#anyrun

10 posts · Last used 8d

Back to Timeline
ANY.RUN @anyrun_app@infosec.exchange · Aug 06, 2026
🏦 Financial institutions are the #1 target for ransomware, credential theft, and social engineering. A SOC at an investment bank prevented hundreds of attempts with #ANYRUN. 📈 See how to strengthen security for banks: https://any.run/by-industry/finance/?utm_source=mastodon&utm_medium=post&utm_campaign=finance_success_story&utm_term=060826&utm_content=linktofinancelanding
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 30, 2026
🎯 What changed in #ANYRUN’s threat coverage this July? 750+ new Suricata, YARA, and behavior rules help detect threats faster & cut manual work. Plus, a new TI Report and research into emerging threats. See how updates can strengthen your SOC response👇 https://any.run/cybersecurity-blog/july-threat-coverage-2026/?utm_source=mastodon&utm_medium=article&utm_campaign=july_threat_coverage_2026&utm_term=300726&utm_content=linktoblog
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 29, 2026
❗ A US manufacturer had 200+ active vendors with no consistent way to validate incoming files. 🔥 #ANYRUN gave the team behavioral evidence which made triage 2x faster and significant reduction in escalations. 📖 See how to manage third-party risk: https://any.run/by-industry/manufacturing/?utm_source=mastodon&utm_medium=post&utm_campaign=manufacturing_real_case&utm_term=290726&utm_content=linktoblog
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 22, 2026
🚨 𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿 𝗖𝟮 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝗖𝗮𝘂𝗴𝗵𝘁 𝗼𝗻 𝗮 𝗟𝗶𝘃𝗲 𝗦𝘆𝘀𝘁𝗲𝗺. Interactive analysis let us capture what static detonation misses ⚠️ 𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱 𝘁𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴: 𝗚𝗲𝗿𝗺𝗮𝗻𝘆 𝗮𝗻𝗱 𝗨𝗞 ❗️ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT ➡️ exo.exe dropper ➡️ Lenovo FnHotkeyUtility.exe ➡️ spkvol.dll sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT. 🔥 The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory execution, encrypted C2, and active data exfiltration. 1️⃣ we.exe connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands hidden in HTML comments and a spoofed porsche[.]com Host header. 2️⃣ exo.exe unpacks to C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo binary, sideloads spkvol.dll, and delivers a fileless overlord-client Go agent. 📌 OVERLORD connects to lord[.]kirkdridebridge[.]com:5173 over mTLS-encrypted C2. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration. Observed capabilities include remote access, HVNC, keylogging, audio recording, SOCKS proxying, file management, browser/messenger/wallet data theft, and Solana drainer activity. 👨‍💻 See the full execution chain and collect #IOCs: https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoservice&utm_term=220726 ⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoenterpriselanding&utm_term=220726 #cybersecurity #infosec
1
1
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 17, 2026
✍️ "Timely sandboxing prevented the company from suffering millions of dollars in losses, damaged reputation, and years of litigation." — Head of SOC, Investment bank 📖 See how #ANYRUN accelerates SOC triage at enterprise scale: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=triage_challenges&utm_content=linktoenterprise&utm_term=170726
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 16, 2026
🚨 PhantomEnigma Hijacked 20+ Government Websites to Deliver Malware. #ANYRUN connected hundreds of unrelated "generic" samples into a coordinated operation targeting public sector. ❗️ Campaign is active. Read the report and hunt with the IOCs: https://any.run/cybersecurity-blog/phantomenigma-research/?utm_source=mastodon&utm_medium=post&utm_campaign=phantomenigma_research&utm_content=linktoblog&utm_term=160726
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 09, 2026
🚨 We’re tracking increased #DestinyStealer activity targeting organizations across Europe and the US. ⚠️ At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots. ❗️ Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critical for SOC teams. The attack starts with an IP check via ipinfo[.]io. The malware then creates a temporary directory at %TEMP%\\ for data collection. The collected data is then packed into %TEMP%\.zip. Exfiltration uses two parallel channels: HTTP to destinystealer[.]com/fileicin[.]php and raw TCP to tipidor-38534[.]portmap[.]host. 👨‍💻 See the full execution chain and collect IOCs to speed up detection and cut response time: https://app.any.run/tasks/01f70f9e-642d-46fa-b485-cf67dced6436/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoservice&utm_term=090726 🔍 Pivot from IOCs and subscribe to Query Updates to proactively track evolving attacks: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktotilookup&utm_term=090726#%7B%22query%22:%22threatName:%5C%22destinystealer%5C%22%22,%22dateRange%22:180%7D ⚡️ Learn how #ANYRUN Sandbox helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoenterpriselanding&utm_term=090726 IOCs 50008cd78878cb1b3c142e1fd60db55917b233465b8f3f6769ca862902af58bb ca288e609c5e4be27b95b10c4d11c29d3898ea632739dfeed3586b5049e21f26 3d840505ad13b082d6a8d52399ad52f6f0e79c07f25f55357cda09113010b30a Domains: destinystealer[.]com tipidor-38534[.]portmap[.]host Exfil URL: hxxps[:]//destinystealer[.]com/fileicin[.]php
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 09, 2026
❓ Which cyber threats should your SOC prioritize today? 📈 Explore the Top 30 threats targeting US organizations, based on fresh data from #ANYRUN Malware Trends Tracker and learn how to analyze and detect them faster with Interactive Sandbox and Threat Intelligence. Read the full report: https://any.run/cybersecurity-blog/usa-top-30-threats-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=usa_top_30_threats_2026&utm_content=linktoblog&utm_term=090726
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 09, 2026
✅ Check your SOC workflow against this checklist. If any stage rebuilds what the previous one already found — the process is inefficient. #ANYRUN provides actionable & sharable context at every stage ⚡ 🎯 How to use connected intelligence in your SOC: https://any.run/cybersecurity-blog/streamline-your-soc/?utm_source=mastodon&utm_medium=post&utm_campaign=workflow_checklist&utm_content=linktoblog&utm_term=090726
0
0
0
ANY.RUN @anyrun_app@infosec.exchange · Jul 08, 2026
💰 Security gaps cost more when governance, detection, and response operate separately. Learn how CISOs can apply NIST CSF 2.0 with #ANYRUN to reduce exposure, speed up investigations, and turn security operations into measurable risk reduction ⚡️ Read now: https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/?utm_source=mastodon&utm_medium=post&utm_campaign=nist_csf_guide_for_cisos&utm_content=linktomtt&utm_term=080726
0
0
0

You've seen all posts