APT-C-36 new anti-detection tricks
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
Dear Windows Defender, please tell me where I can drop my malicious code
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
Medium
Dear Windows Defender, please tell me where I can drop my malicious code.
The Get-MpPreference cmdlet exposes the field ExclusionPath without administrator privilege.
How the Iranian Cyber Security Agency Detects Emissary Panda Malware
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
Team Cymru
Blog - Team Cymru
This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
Security Intelligence
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
Our team is closely monitoring TrickBot's developing capabilities, including its new cross-channel attacks using the TrickMo component.
Icnanker, a Linux Trojan-Downloader Protected by SHC
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
360 Netlab Blog - Network Security Research Lab at 360
Icnanker, a Linux Trojan-Downloader Protected by SHC
Background
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
BleepingComputer
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
π£FourFans0fFreedom
π@malwr
π£FourFans0fFreedom
π@malwr
Defense One
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
In January, the βwidespreadβ assault targeted a vulnerability in virtual desktops, cloud computing, and network applications, FireEye announced.
Operation Poisoned News: Hong Kong Users Targeted With Mobile Malware via Local News Links
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
Trend Micro
Research, News, and Perspectives
Azorult loader stages
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr
SharpML - Active Directory Password Hunting with ML for File-Shares
π£hunniccyber
Nice approach there!
You might want to have ML-folks/data scientists to chime in here; please add samples of the training data you used; above that, I couldnβt find any hints at the actual accuracy. NLP has seen some great results lately - keep experimenting!
Along the lines you mentioned potentially lacking (ML) domain knowledge - but still you will be offering a paid course - Iβd rather render this into a joint research/project initiative. But these are just my 2 quarantined cents =]
π€vornamemitd
π@malwr
π£hunniccyber
Nice approach there!
You might want to have ML-folks/data scientists to chime in here; please add samples of the training data you used; above that, I couldnβt find any hints at the actual accuracy. NLP has seen some great results lately - keep experimenting!
Along the lines you mentioned potentially lacking (ML) domain knowledge - but still you will be offering a paid course - Iβd rather render this into a joint research/project initiative. But these are just my 2 quarantined cents =]
π€vornamemitd
π@malwr
Hunnic Cyber Blog
Password Hunting with Machine Learning in Active Directory
tdlr: Situation: - Passwords embedded in files on fileshares lead to compromise. Complication: - It is hard to tell what is a password. Resolution: - Use SharpML toβ¦
Looking to learn about system exploitation, but don't know where to start? This (very) detailed guide covers all the basics. Contains 21 detailed CTF solutions, plenty of theory, and zero times the phrase "exercise left to the reader".
π£ynvb
> The standard answer is often an embarrassed mumble that there are no golden rules, and that you should probably follow this or that person on Twitter to get tips, then βgo practice, like you would with CTF exercises.β
CTF exercises are basically self-contained challenges that require the player to crack some problem and recover some piece of text (the βflagβ) as a proof of having cracked the problem.
This is always my answer to this question.
π€MaliciouSSymbol
Thank you!!!
π€redimusu76
This is a great read. I hope more of this pops up.
π€snake_case_believer
π@malwr
π£ynvb
> The standard answer is often an embarrassed mumble that there are no golden rules, and that you should probably follow this or that person on Twitter to get tips, then βgo practice, like you would with CTF exercises.β
CTF exercises are basically self-contained challenges that require the player to crack some problem and recover some piece of text (the βflagβ) as a proof of having cracked the problem.
This is always my answer to this question.
π€MaliciouSSymbol
Thank you!!!
π€redimusu76
This is a great read. I hope more of this pops up.
π€snake_case_believer
π@malwr
Check Point Research
"I want to learn about exploitation! Where do I start?" - Check Point Research
A comprehensive exploitation ("hacking") tutorial based on Georgia Tech's pwnable.kr exercises. Theory, hands-on exercises and detailed solutions.
Writing Your First Bootloader for Better Analyses
https://marcoramilli.com/2019/09/03/writing-your-first-bootloader-for-better-analyses/
π@malwr
https://marcoramilli.com/2019/09/03/writing-your-first-bootloader-for-better-analyses/
π@malwr
Marco Ramilli Web Corner
Writing Your First Bootloader for Better Analyses
From time to time we might observe special Malware storing themselves into a MBR and run during the booting process. Attackers could use this neat technique to infect and to mess-up your disk and eβ¦
InQL Scanner: can be used as a stand-alone script, or as a Burp Suite extension (available for both Professional and Community editions) to assess GraphQL
π£digicat
π@malwr
π£digicat
π@malwr
Doyensec
InQL Scanner
As a part of our continuing security research journey, we started developing an internal tool to speed-up GraphQL security testing efforts. Weβre excited to announce that InQL is available on Github.