Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Girl.scr (Erica Ransomware) Analysis
https://www.dropbox.com/s/f4uulu2rhyj4leb/Girl.scr\_malware\_report.pdf?dl=0
๐Ÿ—ฃdkaye_mal_anst18

Great analysis. May I ask what programs you tend to use for analysis? I normally have to rely on hybrid-analysis or other sites
๐Ÿ‘คaprillols


๐ŸŽ–@malwr
Getting Started with Ghidra: Analyzing Process Hollowing Shellcode from a Maldoc
I've posted a video introducing shellcode analysis with Ghidra. The shellcode comes from an (old) maldoc and uses the windows API to execute shellcode for process hollowing. We'll also look at a Ghidra script that helps with stack strings.

https://youtu.be/JE6QCS6no1Y

​

https://preview.redd.it/hly30srujao41.jpg?width=1199&format=pjpg&auto=webp&s=ce0f4a65f43af3f8b31a115c3645729be537504c
๐Ÿ—ฃjstrosch


๐ŸŽ–@malwr
Microsoft warns of 2 critical RCE vulnerabilities in all recent versions of Windows
๐Ÿ—ฃKanishkt23

MS intended to release patch in next month (14/April). That's very bad.
๐Ÿ‘คHomemade-Cupcake


๐ŸŽ–@malwr
Reverse engineering Blind's API and client side encryption
๐Ÿ—ฃspeckz

Nice article! I myself need to learn more about javacript reversing. Always seems so tedious
๐Ÿ‘คblabbities

Neat.

Why doesn't the client generate a custom AES key on start up and transmit that using pubic/private key encryption to Blind? That would avoid the issue of having the AES key in the source code, and make the whole shebang infinitely more secure. Or am I missing something?
๐Ÿ‘คFlynnClubbaire


๐ŸŽ–@malwr