This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
KevinStear1
Employee KevinStear1
Employee
since ‎2016-09-28
‎2021-04-14

User Statistics

  • 35 Posts
  • 0 Solutions
  • 46 Likes given
  • 26 Likes received
  • NetWitness Community
  • About KevinStear1

User Activity

  • Posts
  • Replies

Lotus Blossom Continues ASEAN Targeting

by KevinStear1 2018-02-13 general.in NetWitness Community Blog
2018-02-13
During the last weeks of January (2018), nation state actors from Lotus Blossom conducted a targeted malspam campaign against the Association of Southeast Asian Nations (ASEAN) countries. Just months after the APT32 watering hole activity against ASE...

Necurs Delivers DRIDEX 1-22-2018

by KevinStear1 2018-01-23 general.in NetWitness Community Blog • latest reply by KevinStear1 2018-01-25
2018-01-23
During the week following the Orthodox New Year (January 14, 2018), the Necurs botnet re-emerged on the scene with a malspam campaign spreading an old friend, the Dridex banking trojan. This activity was first identified by a Forcepoint Labs report, ...

Malspam delivers njRAT 1-11-2018

by KevinStear1 2018-01-12 general.in NetWitness Community Blog • latest reply by KevinStear1 2018-01-13
2018-01-12
During the last several weeks of 2017 and now well into early 2018, RSA FirstWatch has observed a malspam campaign delivering njRAT, a robust and publicly available remote administration tool (RAT) with capabilities for remote desktop, file manager, ...

Zealot Campaign for Monero Mining

by KevinStear1 2017-12-21 general.in NetWitness Community Blog • latest reply by KevinStear1 2018-01-06
2017-12-21
Just in time for the holiday season, a new Monero cryptocurrency mining campaign has kicked off during the first weeks of December. Unlike the plethora of other mining malware thus far in 2017, this new campaign is a sophisticated multi-staged attack...

Rise of the IoT Reaper

by KevinStear1 2017-10-26 general.in NetWitness Community Blog
2017-10-26
During the month of October, and there’s been a disturbance in the force… the growing presence of a new Internet of Things (IoT) botnet, dubbed ‘Reaper’. Initial research published by Checkpoint and Qihoo indicates that the IoT Reaper botnet may have...
View more

Re: Necurs Delivers DRIDEX 1-22-2018

by KevinStear1 2018-01-25 general.in NetWitness Community Blog
2018-01-25
Another #Dridex sample from today... thanks @Ring0x0 https://www.hybrid-analysis.com/sample/2396ac9e2b1b119050f67fd7a5382e8ba018427ab76ac0a969eefb08c537f089?environmentId=10… ANY.RUN

Re: Necurs Delivers DRIDEX 1-22-2018

by KevinStear1 2018-01-25 general.in NetWitness Community Blog
2018-01-25
Thanks for the thoughts David. I'm working with the right content folks to get you a response.

Re: Necurs Delivers DRIDEX 1-22-2018

by KevinStear1 2018-01-23 general.in NetWitness Community Blog
2018-01-23
Vitali Kremez on Twitter: "1-23-2018: #Dridex Botnet ID “7200” -> FTP download w/ VBA Macro #Spam First-layer config (4 …

Re: Malspam delivers njRAT 1-11-2018

by KevinStear1 2018-01-13 general.in NetWitness Community Blog
2018-01-13
Revision made in the above blog post to correctly credit malwarebreakdown.com's recent work on Agent Tesla.

Re: Zealot Campaign for Monero Mining

by KevinStear1 2018-01-06 general.in NetWitness Community Blog
2018-01-06
FirstWatch would like to the benefit of behavior driven parsers such as this, and agree that unsolicited HTTP POSTs have long carried a slew of exploit attempts. Specific to the #ZEALOT campaign, we observed these via powershell, wget, curl, cmd, an...
View more
Likes from
User Count
DavidGassman2
DavidGassman2 Occasional Contributor
1
MaorFranco
Employee MaorFranco
2
ShaneQuintard1
ShaneQuintard1 Beginner
1
RobertConley
RobertConley Beginner
4
DiptanuDas
DiptanuDas Beginner
1
View all
Likes given to
User Count
AhmedSonbol1
Employee AhmedSonbol1
18
RajasSave
Respected Contributor RajasSave Respected Contributor
8
ChristopherAhea
ChristopherAhea Beginner
3
JackRiley
Employee JackRiley
1
KentBackman
Employee KentBackman
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.