Recursos/SentinelOne Vs. RATDispenser – Mitigation and Rollback
diciembre 8, 2021
SentinelOne Vs. RATDispenser – Mitigation and Rollback
⚔️ See how SentinelOne mitigates and rolls back RATDispenser malware loader. RATDispenser is a novel, JavaScript-based malware loader. It has been seen in conjunction with the delivery of multiple RAT families/campaigns and includes the distribution of Remcos, WSHRAT, Formbook, and many others. RATDispenser is typically distributed/delivered via a phishing email. The encoded JavaScript is decoded (at runtime) and written to %temp%. Any additional RAT payloads (in analyzed samples) are dropped into assigned directories in %appdata%/Roaming. Once a user is enticed into clicking/launching the javascript, the relevant installation script for the prescribed RAT will execute.
There is some variation across RATDispenser in that some analyzed variants will reach out to a C2 to download the necessary RAT payload. A majority of them, however, function as direct droppers.
#RATDispenser #ransomware #malware #cybersecurity #infosec #endpointprotection #endpointsecurity
SentinelOne Vs. RATDispenser – Mitigation and Rollback
Recursos relacionados
Resource
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
View Asset
Resource
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
View Asset
Resource
LABScon24 Replay | A Walking Red Flag (With Yellow Stars) | Cary & Benincasa
China's cybersecurity competition ecosystem has grown significantly since 2017, with over 150 unique events and more than 400 total competitions.…
View Asset
Resource
LABScon24 Replay | Kryptina RaaS: From Unsellable Cast-off to Enterprise Ransomware | Jim Walter
Kryptina RaaS, originally a free giveaway, has evolved into a tool for large ransomware groups targeting Linux and cloud environments.…
View Asset
Disfrute de la plataforma de ciberseguridad más avanzada del mundo
Descubra cómo nuestra plataforma de ciberseguridad inteligente y autónoma protege a su empresa, ahora y en el futuro.