Girl.scr (Erica Ransomware) Analysis
https://www.dropbox.com/s/f4uulu2rhyj4leb/Girl.scr\_malware\_report.pdf?dl=0
π£dkaye_mal_anst18
Great analysis. May I ask what programs you tend to use for analysis? I normally have to rely on hybrid-analysis or other sites
π€aprillols
π@malwr
https://www.dropbox.com/s/f4uulu2rhyj4leb/Girl.scr\_malware\_report.pdf?dl=0
π£dkaye_mal_anst18
Great analysis. May I ask what programs you tend to use for analysis? I normally have to rely on hybrid-analysis or other sites
π€aprillols
π@malwr
Dropbox
Girl.scr_AnalysisPaper.pdf
Shared with Dropbox
Getting Started with Ghidra: Analyzing Process Hollowing Shellcode from a Maldoc
I've posted a video introducing shellcode analysis with Ghidra. The shellcode comes from an (old) maldoc and uses the windows API to execute shellcode for process hollowing. We'll also look at a Ghidra script that helps with stack strings.
https://youtu.be/JE6QCS6no1Y
​
https://preview.redd.it/hly30srujao41.jpg?width=1199&format=pjpg&auto=webp&s=ce0f4a65f43af3f8b31a115c3645729be537504c
π£jstrosch
π@malwr
I've posted a video introducing shellcode analysis with Ghidra. The shellcode comes from an (old) maldoc and uses the windows API to execute shellcode for process hollowing. We'll also look at a Ghidra script that helps with stack strings.
https://youtu.be/JE6QCS6no1Y
​
https://preview.redd.it/hly30srujao41.jpg?width=1199&format=pjpg&auto=webp&s=ce0f4a65f43af3f8b31a115c3645729be537504c
π£jstrosch
π@malwr
YouTube
Getting Started with Ghidra: Analyzing Process Hollowing Shellcode from a Maldoc
In this video, we'll reverse engineering shellcode with Ghidra that was used by a maldoc to perform process hollowing. We'll begin by briefly discussing how ...
Phishing in the Time of COVID-19: How to Recognize Malicious Coronavirus Phishing Scams
π£cyberg0100
π@malwr
π£cyberg0100
π@malwr
Electronic Frontier Foundation
Phishing in the Time of COVID-19: How to Recognize Malicious Coronavirus Phishing Scams
Update 3-26-20: A new prevalent example of Android Spyware that leverages COVID-19 as a way to deliver their malicious product has been reported by researchers at Lookout. This particular malware,
Cobaltstrike 4.0 Cracked?
Initial post: https://twitter.com/underthebreach/status/1241840589626322946
Analysis: https://twitter.com/Plazmaz/status/1241971383480901632
If this is indeed out in public now, expect many "users" to migrate from 3.0 for malicious activities.
π£Pir00t
π@malwr
Initial post: https://twitter.com/underthebreach/status/1241840589626322946
Analysis: https://twitter.com/Plazmaz/status/1241971383480901632
If this is indeed out in public now, expect many "users" to migrate from 3.0 for malicious activities.
π£Pir00t
π@malwr
Twitter
Alon Gal (Under the Breach)
@msd0s7 I prefer to refrain from re-uploading it myself, though it did get re-uploaded on a different forum. * I DON'T VOUCH FOR THIS SPECIFIC LINK, BE CAUTIOUS! no one called him out so far so I do think it is legit but due diligence should be done on yourβ¦
Microsoft warns of 2 critical RCE vulnerabilities in all recent versions of Windows
π£Kanishkt23
MS intended to release patch in next month (14/April). That's very bad.
π€Homemade-Cupcake
π@malwr
π£Kanishkt23
MS intended to release patch in next month (14/April). That's very bad.
π€Homemade-Cupcake
π@malwr
Beazley Breach Briefing: Ransomware remains top cyber security threat for businesses
π£what-s-up
π@malwr
π£what-s-up
π@malwr
CRWE World
Beazley Breach Briefing: Ransomware remains top cyber security threat for businesses
Shift to home working heightens risk of cyber breach via remote desktop protocol and phishing attacksNew York, March 23, 2020 (GLOBE NEWSWIRE) -- Ransomware attacks skyrocketed in 2019, according to the latest Beazley Breach Briefing, an
All the IOC's this person has gathered which are used directly in coronavirus / covid-19 / SARS-CoV-2 cyber attack campaigns
π£digicat
Another reresource: https://www.activecypher.com/covid-19-cyberthreats/
π@malwr
π£digicat
Another reresource: https://www.activecypher.com/covid-19-cyberthreats/
π@malwr
GitHub
GitHub - parthdmaniar/coronavirus-covid-19-SARS-CoV-2-IoCs: All the IOC's I have gathered which are used directly involved coronavirusβ¦
All the IOC's I have gathered which are used directly involved coronavirus / covid-19 / SARS-CoV-2 cyber attack campaigns - GitHub - parthdmaniar/coronavirus-covid-19-SARS-CoV-2-IoCs: All t...
Reverse engineering Blind's API and client side encryption
π£speckz
Nice article! I myself need to learn more about javacript reversing. Always seems so tedious
π€blabbities
Neat.
Why doesn't the client generate a custom AES key on start up and transmit that using pubic/private key encryption to Blind? That would avoid the issue of having the AES key in the source code, and make the whole shebang infinitely more secure. Or am I missing something?
π€FlynnClubbaire
π@malwr
π£speckz
Nice article! I myself need to learn more about javacript reversing. Always seems so tedious
π€blabbities
Neat.
Why doesn't the client generate a custom AES key on start up and transmit that using pubic/private key encryption to Blind? That would avoid the issue of having the AES key in the source code, and make the whole shebang infinitely more secure. Or am I missing something?
π€FlynnClubbaire
π@malwr
Autopsy of the Most Stable MediaTek Rootkit (CVE-2020-0069)
https://blog.quarkslab.com/cve-2020-0069-autopsy-of-the-most-stable-mediatek-rootkit.html
π@malwr
https://blog.quarkslab.com/cve-2020-0069-autopsy-of-the-most-stable-mediatek-rootkit.html
π@malwr
Quarkslab
CVE-2020-0069: Autopsy of the Most Stable MediaTek Rootkit - Quarkslab's blog
In March 2020, Google patched a critical vulnerability affecting many MediaTek based devices. This vulnerability had been known by MediaTek since April 2019, and later exploited in the wild! In this post, we give some details about this vulnerability andβ¦
MalwareBazaar β welcome to the abuse-ch malware repository
π£quellaman
Unlike Virustotal, MalwareBazaar follows a different approach:
MalwareBazaar only tracks malware samples. No Adware (PUA/PUP). No benign files
MalwareBazaar is not a multi antivirus scanning engine
You can upload and download as many malware samples as you want
Itβs completely free!
π@malwr
π£quellaman
Unlike Virustotal, MalwareBazaar follows a different approach:
MalwareBazaar only tracks malware samples. No Adware (PUA/PUP). No benign files
MalwareBazaar is not a multi antivirus scanning engine
You can upload and download as many malware samples as you want
Itβs completely free!
π@malwr
Security Affairs
MalwareBazaar - welcome to the abuse-ch malware repository
Abuse.ch launched the MalwareBazaar service, a malware repository to allow experts to share known malware samples and related info.