US Gov Dumps Analysis and TTPs of North Korean Cyber Operations
MAR-10271944-3.v1 – North Korean Trojan: BUFFETLINEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045f
MAR-10265965-1.v1 – North Korean Trojan: BISTROMATHhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045a
MAR-10265965-2.v1 – North Korean Trojan: SLICKSHOEShttps://www.us-cert.gov/ncas/analysis-reports/ar20-045b
MAR-10265965-3.v1 – North Korean Trojan: CROWDEDFLOUNDERhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045c
MAR-10271944-1.v1 – North Korean Trojan: HOTCROISSANThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045d
MAR-10271944-2.v1 – North Korean Trojan: ARTFULPIEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045e
MAR-10135536-8.v3 – North Korean Trojan: HOPLIGHThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045g
from https://www.us-cert.gov/ncas/analysis-reports
samples https://www.virustotal.com/gui/user/CYBERCOM\_Malware\_Alert/comments
🗣digicat
🎖@malwr
MAR-10271944-3.v1 – North Korean Trojan: BUFFETLINEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045f
MAR-10265965-1.v1 – North Korean Trojan: BISTROMATHhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045a
MAR-10265965-2.v1 – North Korean Trojan: SLICKSHOEShttps://www.us-cert.gov/ncas/analysis-reports/ar20-045b
MAR-10265965-3.v1 – North Korean Trojan: CROWDEDFLOUNDERhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045c
MAR-10271944-1.v1 – North Korean Trojan: HOTCROISSANThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045d
MAR-10271944-2.v1 – North Korean Trojan: ARTFULPIEhttps://www.us-cert.gov/ncas/analysis-reports/ar20-045e
MAR-10135536-8.v3 – North Korean Trojan: HOPLIGHThttps://www.us-cert.gov/ncas/analysis-reports/ar20-045g
from https://www.us-cert.gov/ncas/analysis-reports
samples https://www.virustotal.com/gui/user/CYBERCOM\_Malware\_Alert/comments
🗣digicat
🎖@malwr
dga_predict: Tensorflow 2.0 Implementation of "Predicting Domain Generation Algorithms using LSTMs"
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
GitHub
GitHub - bfilar/dga_predict: Pytorch Implementation of "Predicting Domain Generation Algorithms using LSTMs"
Pytorch Implementation of "Predicting Domain Generation Algorithms using LSTMs" - GitHub - bfilar/dga_predict: Pytorch Implementation of "Predicting Domain Generation Alg...
labeless: Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping and interactive Python scripting capabilities.
🗣digicat
I love seeing new open source tools but we really have to start switching over to writing things for Ghidra so everyone can use and contribute to them
👤maverickleopard
ida already has this natively though?
👤tansim
https://research.checkpoint.com/2018/labeless-an-introduction/ 6 articles about this plugin
👤WK-lk
🎖@malwr
🗣digicat
I love seeing new open source tools but we really have to start switching over to writing things for Ghidra so everyone can use and contribute to them
👤maverickleopard
ida already has this natively though?
👤tansim
https://research.checkpoint.com/2018/labeless-an-introduction/ 6 articles about this plugin
👤WK-lk
🎖@malwr
GitHub
GitHub - a1ext/labeless: Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend…
Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping and interactive Python scripting capabilities. - a1ext/labe...
Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world
🗣CodePerfect
I have tried warning people about this, no one wanted to listen. NoOoO mY vPn Is Da SaFeSt TiNg EvAh!!!!!!!! REEEEEEEEEEEEEEE /s
👤BeigeAlmighty
Is there any type of decentralized VPN server?
👤IndividualThoughts
No more nord vpn
👤DogMeatTalk
🎖@malwr
🗣CodePerfect
I have tried warning people about this, no one wanted to listen. NoOoO mY vPn Is Da SaFeSt TiNg EvAh!!!!!!!! REEEEEEEEEEEEEEE /s
👤BeigeAlmighty
Is there any type of decentralized VPN server?
👤IndividualThoughts
No more nord vpn
👤DogMeatTalk
🎖@malwr
ZDNET
Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world
Iranian hackers have targeted Pulse Secure, Fortinet, Palo Alto Networks, and Citrix VPNs to hack into large companies.
Extracting Prefetch from Memory
Good morning,
I’ve just released a new Introduction to Memory Forensics episode. This is an excerpt from the upcoming premiere of a new 13Cubed series called Deep Dives. We'll take a look at how to extract Windows Prefetch data from memory. There are a number of things you'll need to know to get the Volatility prefetchparser plugin to work correctly, especially with Windows 10 Prefetch files since they are compressed. We'll walk through the entire process, including installation of Volatility, the prefetchparser plugin, and of an open source implementation of the Microsoft compression algorithms.
Episode:
https://www.youtube.com/watch?v=6y9Wxch7NKk
Episode Guide:
https://www.13cubed.com/episodes
Channel:
https://www.youtube.com/13cubed
Patreon (Help support 13Cubed):
https://www.patreon.com/13cubed
🗣13Cubed
🎖@malwr
Good morning,
I’ve just released a new Introduction to Memory Forensics episode. This is an excerpt from the upcoming premiere of a new 13Cubed series called Deep Dives. We'll take a look at how to extract Windows Prefetch data from memory. There are a number of things you'll need to know to get the Volatility prefetchparser plugin to work correctly, especially with Windows 10 Prefetch files since they are compressed. We'll walk through the entire process, including installation of Volatility, the prefetchparser plugin, and of an open source implementation of the Microsoft compression algorithms.
Episode:
https://www.youtube.com/watch?v=6y9Wxch7NKk
Episode Guide:
https://www.13cubed.com/episodes
Channel:
https://www.youtube.com/13cubed
Patreon (Help support 13Cubed):
https://www.patreon.com/13cubed
🗣13Cubed
🎖@malwr
YouTube
Extracting Prefetch from Memory
This is an excerpt from the upcoming premiere of a new 13Cubed series called Deep Dives. In this episode, we'll take a look at how to extract Windows Prefetch data from memory. There are a number of things you'll need to know to get the Volatility prefetchparser…