Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
The Wine development release 6.4 is now available.
πŸ—£_-ammar-_

What's new in this release (see below for details):

\- Support for the DTLS protocol.

\- Fontset support in DirectWrite.

\- Dialog for editing Access Control entries.

\- Theming support for a few more common controls.

\- Support for Korean Wansung encoding. - Various bug fixes.


7416 Support multiple independent displays for PowerPoint, OpenOffice.org, etc
16676 RTG Bills 2.x (VB6 app) reports 'ADO error 1BD Object doesn't support this action' on startup (msado15 'connectionGetIDsOfNames' is a stub)
25323 Civilization IV Beyond the Sword crashed when trying to start a new game.
31814 Gecko should clean up when upgrading
36463 wine can't load unstripped gecko builds
36697 64-bit InstallShield engine COM server 'ISBEW64.exe' crashes or hangs (32-bit InstallShield based installers in 64-bit WINEPREFIX)
37011
acid3.acidtests.org can't load with builtin IE
38744 support
UNITYNETWORKAREAREGION
39381 32-bit Turbocad 8.0 LTE 'CrashSender.exe' utility crashes in WMI Query "SELECT * FROM Win32
NetworkAdapterConfiguration where IPEnabled='True' and index=1"
41433 Acrobat Reader XI (11.0.8): Annotations are empty
42827 Canon MP Navigator EX 4.x/5.x installer crashes due to setupapi SPFILENOTIFYFILEINCABINET handler/callback insufficiencies
46969 Multiple 64-bit WDM kernel drivers want Windows 8+ 'ntdll.RtlQueryRegistryValuesEx' (WIBUKEY, Denuvo Anti-Cheat)
48127 Soldiers of Anarchy (demos & full game
1.1.2.178), crashes with an 'Unknown error' message when starting a level
48879 NVIDIA PhysX System Software 9.12.1031 installer fails ('Add64Bit
Reg' VBScript action needs minimal 'WbemScripting.SWbemNamedValueSet' implementation)
49531 Multiple Qt5 applications spam the console continuously with 'fixme:netprofm:connectionGetAdapterId' ('INetworkConnection::GetAdapter' returns incorrect adapter GUID)(Futubull 10.x, Melodics V2, Topaz Video Enhance AI 1.x)
49830 Obduction stops with "fatal error"
49998 widl doesn't support winrt types (runtimeclass, delegate, parameterized types, ...)
50123 The Elder Scrolls V: Skyrim SE has rendering glitches with vulkan renderer
50263 Entropia Universe: Won't Start the Game from Client Loader
50377 Banished cast shadows are broken with Vulkan renderer
50422 Multiple games (Horizon Zero Dawn, Serious Sam 4) crash on start on Nvidia due to missing unwrap for VK
OBJECTTYPESURFACEKHR
50563 The Witcher 3: Wild Hunt has missing sunlight with Vulkan renderer
50632 Neverwinter: Broken graphics (texturing)
50641 Wine cmd handles incorrectly if-for on a single line
50642 Wine cmd handles incorrectly if-set when expanding variable with brackets
50667 Final Fantasy XI Online: Opening movie doesn't play (redux).
50678 Filmotech v3.91: partial black area
50698 ::wcsrtombs does not NULL "const wchar
t PSource" parameter in Wine.
50704 QueueUserAPC() Has Incorrect Error Set When Called On Terminating Thread
50706 6.2 hangs on grey, then crashes Snapdragon855(+) Android 10
50731 All Winelib applications built with winegcc/wineg++ segfault on startup as of Wine 6.3
50732 Multiple Adobe products fail to start due to Wine 6.3 breaking Adobe License Manager/FLEXnet Licensing Service (Acrobat 8.x, FrameMaker 8)
50740 The Suffering (Midway Games) crashes due to missing wmvcore 'IWMSyncReader2', CLSID '{faed3d21-1b6b-4af7-8cb6-3e189bbc187b}'
50744 continuous spamming of fixme:msctf:InputProcessorProfileMgr
GetActiveProfile in console
50769 notepad: menu bar items and title text are not translated.
50774 DirectWrite should use mac platform name entry for English, if Windows entry is missing
50781 cl.exe fails to open program database
50786 WINEPATH env var broken by "ntdll: Set environment variables from the registry on the Unix side.
πŸ‘€_-ammar-_


πŸŽ–@malwr
Reverse Engineering Microsoft Exchange DearCry Ransomware | Brief Analysis
πŸ—£MotasemHa

