Suspicious Prometei Botnet Activity, (Sun, Jan 7th)

On the 31 Dec 2023, after trying multiple username/password combination, actor using IP 194.30.53.68 successfully loging to the honeypot and uploaded eight files where 2 of them are protected with a 7zip password (updates1.7z & updates2.7z). Some of  these files have been identified to be related to the Prometei trojan by Virustotal. The file sqhost.exe [6] was last found by Talos [7] used with the Prometei botnet as a trojan coin miner. 

Continue reading Suspicious Prometei Botnet Activity, (Sun, Jan 7th)

Posted in Uncategorized

Are you sure of your password?, (Sat, Jan 6th)

If many people can detect simple phishing emails these days, some attacks are very well crafted and also have built-in techniques not only to ensure that potential victims will fall into the trap but there is another aspect. From an attacker’s point of view, how to improve the quality of collected data?

Continue reading Are you sure of your password?, (Sat, Jan 6th)

Posted in Uncategorized

Wireshark updates, (Thu, Jan 4th)

The Wireshark Foundation has released 3 new versions of its popular network protocol analyzer. They are versions 4.2.1&#;x26;#;xc2;&#;x26;#;xa0;(which fixes 5 CVEs and a number of other bugs), 4.0.12&#;x26;#;xc2;&#;x26;#;xa0;(2 CVEs &#;x26;#;x2b; additional bugs), and 3.6.20&#;x26;#;xc2;&#;x26;#;xa0;(2 CVEs &#;x26;#;x2b; additional bugs). Version 4.2.0 was just released in November 2023, so if you haven&#;x26;#;39;t tried it out yet, here is your chance to upgrade.

Continue reading Wireshark updates, (Thu, Jan 4th)

Posted in Uncategorized