The Wine development release 6.4 is now available.
π£_-ammar-_
What's new in this release (see below for details):
\- Support for the DTLS protocol.
\- Fontset support in DirectWrite.
\- Dialog for editing Access Control entries.
\- Theming support for a few more common controls.
\- Support for Korean Wansung encoding. - Various bug fixes.
7416 Support multiple independent displays for PowerPoint, OpenOffice.org, etc
16676 RTG Bills 2.x (VB6 app) reports 'ADO error 1BD Object doesn't support this action' on startup (msado15 'connectionGetIDsOfNames' is a stub)
25323 Civilization IV Beyond the Sword crashed when trying to start a new game.
31814 Gecko should clean up when upgrading
36463 wine can't load unstripped gecko builds
36697 64-bit InstallShield engine COM server 'ISBEW64.exe' crashes or hangs (32-bit InstallShield based installers in 64-bit WINEPREFIX)
37011 acid3.acidtests.org can't load with builtin IE
38744 support UNITYNETWORKAREAREGION
39381 32-bit Turbocad 8.0 LTE 'CrashSender.exe' utility crashes in WMI Query "SELECT * FROM Win32NetworkAdapterConfiguration where IPEnabled='True' and index=1"
41433 Acrobat Reader XI (11.0.8): Annotations are empty
42827 Canon MP Navigator EX 4.x/5.x installer crashes due to setupapi SPFILENOTIFYFILEINCABINET handler/callback insufficiencies
46969 Multiple 64-bit WDM kernel drivers want Windows 8+ 'ntdll.RtlQueryRegistryValuesEx' (WIBUKEY, Denuvo Anti-Cheat)
48127 Soldiers of Anarchy (demos & full game 1.1.2.178), crashes with an 'Unknown error' message when starting a level
48879 NVIDIA PhysX System Software 9.12.1031 installer fails ('Add64BitReg' VBScript action needs minimal 'WbemScripting.SWbemNamedValueSet' implementation)
49531 Multiple Qt5 applications spam the console continuously with 'fixme:netprofm:connectionGetAdapterId' ('INetworkConnection::GetAdapter' returns incorrect adapter GUID)(Futubull 10.x, Melodics V2, Topaz Video Enhance AI 1.x)
49830 Obduction stops with "fatal error"
49998 widl doesn't support winrt types (runtimeclass, delegate, parameterized types, ...)
50123 The Elder Scrolls V: Skyrim SE has rendering glitches with vulkan renderer
50263 Entropia Universe: Won't Start the Game from Client Loader
50377 Banished cast shadows are broken with Vulkan renderer
50422 Multiple games (Horizon Zero Dawn, Serious Sam 4) crash on start on Nvidia due to missing unwrap for VKOBJECTTYPESURFACEKHR
50563 The Witcher 3: Wild Hunt has missing sunlight with Vulkan renderer
50632 Neverwinter: Broken graphics (texturing)
50641 Wine cmd handles incorrectly if-for on a single line
50642 Wine cmd handles incorrectly if-set when expanding variable with brackets
50667 Final Fantasy XI Online: Opening movie doesn't play (redux).
50678 Filmotech v3.91: partial black area
50698 ::wcsrtombs does not NULL "const wchart PSource" parameter in Wine.
50704 QueueUserAPC() Has Incorrect Error Set When Called On Terminating Thread
50706 6.2 hangs on grey, then crashes Snapdragon855(+) Android 10
50731 All Winelib applications built with winegcc/wineg++ segfault on startup as of Wine 6.3
50732 Multiple Adobe products fail to start due to Wine 6.3 breaking Adobe License Manager/FLEXnet Licensing Service (Acrobat 8.x, FrameMaker 8)
50740 The Suffering (Midway Games) crashes due to missing wmvcore 'IWMSyncReader2', CLSID '{faed3d21-1b6b-4af7-8cb6-3e189bbc187b}'
50744 continuous spamming of fixme:msctf:InputProcessorProfileMgrGetActiveProfile in console
50769 notepad: menu bar items and title text are not translated.
50774 DirectWrite should use mac platform name entry for English, if Windows entry is missing
50781 cl.exe fails to open program database
50786 WINEPATH env var broken by "ntdll: Set environment variables from the registry on the Unix side.
π€_-ammar-_
π@malwr
π£_-ammar-_
What's new in this release (see below for details):
\- Support for the DTLS protocol.
\- Fontset support in DirectWrite.
\- Dialog for editing Access Control entries.
\- Theming support for a few more common controls.
\- Support for Korean Wansung encoding. - Various bug fixes.
7416 Support multiple independent displays for PowerPoint, OpenOffice.org, etc
16676 RTG Bills 2.x (VB6 app) reports 'ADO error 1BD Object doesn't support this action' on startup (msado15 'connectionGetIDsOfNames' is a stub)
