Introduction to Malware Analysis | Common Terms | Tools to Get Started
π£davidalbertozam
Excellent video.
π€GibsonAleph
π@malwr
π£davidalbertozam
Excellent video.
π€GibsonAleph
π@malwr
YouTube
Malware Analysis Overview For Beginners | Common Terms & Tools
An overview for beginners to get started with malware analysis. You need to know the common terms, what are "Malware Packers", for instance. This will allow you to better approach the nature of any security incident. So, for starters, Malware analysis involvesβ¦
Tigress C Obfuscator v3.1 - now with self-modifying code
Tigress is a highly diversifying obfuscator for the C language that
supports many defenses against reverse engineering attacks. It is
available for download from
https://tigress.wtf
Tigress provides a large collection of obfuscating code transformations, including virtualization, dynamic obfuscation, self-modifying code, and control flow flattening. It also provides transformations designed to thwart particular static and dynamic analyses, such as alias analysis, dynamic taint analysis, and branch analysis. All transformations are randomized and can be freely combined to transform a single program into a large collection of diverse variants of arbitrary complexity.
Tigress have been used to generate reverse engineering challenges for students in security classes, in academic research, and in industrial settings to protect production code.
For examples of Tigress obfuscation scripts and generated code, see: https://tigress.wtf/recipes.html
π£ua-tigress
I wonder how stringent they are regarding the source code process. Maybe it's possible to just hack some random professor and claim to have a legitimate research need.
π€PhisherPrice
π@malwr
Tigress is a highly diversifying obfuscator for the C language that
supports many defenses against reverse engineering attacks. It is
available for download from
https://tigress.wtf
Tigress provides a large collection of obfuscating code transformations, including virtualization, dynamic obfuscation, self-modifying code, and control flow flattening. It also provides transformations designed to thwart particular static and dynamic analyses, such as alias analysis, dynamic taint analysis, and branch analysis. All transformations are randomized and can be freely combined to transform a single program into a large collection of diverse variants of arbitrary complexity.
Tigress have been used to generate reverse engineering challenges for students in security classes, in academic research, and in industrial settings to protect production code.
For examples of Tigress obfuscation scripts and generated code, see: https://tigress.wtf/recipes.html
π£ua-tigress
I wonder how stringent they are regarding the source code process. Maybe it's possible to just hack some random professor and claim to have a legitimate research need.
π€PhisherPrice
π@malwr
Google Removed Over 500 Chrome Extensions Due to Malware Concerns
π£Reshamkadri
Chrome then uninstalled itself
π€8412risk
The article claims Duo has the list of extensions, but didn't link to it. Where is the list?
Edit: https://duo.com/labs/research/crxcavator-malvertising-2020
π€atoponce
π@malwr
π£Reshamkadri
Chrome then uninstalled itself
π€8412risk
The article claims Duo has the list of extensions, but didn't link to it. Where is the list?
Edit: https://duo.com/labs/research/crxcavator-malvertising-2020
π€atoponce
π@malwr
solutionfactory.in
Google Removed Over 500 Chrome Extensions Due to Malware Concerns
Exploit Development: Panic! At The Kernel - Token Stealing Payloads Revisited on Windows 10 x64 and Bypassing SMEP
https://connormcgarr.github.io/x64-Kernel-Shellcode-Revisited-and-SMEP-Bypass/
π@malwr
https://connormcgarr.github.io/x64-Kernel-Shellcode-Revisited-and-SMEP-Bypass/
π@malwr
Connor McGarrβs Blog
Exploit Development: Panic! At The Kernel - Token Stealing Payloads Revisited on Windows 10 x64 and Bypassing SMEP
Revisiting token stealing payloads on Windows 10 x64 and diving into mitigations such as SMEP.
Patching MacOS Sketch.App for unlimited Trial in Ghidra
https://duraki.github.io/posts/o/20200214-sketch.app-patch-in-ghidra.html
π@malwr
https://duraki.github.io/posts/o/20200214-sketch.app-patch-in-ghidra.html
π@malwr
deviltux.thedev.id
Patching MacOS Sketch.App for unlimited Trial in Ghidra
<%= @description %>
IMSI Catcher Detection Solutions List for Consumers and Businesses
π£Oles_Mironov_Mironov
π@malwr
π£Oles_Mironov_Mironov
π@malwr
pykd 0.3.4.12
π£ussrhero
This project can help to automate debugging and crash dump analysis using Python. It allows one to take the best from both worlds: the expressiveness and convenience of Python with the power of WinDbg!
