
PeterM🌻
@altshiftprtscn
Work in DFIR, fighting the good fight. Don't go 5 minutes without saying ransomware.
Created as a failsafe: infosec.exchange/@AltShiftPrtScn
ID: 888301897836367872
http://sophos.com/rapidresponse 21-07-2017 07:37:31
1,1K Tweet
2,2K Followers
102 Following










#HuntersInternational IOCs - Cobalt: virustotal.com/gui/ip-address… & virustotal.com/gui/ip-address…, Other C2s: virustotal.com/gui/ip-address… & virustotal.com/gui/ip-address…. Rclone->SFTP: virustotal.com/gui/ip-address…. Filnames include vmware.exe, vmware.dll, vm.dll in ProgramData and Windows\Temp.








Another great article full of technical info!👏 Great job by Morgan Demboski and security_dumpster as always for this blog! Chinese State-sponsored TAs have become the punching bag for Sophos this year lol 😂 It inspired me to illustrate how they must be feeling right now😆🎬👇

