#anyrun

16 posts · Last used 9d

🪰 We taught a fly to analyze phishing in #ANYRUN Sandbox. No OCR, no LLM, no DOM hints, and no ability to read.

Thanks to sandbox interactivity, the fly can move through the attack chain on its own and observe the full phishing flow: follow links, resolve CAPTCHAs, go through redirects, and fill forms with an email and password.

See how the fly moves through an AiTM phishing flow: 🪰 https://app.any.run/tasks/92c4e053-5abf-428a-8587-bc8abd43c7fd/?utm_source=mastodon&utm_medium=post&utm_campaign=fly_analyzed_phishing&utm_term=210926&utm_content=linktoservice 🪰 https://app.any.run/tasks/f32ec968-3f2d-49f0-8654-6581370740f1/?utm_source=mastodon&utm_medium=post&utm_campaign=fly_analyzed_phishing&utm_term=210926&utm_content=linktoservice Device Code Flow: 🪰 https://app.any.run/tasks/3efc3564-7a8b-4475-8114-c86fde18ad48/?utm_source=mastodon&utm_medium=post&utm_campaign=fly_analyzed_phishing&utm_term=210926&utm_content=linktoservice

🧠 What’s inside:

  1. 𝗕𝗿𝗮𝗶𝗻. Fruit fly hemibrain mapped to FlyWire for 3D visualization.

  2. 𝗙𝗹𝗶𝗴𝗵𝘁. There is inertia, sharp saccades instead of a smooth path, and braking based on how fast the image moves.

  3. 𝗩𝗶𝘀𝗶𝗼𝗻, 𝘀𝗺𝗲𝗹𝗹, 𝗮𝗻𝗱 𝘁𝗮𝘀𝘁𝗲. The fly cannot read. There is only contrast, movement, color, and shape. A button, link, and checkbox are different visual patterns converted into sensory signals.

  4. 𝗟𝗲𝗴𝘀. Landing on the right area counts as a click. If the fly finds an empty field, it “secretes acid”: select all → paste email.

  5. 𝗗𝗼𝗽𝗮𝗺𝗶𝗻𝗲, 𝗺𝗼𝘁𝗶𝘃𝗮𝘁𝗶𝗼𝗻, 𝗮𝗻𝗱 𝗮𝘃𝗲𝗿𝘀𝗶𝗼𝗻. When fed, it mostly flies around and looks at the page instead of clicking blindly. When hungry, it is more active and gets frustrated faster when it finds nothing. A successful click gives a reward signal and reduces frustration. A dead click increases avoidance of that area. When the search reaches a dead end, frustration makes the fly scroll down.

  6. 𝗠𝗲𝗺𝗼𝗿𝘆. It remembers the screen map and does not return to places where nothing happened— inhibition of return.

❗️ The fly is not smarter or more useful than an ML model trained for the task. This is not a phishing detection solution and not an attempt to replace one.