π@malwr
π£ussrhero
This project can help to automate debugging and crash dump analysis using Python. It allows one to take the best from both worlds: the expressiveness and convenience of Python with the power of WinDbg!
π@malwr
US Gov Dumps Analysis and TTPs of North Korean Cyber Operations
MAR-10271944-3.v1 β North Korean Trojan: BUFFETLINEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045f
MAR-10265965-1.v1 β North Korean Trojan: BISTROMATHhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045a
MAR-10265965-2.v1 β North Korean Trojan: SLICKSHOEShttps://www.us-cert.gov/ncas/analysis-reports/ar20-045b
MAR-10265965-3.v1 β North Korean Trojan: CROWDEDFLOUNDERhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045c
MAR-10271944-1.v1 β North Korean Trojan: HOTCROISSANThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045d
MAR-10271944-2.v1 β North Korean Trojan: ARTFULPIEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045e
MAR-10135536-8.v3 β North Korean Trojan: HOPLIGHThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045g
from https://www.us-cert.gov/ncas/analysis-reports
samples https://www.virustotal.com/gui/user/CYBERCOM\_Malware\_Alert/comments
π£digicat
π@malwr
MAR-10271944-3.v1 β North Korean Trojan: BUFFETLINEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045f
MAR-10265965-1.v1 β North Korean Trojan: BISTROMATHhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045a
MAR-10265965-2.v1 β North Korean Trojan: SLICKSHOEShttps://www.us-cert.gov/ncas/analysis-reports/ar20-045b
MAR-10265965-3.v1 β North Korean Trojan: CROWDEDFLOUNDERhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045c
MAR-10271944-1.v1 β North Korean Trojan: HOTCROISSANThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045d
MAR-10271944-2.v1 β North Korean Trojan: ARTFULPIEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045e
MAR-10135536-8.v3 β North Korean Trojan: HOPLIGHThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045g
from https://www.us-cert.gov/ncas/analysis-reports
samples https://www.virustotal.com/gui/user/CYBERCOM\_Malware\_Alert/comments
π£digicat
π@malwr
dga_predict: Tensorflow 2.0 Implementation of "Predicting Domain Generation Algorithms using LSTMs"
π£digicat
π@malwr
π£digicat
π@malwr
GitHub
GitHub - bfilar/dga_predict: Pytorch Implementation of "Predicting Domain Generation Algorithms using LSTMs"
Pytorch Implementation of "Predicting Domain Generation Algorithms using LSTMs" - GitHub - bfilar/dga_predict: Pytorch Implementation of "Predicting Domain Generation Alg...
New Cyber Espionage Campaigns Targeting Palestinians - Part 1: The Spark Campaign
π£digicat
π@malwr
π£digicat
π@malwr
Cybereason
New Cyber Espionage Campaigns Targeting Palestinians - Part 1: The Spark Campaign
Cybereason's Nocturnus team has been tracking recent espionage campaigns specifically directed at entities and individuals in the Palestinian territories.
labeless: Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping and interactive Python scripting capabilities.
π£digicat
I love seeing new open source tools but we really have to start switching over to writing things for Ghidra so everyone can use and contribute to them
π€maverickleopard
ida already has this natively though?
π€tansim
https://research.checkpoint.com/2018/labeless-an-introduction/ 6 articles about this plugin
π€WK-lk
π@malwr
π£digicat
I love seeing new open source tools but we really have to start switching over to writing things for Ghidra so everyone can use and contribute to them
π€maverickleopard
ida already has this natively though?
π€tansim
https://research.checkpoint.com/2018/labeless-an-introduction/ 6 articles about this plugin
π€WK-lk
π@malwr
GitHub
GitHub - a1ext/labeless: Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backendβ¦
Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping and interactive Python scripting capabilities. - a1ext/labe...