Advertisement Β· 728 Γ— 90

Posts by Xavier Mertens πŸ‡§πŸ‡ͺ

ISC Logo

ISC Logo

Python Bot Delivered Through DLL Side-Loading https://isc.sans.edu/diary/31778

1 year ago 2 4 0 0

Great talk! πŸ₯³

1 year ago 1 0 0 0

Good morning from #Insomnihack! I’m here today, ping me if you want to meet!

1 year ago 2 0 0 0
ISC Logo

ISC Logo

Shellcode Encoded in UUID's https://isc.sans.edu/diary/31752

1 year ago 0 5 0 0
Post image

Njrat Campaign Using Microsoft Dev Tunnels isc.sans.edu/diary/31724
#SANSISC

1 year ago 0 0 0 0

Every once in a while you come across interesting PE Section names

Hello
Guy!

www.virustotal.com/gui/file/051...

1 year ago 8 2 1 1
Preview
XWorm Cocktail:οΏ½ A Mix of PE data with PowerShell Code - SANS Internet Storm Center

XWorm Cocktail:Β  A Mix of PE data with PowerShell Code isc.sans.edu/diary/31700 #SANSISC

1 year ago 0 0 0 0
Preview
You've Got Malware: FINALDRAFT Hides in Your Drafts β€” Elastic Security Labs During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and backdoor with many features including using...

Monday morning reading with your 0xC0FFEE:
www.elastic.co/security-lab...

1 year ago 0 1 0 0
Preview
The Danger of IP Volatility - SANS Internet Storm Center The Danger of IP Volatility, Author: Xavier Mertens

The Danger of IP Volatility isc.sans.edu/diary/31688 #SANSISC

1 year ago 0 1 0 0
ISC Logo

ISC Logo

Fake BSOD Delivered by Malicious Python Script https://isc.sans.edu/diary/31686

1 year ago 2 3 0 0
Advertisement

Following back!

1 year ago 1 0 0 0

The Unbreakable Multi-Layer Anti-Debugging System isc.sans.edu/diary/31658

1 year ago 0 0 0 0
https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/

Be honest… we all do that… taking screenshots of important information! Be careful and don’t keep them for a long time! #InfoStealer #Malware #OCR

t.co/cjI7gNLkW5

1 year ago 0 0 0 0
ISC Logo

ISC Logo

From PowerShell to a Python Obfuscation Race! https://isc.sans.edu/diary/31634

1 year ago 1 1 0 0
ISC Logo

ISC Logo

Fileless Python InfoStealer Targeting Exodus https://isc.sans.edu/diary/31630

1 year ago 0 1 0 0
Post image

Let’s wrap up the week with the malware analysis tournament! Wanna join the fun? My next class is in March in London #FOR610 #SANSEMEA

1 year ago 1 0 0 0

Make Malware Happy isc.sans.edu/diary/31560 #SANSISC

1 year ago 1 0 0 0
Preview
SwaetRAT Delivery Through Python - SANS Internet Storm Center SwaetRAT Delivery Through Python, Author: Xavier Mertens

SwaetRAT Delivery Through Python isc.sans.edu/diary/31554

1 year ago 0 0 0 0
Advertisement
Preview
More SSH Fun! - SANS Internet Storm Center More SSH Fun!, Author: Xavier Mertens

More SSH Fun! isc.sans.edu/diary/31542

1 year ago 1 0 0 0
Preview
Modiloader From Obfuscated Batch File - SANS Internet Storm Center Modiloader From Obfuscated Batch File, Author: Xavier Mertens

Modiloader From Obfuscated Batch File isc.sans.edu/diary/31540

1 year ago 1 0 0 0
Preview
Christmas Christmas "Gift" Delivered Through SSH, Author: Xavier Mertens

Christmas "Gift" Delivered Through SSH isc.sans.edu/diary/31538

1 year ago 0 0 0 0

Interesting read: Windows Server 2022 and MsMpEng.exe www.hexacorn.com/blog/2024/12...

1 year ago 1 1 0 0
Preview
Python Delivering AnyDesk Client as RAT - SANS Internet Storm Center Python Delivering AnyDesk Client as RAT, Author: Xavier Mertens

Python Delivering AnyDesk Client as RAT isc.sans.edu/diary/31524

1 year ago 3 0 0 0

Is it me or the price of printer cartridges became really insane? @HP has a business more lucrative than #ransomware gangs! Hey Bad Guys, move to the printer business! πŸ‘Ώ

1 year ago 0 0 0 0

β€œI see coins everywhere!” 😍

1 year ago 0 0 0 0
Post image

Cyber Defense #Netwars running at full speed in Frankfurt! #SANSEMEA

1 year ago 1 0 0 0
Post image

Full set of Belgian speakers at SANS@Night in Frankfurt tonight! πŸ‡§πŸ‡ͺ The room was full! So exciting! #SANSEMEA

1 year ago 3 0 0 0
Post image

My last #FOR610 run for this year! Welcome Frankfurt!

1 year ago 4 0 0 0
Advertisement
Preview
From a Regular Infostealer to its Obfuscated Version - SANS Internet Storm Center From a Regular Infostealer to its Obfuscated Version, Author: Xavier Mertens

From a Regular Infostealer to its Obfuscated Version isc.sans.edu/diary/31484 #SANSISC

1 year ago 1 0 0 0
Post image

Some attackers look like #scriptkiddies and need a GUI πŸ˜† #Ransomware

1 year ago 0 0 0 0