b84375384719f21f3250b93cd3e7550c685bec_20211107.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;MITRE ATT&amp;amp;CK&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-Kzp5_2FYF8k/YY66eQz6u7I/AAAAAAAAHbA/gkcvHzFZ1qYdRjMcPA2Mt2Ts1nji_b8FwCLcBGAsYHQ/s2020/mitre_attack_26775.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1259&quot; data-original-width=&quot;2020&quot; height=&quot;398&quot; src=&quot;https://1.bp.blogspot.com/-Kzp5_2FYF8k/YY66eQz6u7I/AAAAAAAAHbA/gkcvHzFZ1qYdRjMcPA2Mt2Ts1nji_b8FwCLcBGAsYHQ/w640-h398/mitre_attack_26775.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;               &lt;hr class=&quot;thin&quot; /&gt;        &lt;h3&gt;Win.Dropper.Nymaim-9906679-0&lt;/h3&gt;     &lt;h4&gt;Indicators of Compromise&lt;/h4&gt;    &lt;ul&gt;&lt;li&gt;IOCs collected from dynamic analysis of 23 samples&lt;/li&gt;&lt;/ul&gt;              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Registry Keys&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\GOCFK             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCU&amp;gt;\SOFTWARE\MICROSOFT\GOCFK                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: mbijg&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCR&amp;gt;\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\SHELL\BAGS\159             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;22&lt;/td&gt;        &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                    &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Mutexes&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{1181F583-B634-69BF-E703-D4756599024F}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{180BBEAD-0447-044A-68BD-247EB6D0E352}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{18DD7903-1E96-FEAF-92BF-014008A1248C}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{92502033-C012-7F46-D6A8-0AC972DF6662}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{25754F3F-7A37-56CA-31BB-3C9D33DA226B}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{8B75523D-CAF4-D06B-A2AD-13EEF593AC52}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{D2CC4CCA-CB77-CF10-8293-17C78DEC853F}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{67EB9FBC-0AC5-BAD6-80A0-015E2C7D43E8}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Local\{F78DA135-BD1C-3BA1-2EC7-6B375301FFDF}&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                                    &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Domain Names contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;microsoft[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;google[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;hkzqekcz[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;zrailjorqed[.]pw&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;nckynkrjg[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;xxrwudfhbr[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;iuojcbwlb[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;gjlngkx[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;nmovreiit[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;gpuxnhtdhztg[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;xpbyti[.]pw&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;nlaoyufe[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;syffllqlu[.]pw&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;phgrcrm[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;qbpqbucz[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;hdrqny[.]pw&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;emcqaelhfn[.]pw&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;www[.]msftncsi[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;4&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;wpad[.]example[.]org&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;4&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;neolx[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;rqdptmnlyy[.]pw&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;arlllswc[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;gjyttpvb[.]net&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;ytfalkcclaw[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;afoctlamhq[.]in&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                      &lt;div