Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile
Emanuele De Lucia

@manu_de_lucia

#DFIR #CTI #REM #APT

ID: 977272715500498951

linkhttps://www.emanueledelucia.net/ calendar_today23-03-2018 19:55:46

611 Tweet

2,2K Takipçi

229 Takip Edilen

Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile Photo

Looks like #Amadey #AmadeyLoader added exclusion for #CIS Countries in 4.30 on both the panel and loader. Maybe there really is someone who believes that their creations are usually used for good and feels the need to include countermeasures md5:1596ee7e65daddbde81639b512266192

Looks like #Amadey #AmadeyLoader added exclusion for #CIS Countries in 4.30 on both the panel and loader. Maybe there really is someone who believes that their creations are usually used for good and feels the need to include countermeasures
md5:1596ee7e65daddbde81639b512266192
Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile Photo

few #powershell lines to deobfuscate #batch files obfuscated via #skyemie obfuscator #malware #italy #malspam emanueledelucia.net/unveiling-obfu…

Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile Photo

Latest #malware samples linked to #nitrogen campaigns appear to share code similarities with the recently discovered ransomware #lukalocker. Nitrogen previously delivered #ALPHV / #BlackCat. Potential proprietary development of BlackCat's former affiliates.

Latest #malware samples linked to #nitrogen campaigns appear to share code similarities with the recently discovered ransomware #lukalocker. Nitrogen previously delivered #ALPHV / #BlackCat. Potential proprietary development of BlackCat's former affiliates.
Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile Photo

If they keep doing it, it means it's working. Be careful of #virgilio #italy #phishing #credentialtheft... zip -> pdf -> URL -> #fake login

If they keep doing it, it means it's working. Be careful of #virgilio #italy #phishing #credentialtheft... zip -> pdf -> URL -> #fake login
Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile Photo

I tried to have a look inside the #wiper #malware previously reported (by Kevin and Costin) below 👇 My personal speculations lead me to think of #TA402 but very uncertainly. emanueledelucia.net/hey-eset-wait-…

Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile Photo

#Agcom #PiracyShield #Google. Si parla molto di #whitelist ma cosa sono davvero e quanto è complicato applicarle ad un sistema complesso ? Da dove si parte solitamente per evitare blocchi accidentali ? Ho approfondito l'argomento nel mio blog personale: emanueledelucia.net/whitelist-di-s…

Emanuele De Lucia (@manu_de_lucia) 's Twitter Profile Photo

#Fortinet #FortiGate #Belsen #Dataleak impatto, in percentuale, per settori su #Italia - Da notare che dalla presunta vulnerabilità sfruttata (CVE-2022–40684) al rilascio di questo archivio sono passati anni. Da quanto tempo i cattivi avevano questi dati ?

#Fortinet #FortiGate #Belsen #Dataleak impatto, in percentuale, per settori su #Italia - Da notare che dalla presunta vulnerabilità sfruttata (CVE-2022–40684) al rilascio di questo archivio sono passati anni. Da quanto tempo i cattivi avevano questi dati ?
francescofaenzi (@francescofaenzi) 's Twitter Profile Photo

What can go wrong? VanHelsing ransomware builder leaked on hacking forum + Curated prompts for Jules, an async coding agent from Google Labs (or Codex, or Devin, choose yours). github.com/google-labs-co… x.com/Manu_De_Lucia/… #TrustEverybodyButCutTheCards