Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Vulnhub write-up: Five86–1 ( no metasploit )
I'd like to share my second attempt at a write up! I hope you will enjoy it, any suggestion welcome.

https://link.medium.com/XaOwiH6Q43
πŸ—£kolima_


πŸŽ–@malwr
Tigress C Obfuscator v3.1 - now with self-modifying code
Tigress is a highly diversifying obfuscator for the C language that
supports many defenses against reverse engineering attacks. It is
available for download from
https://tigress.wtf

Tigress provides a large collection of obfuscating code transformations, including virtualization, dynamic obfuscation, self-modifying code, and control flow flattening. It also provides transformations designed to thwart particular static and dynamic analyses, such as alias analysis, dynamic taint analysis, and branch analysis. All transformations are randomized and can be freely combined to transform a single program into a large collection of diverse variants of arbitrary complexity.

Tigress have been used to generate reverse engineering challenges for students in security classes, in academic research, and in industrial settings to protect production code.

For examples of Tigress obfuscation scripts and generated code, see: https://tigress.wtf/recipes.html
πŸ—£ua-tigress

I wonder how stringent they are regarding the source code process. Maybe it's possible to just hack some random professor and claim to have a legitimate research need.
πŸ‘€PhisherPrice


πŸŽ–@malwr
Google Removed Over 500 Chrome Extensions Due to Malware Concerns
πŸ—£Reshamkadri

Chrome then uninstalled itself
πŸ‘€8412risk

The article claims Duo has the list of extensions, but didn't link to it. Where is the list?

Edit: https://duo.com/labs/research/crxcavator-malvertising-2020
πŸ‘€atoponce


πŸŽ–@malwr
pykd 0.3.4.12
πŸ—£ussrhero
This project can help to automate debugging and crash dump analysis using Python. It allows one to take the best from both worlds: the expressiveness and convenience of Python with the power of WinDbg!


πŸŽ–@malwr
US Gov Dumps Analysis and TTPs of North Korean Cyber Operations
MAR-10271944-3.v1 – North Korean Trojan: BUFFETLINEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045f

MAR-10265965-1.v1 – North Korean Trojan: BISTROMATHhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045a

MAR-10265965-2.v1 – North Korean Trojan: SLICKSHOEShttps://www.us-cert.gov/ncas/analysis-reports/ar20-045b

MAR-10265965-3.v1 – North Korean Trojan: CROWDEDFLOUNDERhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045c

MAR-10271944-1.v1 – North Korean Trojan: HOTCROISSANThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045d

MAR-10271944-2.v1 – North Korean Trojan: ARTFULPIEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045e

MAR-10135536-8.v3 – North Korean Trojan: HOPLIGHThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045g

from https://www.us-cert.gov/ncas/analysis-reports

samples https://www.virustotal.com/gui/user/CYBERCOM\_Malware\_Alert/comments
πŸ—£digicat


πŸŽ–@malwr