class=&quot;threat-table-note&quot;&gt;*See JSON for more IOCs&lt;/div&gt;                             &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Files and or directories created&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%ProgramData%\ph&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%ProgramData%\ph\fktiipx.ftf&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\gocf.ksv&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%ProgramData%\&amp;lt;random, matching &#39;[a-z0-9]{3,7}&#39;&amp;gt;&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\&amp;lt;random, matching &#39;[a-z0-9]{3,7}&#39;&amp;gt;&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%LOCALAPPDATA%\&amp;lt;random, matching &#39;[a-z0-9]{3,7}&#39;&amp;gt;&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;23&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%ProgramData%\jzk\icolry.ylg&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;5&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Users\user\AppData\Local\Temp\qnvgtx.eww&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;5&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\aneba.qsz&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;\Documents and Settings\All Users\wrg\orjdwj.ppt&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                     &lt;h4&gt;File Hashes&lt;/h4&gt;    &lt;div class=&quot;code&quot;&gt;    &lt;code&gt;             0a5a39e943850137bf7296a9b11e9af5c0e05e391c3381733cc2f03020208b12              1657415b3e51540e23ecb6fdc619978af4463ce9e9c880f5e4f0ef1558297040              1984124ab6ba6f3fdb04ff885408c9f4f35f22d8d07746ddd2a585cb412fde6a              2f9fd8377a8e7bfbe6b13198d578d06b883402a5084f6c1c5c4cdebabfbd8fce              305b0c43a3c29d6153f0636d77032debf4fceabc2c035d48268a09692ae6cd20              31181eee5991422042784e1f845d11a32e1381aea1d8009e7090d88393ba98bc              386f665bedb4efaef8d7c12d11e49d1fd488a5a2a543588762897fdc64caf858              3a95f93f80be8d0cd76705da445da77c1d498a8aba99ee222f8e451e81aa1454              3f438f5360c449ba9d1d9349c6a0fa2fcab962a89cdc16581ebc1fea79051768              51e01e124b5faa392ae3517603049fea41a5c13a6ec82aa3fc23c2db41961189              5395c7598ca1145728fe0ed9f2422bf8d7cdc5a4aefee9c66e9a4be014a39753              5d94592ee0b18888cec53c526984a7a2505c757b66d17986f3f237c3ac843c20              61753686a9b172316b339850fe425602122dadc8b9a880b6d8fe11a2061faf77              6300fa292145cb7ad0810ae32eb5742f3eb71fe36986eb15bc5bccf6a7c15b50              73f6323cdc4c439a7ee8626daf5a8219f5d2d91498acf3161abc8764e3150277              75df28107d722b325ca55f1639be556839b1ab5ae99256008edc8bcd469b30f8              84d6081d0a956de98053024cc863b23e15b842d6677a4ee22b00c5d63b10ee6b              a9c642d3899cf12cceff9fef3c83a36794b6ccb6539c8a778b0809ecc74ee6ce              b28275a44a8d9a4e8ac0740384d48df297fd59b12d6c0a22c74256bc6cbc4cb5              d91e71f0ccf719c2242aa8ffa03d675ce6c536c50b5da571f6ae87f1076c7c9b              dad54799bb4ffc4866978c7c655eae50bb1274b586dcf194f3fd64863d301e84              de1c74e3225d1170fa8494b327b2944b7e31968f4f5fedf17390ead6f3fd7691              f79946e8464c138f028b3d4ce15f04579b16600f49680a5e53a1c99ffae31007          &lt;/code&gt;    &lt;/div&gt;           &lt;h4&gt;Coverage&lt;/h4&gt;     &lt;table class=&quot;threat-coverage-table&quot;&gt;    &lt;thead&gt;        &lt;tr&gt;            &lt;th&gt;Product&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Protection&lt;/th&gt;        &lt;/tr&gt;    &lt;/thead&gt;    &lt;tbody&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Endpoint&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Cloudlock&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;CWS&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Email Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Network Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch Cloud&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Malware Analytics&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Umbrella&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;WSA&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;             &lt;/tbody&gt;    &lt;/table&gt;               &lt;h4&gt;Screenshots of Detection&lt;/h4&gt;             &lt;h4&gt;Secure Endpoint&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-cc_5ZwH_rJY/YY66vAdAqyI/AAAAAAAAHbQ/BM5D38WNZgUlot7d873zJYIw96f4RX0WwCLcBGAsYHQ/s702/amp_305b0c43a3c29d6153f0636d77032debf4fceabc2c035d48268a09692ae6cd20_20211109.