#heur

acrypthash👨🏻‍💻acrypthash@infosec.exchange
2022-12-23

There must be something about today. I received another alert from our EDR of a malicious file landing on an end user asset. After further investigation it was another phishing email, with the same TTP as previous... File has been removed, the asset has been quarantined and scanned.

Sample: baa9e6b2fa25f1a62a0e2704d7879054

YARA Signature Match - THOR APT Scanner

RULE: SUSP_ISO_In_ZIP_Small_May22_1
RULE_SET: Livehunt - Suspicious42 Indicators 🏹
RULE_TYPE: THOR APT Scanner's rule set only 🔨
RULE_LINK: valhalla.nextron-systems.com/i
DESCRIPTION: Detects suspicious ISO file in small ZIP files

#security #phishing #yara #malware #HEUR #trojan #EDR #ISO #TTP

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst