andx86

. . a minimalistic personal blog focused on cybersecurity.

  • Home
  • Categories
    • Analysis
    • Shorts
  • About Me
  • Contact

VelvetSweatshop: Abusing the default MS Office password

posted in Analysis on September 2, 2023 by andx86 0 Comments

Time ago, we receive a phishing that easily bypassed the Microsoft Exchange Protection (EOP) and a third part email sandbox solution. The technique was an old one, but it was still effective.

Continue reading →

Deny delete permissions on a folder

posted in Shorts on March 7, 2023 by andx86 0 Comments
File permissions
flaticon.com

Some times, when you analysis dynamically a malware sample and this created files and then deleted them, disable the permissions for delete files in one specific folder could be useful.

Continue reading →

Enabling Netlogon debug mode

posted in Shorts on February 11, 2023 by andx86 0 Comments

Some time ago I had to investigate a case in which a lot of failed login events were being received in the Domain Controller of a public organization (apparently a brute force attack). The events did not show which machine was being logged on. In some cases it showed the name of the connection source machine and in others it did not.

Continue reading →

Deobfuscating a Powershell payload of Cobalt Strike

posted in Analysis on February 7, 2023 by andx86 0 Comments

On January 27th 2023 the chilean goverment CSIRT disclosed IOCs of a failed intrusion to an entity related with the economic sector in Chile. What was published corresponded to a hash (md5) and two IPv4 addresses. In this post we reviewed this data and try to get more information about the threat.

Continue reading →

Hello world!

posted in Uncategorized on February 4, 2023 by andx86 0 Comments

Welcome to andx86.com. First post coming soon!