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;480&quot; data-original-width=&quot;702&quot; height=&quot;274&quot; src=&quot;https://1.bp.blogspot.com/-cc_5ZwH_rJY/YY66vAdAqyI/AAAAAAAAHbQ/BM5D38WNZgUlot7d873zJYIw96f4RX0WwCLcBGAsYHQ/w400-h274/amp_305b0c43a3c29d6153f0636d77032debf4fceabc2c035d48268a09692ae6cd20_20211109.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;Secure Malware Analytics&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-7OtiUuKmtO4/YY660h3x_yI/AAAAAAAAHbU/ARmRe-YZCuwHx0PFbOV48MXet0A8IHyZwCLcBGAsYHQ/s962/tg_305b0c43a3c29d6153f0636d77032debf4fceabc2c035d48268a09692ae6cd20_20211109.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;721&quot; data-original-width=&quot;962&quot; height=&quot;480&quot; src=&quot;https://1.bp.blogspot.com/-7OtiUuKmtO4/YY660h3x_yI/AAAAAAAAHbU/ARmRe-YZCuwHx0PFbOV48MXet0A8IHyZwCLcBGAsYHQ/w640-h480/tg_305b0c43a3c29d6153f0636d77032debf4fceabc2c035d48268a09692ae6cd20_20211109.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;MITRE ATT&amp;amp;CK&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-Zm2ySEZ8XJA/YY667FgufcI/AAAAAAAAHbY/ji9bXN5MbCE3Gw9H9w-kYWCGaSzZ2szFQCLcBGAsYHQ/s2020/mitre_attack_26777.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1259&quot; data-original-width=&quot;2020&quot; height=&quot;398&quot; src=&quot;https://1.bp.blogspot.com/-Zm2ySEZ8XJA/YY667FgufcI/AAAAAAAAHbY/ji9bXN5MbCE3Gw9H9w-kYWCGaSzZ2szFQCLcBGAsYHQ/w640-h398/mitre_attack_26777.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;          &lt;hr class=&quot;thin&quot; /&gt;        &lt;h3&gt;Win.Dropper.TrickBot-9906689-0&lt;/h3&gt;     &lt;h4&gt;Indicators of Compromise&lt;/h4&gt;    &lt;ul&gt;&lt;li&gt;IOCs collected from dynamic analysis of 26 samples&lt;/li&gt;&lt;/ul&gt;              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Registry Keys&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: DisableAntiSpyware&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\WINDEFEND                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: DeleteFlag&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SYSTEM\CONTROLSET001\SERVICES\WINDEFEND                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: Start&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER\REAL-TIME PROTECTION                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: DisableBehaviorMonitoring&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER\REAL-TIME PROTECTION                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: DisableIOAVProtection&lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER\REAL-TIME PROTECTION             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER\REAL-TIME PROTECTION                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: DisableOnAccessProtection &lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKLM&amp;gt;\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER\REAL-TIME PROTECTION                          &lt;br /&gt;            &lt;span style=&quot;padding-left: 20px;&quot;&gt;Value Name: DisableScanOnRealtimeEnable &lt;/span&gt;            &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;        &lt;td&gt;&lt;code&gt;&amp;lt;HKCR&amp;gt;\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\SHELL\BAGS\159             &lt;/code&gt;        &lt;/td&gt;        &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;        &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                    &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Mutexes&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;Global\316D1C7871E10&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                             &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;IP Addresses contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;72[.]22[.]185[.]200&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;15&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;72[.]22[.]185[.]208&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;9&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;160[.]72[.]43[.]240&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;1&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Domain