Joe Security's Blog
Inside ScarfaceStealer's Sandbox-Aware Anti-Analysis System
IntroductionIn this blog post, we examine a multi-stage ScarfaceStealer infection chain delivered through an Electron-based application packaged with NSIS.The investigation began with a Joe Sandbox Cloud Basic analysis https://www.joesandbox.com/analysis/1915862/0/html that produced only limited behavioral indicators, suggesting that the sample did not fully expose its intended execution path.
Read more...
Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign
In this blog post, we examine a multi-stage phishing campaign targeting staff members of the Punjab Safe Cities Authority (PSCA) and PPIC3 in Pakistan. The attack leveraged two distinct infection vectors, both relying on the same underlying infrastructure.The phishing email was analyzed by Joe Reverser in the report available here:https://www.joesandbox.
Read more...
Deep Malware Analysis of a Multi-Stage Cobalt Strike Loader
In this blog post, we provide a detailed technical reconstruction of a multi-stage malware chain that ultimately delivers a Cobalt Strike Beacon.The sample was obtained from the following Joe Sandbox Cloud Basic analysis:https://www.joesandbox.com/analysis/1894688/1/htmlOur investigation began with a low-signal sample that initially appeared harmless.
Read more...