Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Forwarded from CVE Notify
๐Ÿšจ CVE-2020-9320
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK.

๐ŸŽ–@cveNotify
Forwarded from CVE Notify
๐Ÿšจ CVE-2019-14688
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.

๐ŸŽ–@cveNotify
Mobile networks - Do they have a text message spam filter?
Someone is using my phone number when making online enquires. They've been doing it for about 2 months now. So I'm getting unsolicited texts and calls.

I've decided to attempt to contact the person to persuade them to stop. In my country, I predict I'll need to send 100 text messages to find them...if they respond to the text. It feels like they're changing a digit of their own phone number.

The content of the text will be exactly the same, it'll be using a newly registered sim, and I'll be using a GSM module connected to my computer.

If this were emails, I imagine Google and Microsoft would probably mark the emails as spam. And so I'm curious if mobile networks would treat text messages in the same manner?

I ask in this sub because I imagine someone in this community has played with mass text messages and I can't think of a better sub.
๐Ÿ—ฃreddit_user33

Mobile networks do have some spam protections, depending on the service provider. The problem is that many of these networks allow phone number spoofing, meaning you can call from a number you donโ€™t own. This bypasses a lot of the anti-spam protections in place. Itโ€™s a huge problem world wide and thereโ€™s not much anyone can do about it because networks donโ€™t want to spend the money to fix it, and government agencies wonโ€™t force them to fix it. (Often because these government agencies get lobbied by the networks)

Thereโ€™s really just not much you can do. Even if you call the original number, thereโ€™s probably not a person on the other side, just a computer.
๐Ÿ‘คNullOfUndefined


๐ŸŽ–@malwr
A new malware sample format called UMSE (Universal Malware Sample Encryption) which improves user confidentiality and reverse engineering process is now available here: https://github.com/dalvarezperez/umse/


โ„น๏ธ Sent from one of our subscribers

๐ŸŽ–@malwr
Opposition Research (OSINT): Twitter
๐Ÿ—ฃNattyFried1


๐ŸŽ–@malwr
Chinese Bitcoin investor loses $45 million to a SIM-Swapping attack.
๐Ÿ—ฃnilehighclub

SIM Swapping is stupid easy too, thatโ€™s why this is a rampant issue - all it takes is someone inside the carrier (and not even a high ranking person)
๐Ÿ‘คmc2memes

These sort of attacks are just stunning.

I still have not really worked out how they manage to steal a persons phone number.

I guess they gain a lot of information about a person so they can answer any question an ISP may ask. Or is it simply the fact that ISP's have basically no security built into their processes?
๐Ÿ‘คVestigialHead

You keep 45 million on something protected by an sms on a phone.... youโ€™re an idiot
๐Ÿ‘คEAP007


๐ŸŽ–@malwr
Binwalk
I've figured out how and when exactly to use Binwalk on files (JPG files for example, steganography).

But what is exactly Binwalk? How does it show me more files inside a file?

How does it work?
๐Ÿ—ฃblue8ird

It looks for file format signatures and for file headers/footers of different formats.

Btw a more common use case than steganography is extracting files from a firmware image.
๐Ÿ‘คTompazi


๐ŸŽ–@malwr