Names contacted by malware. Does not indicate maliciousness&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;crl[.]microsoft[.]com&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                              &lt;table class=&quot;threat-breakdown-table&quot;&gt;        &lt;thead&gt;        &lt;tr&gt;            &lt;th style=&quot;width: 600px;&quot;&gt;Files and or directories created&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Occurrences&lt;/th&gt;        &lt;/tr&gt;        &lt;/thead&gt;        &lt;tbody&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2580483871-590521980-3826313501-500\a18ca4003deb042bbee7a40f15e1970b_d19ab989-a35f-4710-83df-7b2db7efe7c5&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%ProgramData%\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_d19ab989-a35f-4710-83df-7b2db7efe7c5&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%System32%\Tasks\Windows Network&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\wnetwork&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\wnetwork\Data&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%APPDATA%\WNETWORK\&amp;lt;original file name&amp;gt;.exe&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;25&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%System32%\Microsoft\Protect\S-1-5-18\User\496a850c-d71a-4ccc-b3de-e64e84a540af&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;18&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%System32%\Microsoft\Protect\S-1-5-18\User\13022768-a353-4a4c-8032-ece2f429bad3&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;7&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\&amp;lt;random, matching &#39;[a-f0-9]{3,5}&#39;&amp;gt;_appcompat.txt&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;7&lt;/td&gt;            &lt;/tr&gt;                     &lt;tr&gt;            &lt;td&gt;&lt;code&gt;%TEMP%\&amp;lt;random, matching &#39;[A-F0-9]{4,5}&#39;&amp;gt;.dmp&lt;/code&gt;&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;7&lt;/td&gt;            &lt;/tr&gt;                 &lt;/tbody&gt;        &lt;/table&gt;                     &lt;h4&gt;File Hashes&lt;/h4&gt;    &lt;div class=&quot;code&quot;&gt;    &lt;code&gt;             0205f7cb31c95adeab976245edd2808d58a066e39f8bc953a3e10347189f61ca              0295aa15b36df5df2c8beba2e056a50efe5a88bcc8d07adefaf262a54d27ac18              0ec324720fb6f0af3f230556949689f2fee2ecd529c8a513c7f12c096eae0758              157958a490ec7591a3318c783691ce26e8f525f5c88367341cbfa5aca577586e              1a3cd06480513c10bd6c487e9bb015111ec4e17bfe26312f769233ab7e22f7f7              2413d734d5844c4bda1641d3a06669c6918f22308f45fef63e0b3a3d32c815a6              342477e56614066942a58b31dfb00f2dbaddc041738bde17bb701eb7c2a6c012              442cf13192bc89185839b955a2a21f6a16a1ca028208cb332f930a33367e2814              4bb1d3c102a9319ee88afed519dea172735f763b55859085ca0a145ceeee6b82              54eec51d0cc063797c45dc68f4a0b4376246893b8c799cabaa62be3b288947b7              586126be0b9bf36790dfbd9dea8ceb927df1d4c94745c306e93062aec647b0b0              6086f48f02196b9db367b87819e0d4b8ecc381971c63fde3b8dbb871341a2e5a              7fc8d238f3ff3bd7d77e18111763ac554c2d289643dc077b2253f8ee1d575926              94b83154ffbc39c28cd5a461ad264bb5cea73822d7d1a4ca5471a6ff8b28569c              967366fbebcf26142423b0df333ea09ae01cc728d5ab54edbcd387030afcccde              a36b2cac421b101c599d704dd66407e652cc056e9d58abf52d46b5f8b23f20f1              a3bf700a4f33a7852820daa9d580c2e9f8a9e21e04670212d64a9a4884ae065c              a412aa575f67c189ea62191942acbe30db28548f2a900019c8a3368ce8d3ec81              ba1ff4f69508562ea2c62a39861c7281176b979e200d1ebb95e32338f936a490              bc775c4705a8724ff10e0a946b510017c5e762ea1877a22a1897db34a1e6fabe              c082233374ed32db6a234c6901cda079466eb9e0746a07c4625c1e68d2ffbccc              c4c1ced7f088f61260705540b870ffe4e33af54ef4a1e86f1ef5729ef349bb75              cd133a17f8aeaa36f510595c5fc11e22fb40fbb88150fab1971d1094e75e7611              d294e9b17cbda134bfe607cc2e214d2c689c582bc7a94f24588df028814bd928              d32532cc718758d511caf22a6238049d422c0e12b60a0146a845e760b34e2d1a          &lt;/code&gt;    &lt;/div&gt;             &lt;div class=&quot;threat-table-note&quot;&gt;*See JSON for more