Two suggestions: get a better mic. Sometimes your voice sounds muffled. It’s not your accent, I’m spanish and I have a good ear for accents but your voice doesn’t come in clear.
Second: you need to zoom in because if someone is watching on a phone, we cannot see what you are seeing. It just looks like blobs to me. I wish I could understand what you are doing because I want to learn, but I just can’t from what you posted. Your set up looks nice but it needs to be edited to show code bigger. I understand if you see this on a computer you can see it big but not everyone is on a computer 24/7.
πŸ‘€Simsimma76


πŸŽ–@malwr
Trapdoor - A serverless HTTP honeypot/honeytoken
Available in the AWS Serverless Application Repository, Trapdoor is an open-source honeytoken platform with alerting, client fingerprinting and history tracking.

Github: [https://github.com/3CORESec/Trapdoor](https://github.com/3CORESec/Trapdoor)
Blog: https://blog.3coresec.com/2021/03/trapdoor-serverless-http-honeypot.html

I would love feedback from the community in case someone wants to chat about it.
πŸ—£0x229


πŸŽ–@malwr
IDA Pro 7.6 released
πŸ—£KindOne

The pricing has always confused me - Yes, its definitely worth that much, but i'd have to make at least the price of this software purely by what the program offers, and that will never be the case for anything I can imagine.

Not to even mention that there is an educational license, but they dont give it to students, that there is a home license which doesnt include the literal reason people use IDA over Ghidra, etc.

I really wonder if dropping a zero on those prices and getting a few thousand new customers would be so terrible.
πŸ‘€LeeHide

The situation is still as pathetic as ever for non-commercial users. Cloud-based decompilers are a step backward into the always-online DRM of the 2000s. IDA Home feels less like a legitimate attempt to enter the hobbyist market than an excuse for Ilfak to keep whining when people keep pirating the pro version. "They could have used IDA Home instead!"... yeah, maybe if it wasn't crippleware.
πŸ‘€Immediate_Sun_7906


πŸŽ–@malwr
Cuckoo Sandbox with Docker
Hello guys,

I want to ask if anyone has used cuckoo sandbox in Docker container? I've checked some github repos but cannot find something useful.
πŸ—£serhattsnmz

Just use pip in python
πŸ‘€gbdavidx

I've had difficulty getting it working in the past. Dunno if capev2 or panda.re have docker options (panda.re is qemu based so I doubt they do, possibly capev2)
πŸ‘€3lpsy

That’s the reason i used cuckoo.cert.ee
πŸ‘€Kantry123


πŸŽ–@malwr
VirusTotal Chi2
Hi all,

I'm currently teaching myself the basics of malware analysis for my final project at university and have been working on a script to automate some static analysis. In doing so I've been using the VT API and noticed some objects contain a Chi2 value. I think Chi2 is used to measure the difference in distribution of elements in a dataset, but I am unsure which distributions are being compared here? To be specific, I am referring the the Chi2 value referenced in the PEInfo Sections objects. I appreciate any help :)
πŸ—£Origin144

So I think there are two different uses of the chi squared approximation algorithm here. I'll talk about each of them separately.

For the case of virus total, it looks like they're applying the chi-squared approximation algorithm to the entire file stream. The purpose of this calculation is similar to that of entropy and that it should help you determine whether or not a file is packed, encrypted, encoded, or obfuscated. The calculation is a little bit different than entropy, so It may help some machine learning models to differentiate between various specific packing, encryption, encoding, or obfuscation techniques. I don't have an intuitive sense of what values of chi-squared are more or less indicative of malware like I do entropy.

There was another research article that was posted a while back that used the chi squared approximation calculation to measure distance between the expected PE header fields of legitimate files to the file that's currently being looked at. The assumption being that the further the distance between the two data sets, as represented by the chi squared approximation value, the more likely the file is to be malicious.

From a machine learning perspective, the chi squared approximation almost seems to be a way of doing data compression on the initial feature set. As opposed to having a separate feature for each PE header field in the machine learning model, the features are compressed into a single chi squared approximation calculation and that's what's fed into the model. The purpose of doing that would be to reduce the total number of calculations, and thus time, required to classify an individual file. For real time malware detection, extremely short analysis times are required.

Link: https://link.springer.com/chapter/10.1007/978-3-319-19578-034
πŸ‘€*FusionCarcass*

[
https://developers.virustotal.com/v3.0/reference#dot\net_assembly](https://developers.virustotal.com/v3.0/reference#dotnetassembly)

>chi2
: <float\> chi-squared test value of stream data.
πŸ‘€eclairum115


πŸŽ–@malwr