All the IOC's this person has gathered which are used directly in coronavirus / covid-19 / SARS-CoV-2 cyber attack campaigns
π£digicat
Another reresource: https://www.activecypher.com/covid-19-cyberthreats/
π@malwr
π£digicat
Another reresource: https://www.activecypher.com/covid-19-cyberthreats/
π@malwr
GitHub
GitHub - parthdmaniar/coronavirus-covid-19-SARS-CoV-2-IoCs: All the IOC's I have gathered which are used directly involved coronavirusβ¦
All the IOC's I have gathered which are used directly involved coronavirus / covid-19 / SARS-CoV-2 cyber attack campaigns - GitHub - parthdmaniar/coronavirus-covid-19-SARS-CoV-2-IoCs: All t...
Reverse engineering Blind's API and client side encryption
π£speckz
Nice article! I myself need to learn more about javacript reversing. Always seems so tedious
π€blabbities
Neat.
Why doesn't the client generate a custom AES key on start up and transmit that using pubic/private key encryption to Blind? That would avoid the issue of having the AES key in the source code, and make the whole shebang infinitely more secure. Or am I missing something?
π€FlynnClubbaire
π@malwr
π£speckz
Nice article! I myself need to learn more about javacript reversing. Always seems so tedious
π€blabbities
Neat.
Why doesn't the client generate a custom AES key on start up and transmit that using pubic/private key encryption to Blind? That would avoid the issue of having the AES key in the source code, and make the whole shebang infinitely more secure. Or am I missing something?
π€FlynnClubbaire
π@malwr
Autopsy of the Most Stable MediaTek Rootkit (CVE-2020-0069)
https://blog.quarkslab.com/cve-2020-0069-autopsy-of-the-most-stable-mediatek-rootkit.html
π@malwr
https://blog.quarkslab.com/cve-2020-0069-autopsy-of-the-most-stable-mediatek-rootkit.html
π@malwr
Quarkslab
CVE-2020-0069: Autopsy of the Most Stable MediaTek Rootkit - Quarkslab's blog
In March 2020, Google patched a critical vulnerability affecting many MediaTek based devices. This vulnerability had been known by MediaTek since April 2019, and later exploited in the wild! In this post, we give some details about this vulnerability andβ¦
MalwareBazaar β welcome to the abuse-ch malware repository
π£quellaman
Unlike Virustotal, MalwareBazaar follows a different approach:
MalwareBazaar only tracks malware samples. No Adware (PUA/PUP). No benign files
MalwareBazaar is not a multi antivirus scanning engine
You can upload and download as many malware samples as you want
Itβs completely free!
π@malwr
π£quellaman
Unlike Virustotal, MalwareBazaar follows a different approach:
MalwareBazaar only tracks malware samples. No Adware (PUA/PUP). No benign files
MalwareBazaar is not a multi antivirus scanning engine
You can upload and download as many malware samples as you want
Itβs completely free!
π@malwr
Security Affairs
MalwareBazaar - welcome to the abuse-ch malware repository
Abuse.ch launched the MalwareBazaar service, a malware repository to allow experts to share known malware samples and related info.
Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers
https://www.virusbulletin.com/virusbulletin/2020/03/vb2019-paper-attribution-object-using-rtf-object-dimensions-track-apt-phishing-weaponizers/
π@malwr
https://www.virusbulletin.com/virusbulletin/2020/03/vb2019-paper-attribution-object-using-rtf-object-dimensions-track-apt-phishing-weaponizers/
π@malwr
Virusbulletin
Virus Bulletin :: VB2019 paper: Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers
Anomali Labs has conducted an in-depth study of the unique object dimensions present in weaponized RTF exploits used in phishing attacks. Through this research we have found that the developers of malicious RTF weaponizers leave behind a unique fingerprintβ¦
Frida 12.8.15 is out w/ full support for iOS/arm64e and iOS 13.4
π£oleavr
Says it was released is December 2019?
π€tigr87
I simple getting started guide if interested.
https://frida.re/docs/ios/
π€littlejob
π@malwr
π£oleavr
Says it was released is December 2019?
π€tigr87
I simple getting started guide if interested.
https://frida.re/docs/ios/
π€littlejob
π@malwr
Frida β’ A world-class dynamic instrumentation toolkit
iOS
Observe and reprogram running programs on Windows, macOS, GNU/Linux, iOS, watchOS, tvOS, Android, FreeBSD, and QNX
Understanding Hardware-enforced Stack Protection
https://techcommunity.microsoft.com/t5/windows-kernel-internals/understanding-hardware-enforced-stack-protection/ba-p/1247815
π@malwr
https://techcommunity.microsoft.com/t5/windows-kernel-internals/understanding-hardware-enforced-stack-protection/ba-p/1247815
π@malwr
TECHCOMMUNITY.MICROSOFT.COM
Understanding Hardware-enforced Stack Protection
ROP (Return Oriented Programming) based control flow attacks have become a common form of attack. In this post, we will describe our efforts to harden control..
APT-C-36 new anti-detection tricks
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
Dear Windows Defender, please tell me where I can drop my malicious code
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
Medium
Dear Windows Defender, please tell me where I can drop my malicious code.
The Get-MpPreference cmdlet exposes the field ExclusionPath without administrator privilege.
How the Iranian Cyber Security Agency Detects Emissary Panda Malware
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
Team Cymru
Blog - Team Cymru
This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
Security Intelligence
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
Our team is closely monitoring TrickBot's developing capabilities, including its new cross-channel attacks using the TrickMo component.
Icnanker, a Linux Trojan-Downloader Protected by SHC
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
360 Netlab Blog - Network Security Research Lab at 360
Icnanker, a Linux Trojan-Downloader Protected by SHC
Background
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
BleepingComputer
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
π£FourFans0fFreedom
π@malwr
π£FourFans0fFreedom
π@malwr
Defense One
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
In January, the βwidespreadβ assault targeted a vulnerability in virtual desktops, cloud computing, and network applications, FireEye announced.