IOCs&lt;/div&gt;           &lt;h4&gt;Coverage&lt;/h4&gt;     &lt;table class=&quot;threat-coverage-table&quot;&gt;    &lt;thead&gt;        &lt;tr&gt;            &lt;th&gt;Product&lt;/th&gt;            &lt;th class=&quot;text-center&quot;&gt;Protection&lt;/th&gt;        &lt;/tr&gt;    &lt;/thead&gt;    &lt;tbody&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Endpoint&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Cloudlock&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;CWS&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Email Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Network Security&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Stealthwatch Cloud&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Secure Malware Analytics&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         &lt;img alt=&quot;This has coverage&quot; src=&quot;https://www.talosintelligence.com/assets/icon_check_white.svg&quot; /&gt;                                     &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;Umbrella&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;                 &lt;tr&gt;            &lt;td&gt;WSA&lt;/td&gt;            &lt;td class=&quot;text-center&quot;&gt;                &lt;span class=&quot;coverage-check&quot;&gt;                                         N/A                                      &lt;/span&gt;            &lt;/td&gt;        &lt;/tr&gt;             &lt;/tbody&gt;    &lt;/table&gt;               &lt;h4&gt;Screenshots of Detection&lt;/h4&gt;             &lt;h4&gt;Secure Endpoint&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-FiV45a8hddw/YY67Hz0JkSI/AAAAAAAAHbg/xgKvW1MVR_EEMRnIyHSgzSvxeZJekyrzACLcBGAsYHQ/s702/amp_bc775c4705a8724ff10e0a946b510017c5e762ea1877a22a1897db34a1e6fabe_20211109.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;480&quot; data-original-width=&quot;702&quot; height=&quot;274&quot; src=&quot;https://1.bp.blogspot.com/-FiV45a8hddw/YY67Hz0JkSI/AAAAAAAAHbg/xgKvW1MVR_EEMRnIyHSgzSvxeZJekyrzACLcBGAsYHQ/w400-h274/amp_bc775c4705a8724ff10e0a946b510017c5e762ea1877a22a1897db34a1e6fabe_20211109.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;Secure Malware Analytics&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-dBendpLKicY/YY67MShNLaI/AAAAAAAAHbo/3aqEP9RFD2oHTGEi5q3snYHuTmeSrHj-wCLcBGAsYHQ/s962/tg_a36b2cac421b101c599d704dd66407e652cc056e9d58abf52d46b5f8b23f20f1_20211109.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;800&quot; data-original-width=&quot;962&quot; height=&quot;532&quot; src=&quot;https://1.bp.blogspot.com/-dBendpLKicY/YY67MShNLaI/AAAAAAAAHbo/3aqEP9RFD2oHTGEi5q3snYHuTmeSrHj-wCLcBGAsYHQ/w640-h532/tg_a36b2cac421b101c599d704dd66407e652cc056e9d58abf52d46b5f8b23f20f1_20211109.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;             &lt;h4&gt;MITRE ATT&amp;amp;CK&lt;/h4&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-OAGcUNfLVBU/YY67RnrB96I/AAAAAAAAHbs/T9fn-jtByygwekIJyp0gbnuzXKEsIjgbgCLcBGAsYHQ/s2020/mitre_attack_26779.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1259&quot; data-original-width=&quot;2020&quot; height=&quot;398&quot; src=&quot;https://1.bp.blogspot.com/-OAGcUNfLVBU/YY67RnrB96I/AAAAAAAAHbs/T9fn-jtByygwekIJyp0gbnuzXKEsIjgbgCLcBGAsYHQ/w640-h398/mitre_attack_26779.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;                &lt;hr class=&quot;thin&quot; /&gt;   &lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.talosintelligence.com/feeds/8138324693781507974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.talosintelligence.com/2021/11/threat-roundup-1105-1112.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/8138324693781507974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/8138324693781507974'/><link rel='alternate' type='text/html' href='http://blog.talosintelligence.com/2021/11/threat-roundup-1105-1112.html' title='Threat Roundup for November 5 to November 12'/><author><name>William Largent</name><uri>http://www.blogger.com/profile/12206979422726316011</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/-CJVRIdPek0Q/Vg1SP2sEdRI/AAAAAAAAAC8/rnWxyiZYOek/s220/BlogSize.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://1.bp.blogspot.com/-NKUlpGEjBF4/XysV8o-5eKI/AAAAAAAAEXI/dPnA1tgXnNAlMZrArPMPpydaWKiZLbgrACLcBGAsYHQ/s72-c-d/recurring%2Bblog%2Bimages_threat%2Broundup%25281%2529.