Archives: Out of Band

Malware Analysis – Supersuso
2022-01-09
Malware Analysis – Supersuso

Supersuso is a ransomware intended to encrypt sensitive data in order to restrict access to it. During

TECHNICAL ANALYSIS – BIGLOCK RANSOMWARE
2021-12-30
TECHNICAL ANALYSIS – BIGLOCK RANSOMWARE

BigLock is a ransomware discovered in 2020 and also known as “corona-lock.” It encrypts

Apache Log4j – Technical Analysis of Critical Remote Code Execution Vulnerability Tracked as CVE-2021-44228
2021-12-15
Apache Log4j – Technical Analysis of Critical Remote Code Execution Vulnerability Tracked as CVE-2021-44228

EXECUTIVE SUMMARY   A critical Remote Code Execution Vulnerability tracked as CVE-2021-44228

TECHNICAL ANALYSIS – Makop Ransomware
2021-12-11
TECHNICAL ANALYSIS – Makop Ransomware

Makop Ransomware Analysis Brief Introduction: Makop ransomware is the latest malware and is trending

KARMA Leak Ransomware Technical Analysis
2021-12-07
KARMA Leak Ransomware Technical Analysis

KARMA Leak Ransomware Technical Analysis   Risk Score: 8 Confidence Level: High Suspected Malware:

Malware Analysis related to APT41 – STEALTHVECTOR
2021-12-01
Malware Analysis related to APT41 – STEALTHVECTOR

Malware Analysis related to APT41 – STEALTHVECTOR Risk Score: 8. Confidence Level: High. Suspected

Blacklisted IP (Gh0st RAT) Analysis
2021-11-23
Blacklisted IP (Gh0st RAT) Analysis

Ongoing analysis of Gh0st RAT Blacklisted IP: 23[.]225.73.110 Risk Score: 10 Confidence Level: High

FormBook Malware Technical Analysis
2021-11-17
FormBook Malware Technical Analysis

Overview Risk Score: 8 Confidence Level: High Suspected Malware: FormBook Malware/Trojan Function:

Malware Research on AtomSilo Ransomware
2021-10-27
Malware Research on AtomSilo Ransomware

Malware Research on AtomSilo Ransomware AtomSilo is a new Ransomware recently seen in September 2021

Kaseya Supply Chain Attacks
2021-08-06
Kaseya Supply Chain Attacks

By CYFIRMA Research First Published on 6 August 2021 EXECUTIVE SUMMARY REvil ransomware has set a

WebKit
2021-08-06
WebKit

By CYFIRMA Research First Published on 6 August 2021 EXECUTIVE SUMMARY Russian threat actors are suspected

PrintNightmare
2021-08-06
PrintNightmare

By CYFIRMA Research First Published on 6 August 2021 EXECUTIVE SUMMARY Russian threat actors are suspected

Anonymous Group OpMyanmar
2021-05-19
Anonymous Group OpMyanmar

By CYFIRMA Research First Published on 27 Apr 2021 Following the coup in Myanmar by the country’s

Anonymous Group OpFukushima
2021-05-19
Anonymous Group OpFukushima

By CYFIRMA Research First Published on 17 May 2021 Post Japanese government’s announcement to approve

US Oil and Gas Pipeline Attack
2021-05-19
US Oil and Gas Pipeline Attack

By CYFIRMA Research Large-scale cyberattacks targeting critical infrastructure and operations is back

SilentFade Malware Exploitation of Weakness in Facebook
2021-03-23
SilentFade Malware Exploitation of Weakness in Facebook

Out-of-Band Report 8 Mar 2021 Content 1. Executive Summary 2. Impact 3. Hypotheses 4. Process Flow

Incidents, attributions, and exploitation techniques for path traversal flaw in Fortinet FortiOS SSL VPN devices
2020-12-28
Incidents, attributions, and exploitation techniques for path traversal flaw in Fortinet FortiOS SSL VPN devices

First published on 16 Dec 2020 A hacker has published a list of one-line exploits that can exfiltrate

Hackers Abuse Microsoft Teams’ Vulnerabilities
2020-12-24
Hackers Abuse Microsoft Teams’ Vulnerabilities

Microsoft Teams could be targeted by suspected threat actors as they have been observed manipulating

Spear Phishing Attack by N. Korean Hacking Group, Kimsuky
2020-12-16
Spear Phishing Attack by N. Korean Hacking Group, Kimsuky

Kimsuky (aka Velvet Chollima, Black Banshee, and Thallium) is a known N. Korean state-sponsored threat

Understanding Open Proxies and Cyberattacks
2020-11-09
Understanding Open Proxies and Cyberattacks

CYFIRMA research first alerted clients on the increase in open proxy usage as the attack method by

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.