Time ago, we receive a phishing that easily bypassed the Microsoft Exchange Protection (EOP) and a third part email sandbox solution. The technique was an old one, but it was still effective.
Continue readingPost Category → Analysis
Deobfuscating a Powershell payload of Cobalt Strike
On January 27th 2023 the chilean goverment CSIRT disclosed IOCs of a failed intrusion to an entity related with the economic sector in Chile. What was published corresponded to a hash (md5) and two IPv4 addresses. In this post we reviewed this data and try to get more information about the threat.
Continue reading