MSIX With Heavily Obfuscated PowerShell Script, (Fri, Feb 9th)

A few months ago, we saw waves of MSIX malicious packages&#;x26;#;x5b;1&#;x26;#;x5d; dropping malware once installed on victim&#;x26;#;39;s computers. I started to hunt for such files and saw a big decrease in interesting hints. Today, my YARA rule triggered a new sample. Called “Rabby-Wallet.msix”, the file has a VT score of 8/58&#;x26;#;x5b;2&#;x26;#;x5d;

Continue reading MSIX With Heavily Obfuscated PowerShell Script, (Fri, Feb 9th)

Posted in Uncategorized

Internet Storm Center Podcast (“Stormcast”) 15th Birthday, (Fri, Feb 9th)

Happy Birthday to our daily Podcast. 3,685 episodes, about 410 hours or 17 days of content. I hope you are enjoying it. Please do me a favor and participate in our quick two-question survey to help me improve the podcast. It will remain brief and no-frills. But is there any content I should emphasize? Are there any stories I missed or should not have included? Let me know.

Continue reading Internet Storm Center Podcast (“Stormcast”) 15th Birthday, (Fri, Feb 9th)

Posted in Uncategorized

A Python MP3 Player with Builtin Keylogger Capability, (Thu, Feb 8th)

I don&#;x26;#;39;t know if there is a trend but I recently found some malicious Python scripts (targeting Windows hosts) that include a GUI. They don&#;x26;#;39;t try to hide from the victim but, on the opposite, they try to make them confident. One example was the game[1] combined with an infostealer.

Continue reading A Python MP3 Player with Builtin Keylogger Capability, (Thu, Feb 8th)

Posted in Uncategorized

Anybody knows that this URL is about? Maybe Balena API request?, (Wed, Feb 7th)

Yesterday, I noticed a new URL in our honeypots: /v5/device/heartbeat. But I have no idea what this URL may be associated with. Based on some googleing, I came across Balena, a platform to manage IoT devices [1]. Does anybody have any experience with this software and know what an attacker would attempt to gain from the URL above? Maybe just fingerprinting devices? I do not see recent vulnerabilities anywhere, but there is a good chance that vulnerable components are being used by the software.

Continue reading Anybody knows that this URL is about? Maybe Balena API request?, (Wed, Feb 7th)

Posted in Uncategorized