Malware News
15.5K subscribers
1.64K photos
7 videos
130 files
8.04K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Hiding Your Tracks: Bash History
πŸ—£bad3r_

Nice! I would add another one, kill the console to quit bash without saving history:


kill -9 $$
πŸ‘€ReigningShells


πŸŽ–@malwr
What do you use for IP Reputation?
We are currently using IBM X-force, but o don't find it that reliable there is a lot if false positives in there.
Any suggestions? Especially for one were we can get a feed from (API or something)
πŸ—£Mo7Robot

https://www.abuseipdb.com/register

https://talosintelligence.com/reputation\_center

https://www.apivoid.com/api/ip-reputation/
πŸ‘€chrisknight1985

If you are looking for malicious domains the Fortinet threat feed is pretty good. It's part of their Fortinet Developer's Network Site License. It's an API feed that supports csv and stix formats.
πŸ‘€Defiant_Success


πŸŽ–@malwr
EFS Ransomware
πŸ—£ikotler


πŸŽ–@malwr
Ubisoft send 2FA recovery code by email
πŸ—£-d4v3-

Once someone has access to your email they can take away the 2FA anyways. So it's not really weird or smth
πŸ‘€Axua247


πŸŽ–@malwr
Emotet file hashes, Compromised IP addresses and domains, and malicious powershell artifacts
While collecting malware samples on pastebin, my bot found an anonymous paste that contained a large amount of data relating to emotet.

It includes a section of file hashes, malicious IP addresses, compromised servers, compromised domains, and a few obfuscated powershell artifacts that look to either be post-exploitation or an alternative infection method.

File samples can be collected by simply using wget on a live compromised domain.


Here is a link to a reupload of the document:
https://pastebin.com/V6GGEPVA
πŸ—£NovateI


πŸŽ–@malwr
Fake Company, Real Threats: Logs From a Smart Factory Honeypot - Security News
πŸ—£_TM_dude

The most interesting part of this piece was the layout they used on their website to show the story.

It looks like it was running for several months, but didn't produce any revealing information. A few non-technical ransomware attacks. Simple stuff caused by poor security, which, I get it, it was mainly to show how weak security is a main point of entry. Not exactly revolutionary.
πŸ‘€DegenerateJC

Disappointed. I wish the guy came from real APT group doing more sophisticated or unknown exploits. No PLC system were harmed or attempted.
πŸ‘€thanoscsgo

I like the guy who acted like he was installing ransomware then renamed their files instead.
πŸ‘€steezefries


πŸŽ–@malwr