Made for fun, research curiosity, and the community 🤗

#cybersecurity #infosec

0
1
0
0
🚨 𝗜𝗻𝘀𝗶𝗱𝗲 #𝗧𝗲𝗿𝗺𝗶𝗻𝗮𝗹𝗙𝗶𝘅: 𝗪𝗼𝗿𝗱-𝗘𝗻𝗰𝗼𝗱𝗲𝗱 𝗣𝗮𝘆𝗹𝗼𝗮𝗱𝘀, 𝗦𝗺𝗮𝗿𝘁-𝗖𝗼𝗻𝘁𝗿𝗮𝗰𝘁 𝗟𝘂𝗿𝗲𝘀, 𝗙𝗼𝗿𝘂𝗺-𝗕𝗮𝘀𝗲𝗱 𝗖𝟮 ⚠️ Targeting the US and Canada, the chain starts on a compromised WordPress site and ends with a WinHTTP stager running inside a signed Microsoft executable. A user-driven lure becomes trusted-process C2 activity that can evade early validation and slow containment. ❗️ Key evasion detail: binaries are stored as English word sequences inside JavaScript code, executed by a legitimate Node.js runtime downloaded to the host. Fixed vocabularies decode them into payloads that look like ordinary text, not executable content. 📌 Lure domains come from a Polygon smart contract, and the final C2 list is pulled from a public forum profile before beaconing. 👨‍💻 Static checks only show part of the chain, making real business exposure harder to assess. See each stage unfold in #ANYRUN Sandbox: https://app.any.run/tasks/00d12fa2-c9da-44fc-848f-7481a520762a/?utm_source=mastodon&utm_medium=post&utm_campaign=inside_terminalfix&utm_term=090926&utm_content=linktoservice 🔍 Pivot from IOCs and subscribe to query updates to proactively track evolving activity: https://intelligence.any.run/analysis/lookup?utm_source=mastodonr&utm_medium=post&utm_campaign=inside_terminalfix&utm_content=linktotilookup&utm_term=090926#%7B%22query%22:%22filePath:%5C%22LockScreenContentServer%2Eexe%5C%22%20and%20filePath:%5C%22dui70%2Edll%5C%22%22,%22dateRange%22:180%7D%20 Want the deep dive on word-list payload encoding, EtherHiding, and dead-drop C2? Let us know 💬 ⚡️ See how #ANYRUN helps SOC teams detect & investigate complex threats faster: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=inside_terminalfix&utm_term=090926&utm_content=linktoenterprise #cybersecurity #infosec
0
2
0
0
Replying to
💡 #ANYRUN TI Feeds turn IOCs into continuous monitoring by streaming fresh, validated indicators and behavior-based threat data into your security stack. 📋 IOCs: C2 documentsphotos[.]com getimageinformation[.]com openandopen[.]com openpdfanywhere[.]com Lure (TerminalFix) updatemsnow[.]com updatecurrent[.]com uptodatehere[.]com superwebprotection[.]com exclusivecloudprotection[.]com extrafireprotection[.]com Redirect / fingerprint daskljtitaskastvv[.]pro momsdodigital[.]com beroniw[.]com Dropper 2e86d7adf50329896e81ce0a3d5f2c2bd0cb957bc47c8a69078e25ff6a6d6bba Trojanized mscoree.dll 18e3bc2b57f0de6a14b6abd283fa964ffde5b85bc3985988b56acc0a212b2099 Persistence %PROGRAMDATA%\NET Runtime Optimization Service WtACgCrCWnJB\ HKCU\...\CurrentVersion\Run - "NET Runtime Optimization Service uD9n5qAinyOu"
0
0
0
0
🎯 What changed in #ANYRUN’s threat coverage this July? 750+ new Suricata, YARA, and behavior rules help detect threats faster & cut manual work. Plus, a new TI Report and research into emerging threats. See how updates can strengthen your SOC response👇 https://any.run/cybersecurity-blog/july-threat-coverage-2026/?utm_source=mastodon&utm_medium=article&utm_campaign=july_threat_coverage_2026&utm_term=300726&utm_content=linktoblog
0
0
0
0
🚨 𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿 𝗖𝟮 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝗖𝗮𝘂𝗴𝗵𝘁 𝗼𝗻 𝗮 𝗟𝗶𝘃𝗲 𝗦𝘆𝘀𝘁𝗲𝗺. Interactive analysis let us capture what static detonation misses ⚠️ 𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱 𝘁𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴: 𝗚𝗲𝗿𝗺𝗮𝗻𝘆 𝗮𝗻𝗱 𝗨𝗞 ❗️ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT ➡️ exo.exe dropper ➡️ Lenovo FnHotkeyUtility.exe ➡️ spkvol.dll sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT. 🔥 The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory execution, encrypted C2, and active data exfiltration. 1️⃣ we.exe connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands hidden in HTML comments and a spoofed porsche[.]com Host header. 2️⃣ exo.exe unpacks to C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo binary, sideloads spkvol.dll, and delivers a fileless overlord-client Go agent. 📌 OVERLORD connects to lord[.]kirkdridebridge[.]com:5173 over mTLS-encrypted C2. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration. Observed capabilities include remote access, HVNC, keylogging, audio recording, SOCKS proxying, file management, browser/messenger/wallet data theft, and Solana drainer activity. 👨‍💻 See the full execution chain and collect #IOCs: https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoservice&utm_term=220726 ⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoenterpriselanding&utm_term=220726#cybersecurity #infosec
1
1
0
0
🚨 We’re tracking increased #DestinyStealer activity targeting organizations across Europe and the US. ⚠️ At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots. ❗️ Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critical for SOC teams. The attack starts with an IP check via ipinfo[.]io. The malware then creates a temporary directory at %TEMP%\\ for data collection. The collected data is then packed into %TEMP%\.zip. Exfiltration uses two parallel channels: HTTP to destinystealer[.]com/fileicin[.]php and raw TCP to tipidor-38534[.]portmap[.]host. 👨‍💻 See the full execution chain and collect IOCs to speed up detection and cut response time: https://app.any.run/tasks/01f70f9e-642d-46fa-b485-cf67dced6436/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoservice&utm_term=090726 🔍 Pivot from IOCs and subscribe to Query Updates to proactively track evolving attacks: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktotilookup&utm_term=090726#%7B%22query%22:%22threatName:%5C%22destinystealer%5C%22%22,%22dateRange%22:180%7D ⚡️ Learn how #ANYRUN Sandbox helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoenterpriselanding&utm_term=090726 IOCs 50008cd78878cb1b3c142e1fd60db55917b233465b8f3f6769ca862902af58bb ca288e609c5e4be27b95b10c4d11c29d3898ea632739dfeed3586b5049e21f26 3d840505ad13b082d6a8d52399ad52f6f0e79c07f25f55357cda09113010b30a Domains: destinystealer[.]com tipidor-38534[.]portmap[.]host Exfil URL: hxxps[:]//destinystealer[.]com/fileicin[.]php
0
0
0
0
❓ Which cyber threats should your SOC prioritize today? 📈 Explore the Top 30 threats targeting US organizations, based on fresh data from #ANYRUN Malware Trends Tracker and learn how to analyze and detect them faster with Interactive Sandbox and Threat Intelligence. Read the full report: https://any.run/cybersecurity-blog/usa-top-30-threats-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=usa_top_30_threats_2026&utm_content=linktoblog&utm_term=090726
0
0
0
0
💰 Security gaps cost more when governance, detection, and response operate separately. Learn how CISOs can apply NIST CSF 2.0 with #ANYRUN to reduce exposure, speed up investigations, and turn security operations into measurable risk reduction ⚡️ Read now: https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/?utm_source=mastodon&utm_medium=post&utm_campaign=nist_csf_guide_for_cisos&utm_content=linktomtt&utm_term=080726
0
0
0
0
You've seen all posts