Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
2 résultats taggé AvNeutralizer  ✕
Unpacking the unpleasant FIN7 gift: PackXOR https://harfanglab.io/insidethelab/unpacking-packxor/
06/09/2024 11:25:16
QRCode
archive.org
thumbnail

In early July 2024, the Sentinel Labs researchers released an extensive article1 about “FIN7 reboot” tooling, notably introducing “AvNeutralizer”, an anti-EDR tool. This tool has been found in the wild as a packed payload.

In this article, we offer a thorough analysis of the associated private packer that we named “PackXOR”, as well as an unpacking tool. Additionally, while investigating the packer usage, we determined that PackXOR might not be exclusively leveraged by FIN7.

HarfangLab EN 2024 PackXOR analysis FIN7 AvNeutralizer
Researchers Unpacked AvNeutralizer EDR Killer Used By FIN7 Group https://gbhackers.com/avneutralizer-edr-killer-unpacked/
06/09/2024 11:19:16
QRCode
archive.org
thumbnail

FIN7 (aka Carbon Spider, ELBRUS, Sangria Tempest) is a Russian APT group that is primarily known for targeting the U.S. retail, restaurant, and hospitality sectors since mid-2015. 

gbhackers EN 2024 FIN7 AvNeutralizer EDR Killer
4368 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio