PEMB

PEMB

Security Researcher, Threat Intel Analyst, Malware Analyst.

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

Massive campaign targets over 27,000+ emails across across 14,000 domains from corporate and education. A threat actor by the name of "Armandabors" on github initially made a commit to github to update the massive list of emails used for one of the phihing domains.

in
Post Patch Threat Hunting

Post Patch Threat Hunting

Earlier today MITRE went public stating that a state-backed hacking group breached its systems using two Ivanti VPN zero-days back in January 2024.

in
Static Malware Analysis∶ to string or to floss that is the question

Static Malware Analysis∶ to string or to floss that is the question

Every analyst has one or two methodologies for analyzing malware and perhaps even different approaches based on the malware type being analyzed. Regardless of many ways you can analyze malware we all do static analysis and look into strings at some point.

in
Powershell Dropper

Powershell Dropper

I found an interesting PowerShell script uploaded today on Malware Bazaar uploaded at 2023-05-31 02:06 (UTC) then turns out to be a dropper...

in