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-4167372872904812250</id><published>2021-11-12T11:37:00.004-05:00</published><updated>2021-11-12T11:37:49.757-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Features"/><category scheme="http://www.blogger.com/atom/ns#" term="podcasts"/><category scheme="http://www.blogger.com/atom/ns#" term="Talos Takes"/><title type='text'>Talos Takes Ep. #76: What is Kimsuky phishing around for?</title><content type='html'>&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhS1PNrOhC4a-SiBdqigSnQFlcfiMIw7IoJMMAvCQul2JNKnjAN30rB5td9_5UYj2LJp6UpBtM7STLNncMfHuU6yqN7sqyXzFDY3mAbxmvQqphrNb_11ilFbCowAhcMo1ppwI0uyAwUDC8llxCl_PEW_Fyn7cvQ5aX2T7-w7UglRQifafGMGrbyV3iJ=s1200&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;676&quot; data-original-width=&quot;1200&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhS1PNrOhC4a-SiBdqigSnQFlcfiMIw7IoJMMAvCQul2JNKnjAN30rB5td9_5UYj2LJp6UpBtM7STLNncMfHuU6yqN7sqyXzFDY3mAbxmvQqphrNb_11ilFbCowAhcMo1ppwI0uyAwUDC8llxCl_PEW_Fyn7cvQ5aX2T7-w7UglRQifafGMGrbyV3iJ=s16000&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;By Jon Munshaw.&lt;/i&gt;&lt;/p&gt;&lt;p&gt;The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit the&amp;nbsp;&lt;a href=&quot;https://talosintelligence.com/podcasts/shows/talos_takes&quot; target=&quot;_blank&quot;&gt;Talos Takes page&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Blog posts aren&#39;t just for sharing your darkest secrets from high school anymore. They&#39;re also used by attackers to spread malware and steal international secrets. &lt;span&gt;&lt;/span&gt;&lt;/p&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;On this week&#39;s episode of Talos Takes, Asheer Malhotra, part of the research team who recently discovered a campaign from the Kimsuky state-sponsored actor, joins us to talk about a recent campaign that had some pretty high stakes. Kimsuky, a known APT out of North Korea, recently used a series of fake blog posts to spread malware to high-profile targets in South Korea.&lt;p&gt;&lt;/p&gt;&lt;p&gt;Asheer discusses what information the attackers may have been after, how they infected victims, exactly, and how to detect future bad blog posts.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class=&quot;button-link&quot; href=&quot;https://podcasts.apple.com/us/podcast/talos-takes/id1497572268&quot; target=&quot;_blank&quot;&gt;&lt;button class=&quot;blog-podcast-button&quot;&gt;&lt;img alt=&quot;Apple Podcasts&quot; src=&quot;https://www.talosintelligence.com/assets/icon_apple_podcasts_orange.svg&quot; title=&quot;Apple Podcasts&quot; /&gt;Apple Podcasts&amp;nbsp;&lt;/button&gt;&lt;/a&gt;&lt;a class=&quot;button-link&quot; href=&quot;https://open.spotify.com/show/2sZqrFXR3RupDqwXJM7kve&quot; target=&quot;_blank&quot;&gt;&lt;button class=&quot;blog-podcast-button&quot;&gt;&lt;img alt=&quot;Spotify&quot; src=&quot;https://www.talosintelligence.com/assets/icon_spotify_orange.svg&quot; title=&quot;Spotify&quot; /&gt;Spotify&amp;nbsp;&lt;/button&gt;&lt;/a&gt;&lt;a class=&quot;button-link&quot; href=&quot;https://www.stitcher.com/show/talos-takes&quot; target=&quot;_blank&quot;&gt;&lt;button class=&quot;blog-podcast-button&quot;&gt;&lt;img alt=&quot;Stitcher&quot; src=&quot;https://www.talosintelligence.com/assets/icon_stitcher_orange.svg&quot; title=&quot;Stitcher&quot; /&gt;&amp;nbsp;Stitcher&lt;/button&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.talosintelligence.com/feeds/4167372872904812250/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.talosintelligence.com/2021/11/talos-takes-ep-76-what-is-kimsuky.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/4167372872904812250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/posts/default/4167372872904812250'/><link rel='alternate' type='text/html' href='http://blog.talosintelligence.com/2021/11/talos-takes-ep-76-what-is-kimsuky.html' title='Talos Takes Ep. #76: What is Kimsuky phishing around for?'/><author><name>Jon Munshaw</name><uri>http://www.blogger.com/profile/13414456218583234191</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEhS1PNrOhC4a-SiBdqigSnQFlcfiMIw7IoJMMAvCQul2JNKnjAN30rB5td9_5UYj2LJp6UpBtM7STLNncMfHuU6yqN7sqyXzFDY3mAbxmvQqphrNb_11ilFbCowAhcMo1ppwI0uyAwUDC8llxCl_PEW_Fyn7cvQ5aX2T7-w7UglRQifafGMGrbyV3iJ=s72-c" height="72" width="72"/><thr:total>0</thr:total></entry></feed>