25323 Civilization IV Beyond the Sword crashed when trying to start a new game.
31814 Gecko should clean up when upgrading
36463 wine can't load unstripped gecko builds
36697 64-bit InstallShield engine COM server 'ISBEW64.exe' crashes or hangs (32-bit InstallShield based installers in 64-bit WINEPREFIX)
37011 acid3.acidtests.org can't load with builtin IE
38744 support UNITYNETWORKAREAREGION
39381 32-bit Turbocad 8.0 LTE 'CrashSender.exe' utility crashes in WMI Query "SELECT * FROM Win32NetworkAdapterConfiguration where IPEnabled='True' and index=1"
41433 Acrobat Reader XI (11.0.8): Annotations are empty
42827 Canon MP Navigator EX 4.x/5.x installer crashes due to setupapi SPFILENOTIFYFILEINCABINET handler/callback insufficiencies
46969 Multiple 64-bit WDM kernel drivers want Windows 8+ 'ntdll.RtlQueryRegistryValuesEx' (WIBUKEY, Denuvo Anti-Cheat)
48127 Soldiers of Anarchy (demos & full game 1.1.2.178), crashes with an 'Unknown error' message when starting a level
48879 NVIDIA PhysX System Software 9.12.1031 installer fails ('Add64BitReg' VBScript action needs minimal 'WbemScripting.SWbemNamedValueSet' implementation)
49531 Multiple Qt5 applications spam the console continuously with 'fixme:netprofm:connectionGetAdapterId' ('INetworkConnection::GetAdapter' returns incorrect adapter GUID)(Futubull 10.x, Melodics V2, Topaz Video Enhance AI 1.x)
49830 Obduction stops with "fatal error"
49998 widl doesn't support winrt types (runtimeclass, delegate, parameterized types, ...)
50123 The Elder Scrolls V: Skyrim SE has rendering glitches with vulkan renderer
50263 Entropia Universe: Won't Start the Game from Client Loader
50377 Banished cast shadows are broken with Vulkan renderer
50422 Multiple games (Horizon Zero Dawn, Serious Sam 4) crash on start on Nvidia due to missing unwrap for VKOBJECTTYPESURFACEKHR
50563 The Witcher 3: Wild Hunt has missing sunlight with Vulkan renderer
50632 Neverwinter: Broken graphics (texturing)
50641 Wine cmd handles incorrectly if-for on a single line
50642 Wine cmd handles incorrectly if-set when expanding variable with brackets
50667 Final Fantasy XI Online: Opening movie doesn't play (redux).
50678 Filmotech v3.91: partial black area
50698 ::wcsrtombs does not NULL "const wchart PSource" parameter in Wine.
50704 QueueUserAPC() Has Incorrect Error Set When Called On Terminating Thread
50706 6.2 hangs on grey, then crashes Snapdragon855(+) Android 10
50731 All Winelib applications built with winegcc/wineg++ segfault on startup as of Wine 6.3
50732 Multiple Adobe products fail to start due to Wine 6.3 breaking Adobe License Manager/FLEXnet Licensing Service (Acrobat 8.x, FrameMaker 8)
50740 The Suffering (Midway Games) crashes due to missing wmvcore 'IWMSyncReader2', CLSID '{faed3d21-1b6b-4af7-8cb6-3e189bbc187b}'
50744 continuous spamming of fixme:msctf:InputProcessorProfileMgrGetActiveProfile in console
50769 notepad: menu bar items and title text are not translated.
50774 DirectWrite should use mac platform name entry for English, if Windows entry is missing
50781 cl.exe fails to open program database
50786 WINEPATH env var broken by "ntdll: Set environment variables from the registry on the Unix side.
π€_-ammar-_
π@malwr
WineHQ
The Wine development release 6.4 is now available.
Reverse Engineering Microsoft Exchange DearCry Ransomware | Brief Analysis
π£MotasemHa
Two suggestions: get a better mic. Sometimes your voice sounds muffled. Itβs not your accent, Iβm spanish and I have a good ear for accents but your voice doesnβt come in clear.
Second: you need to zoom in because if someone is watching on a phone, we cannot see what you are seeing. It just looks like blobs to me. I wish I could understand what you are doing because I want to learn, but I just canβt from what you posted. Your set up looks nice but it needs to be edited to show code bigger. I understand if you see this on a computer you can see it big but not everyone is on a computer 24/7.
π€Simsimma76
π@malwr
π£MotasemHa
Two suggestions: get a better mic. Sometimes your voice sounds muffled. Itβs not your accent, Iβm spanish and I have a good ear for accents but your voice doesnβt come in clear.
Second: you need to zoom in because if someone is watching on a phone, we cannot see what you are seeing. It just looks like blobs to me. I wish I could understand what you are doing because I want to learn, but I just canβt from what you posted. Your set up looks nice but it needs to be edited to show code bigger. I understand if you see this on a computer you can see it big but not everyone is on a computer 24/7.
π€Simsimma76
π@malwr
YouTube
Reverse Engineering Microsoft Exchange DearCry Ransomware | Brief Analysis
In this video walkthrough, we did reverse engineering on the recent DearCry ransomware that hit Microsoft Exchange systems.
-------------------
Receive video documentation
https://www.youtube.com/channel/UCNSdU_1ehXtGclimTVckHmQ/join
----
Backup channel
β¦
-------------------
Receive video documentation
https://www.youtube.com/channel/UCNSdU_1ehXtGclimTVckHmQ/join
----
Backup channel
β¦
IoT Malware Journals: Prometei (Linux)
Technical analysis of Prometei (Linux):
https://cujo.com/iot-malware-journals-prometei-linux/
π£kernelv0id
π@malwr
Technical analysis of Prometei (Linux):
https://cujo.com/iot-malware-journals-prometei-linux/
π£kernelv0id
π@malwr
CUJO AI
IoT Malware Journals: Prometei (Linux) - CUJO AI
IoT threat researcher Albert Zsigovits takes a closer, technical look at the Linux version of Prometei, dissecting its capabilities and features.
Kuiper is a digital investigation platform that provides a capabilities for the investigation team and individuals to parse, search, visualize collected evidences (evidences could be collected by fast traige script like Hoarder). Collaborate with other team members on the same platforms.
π£digicat
Kuiper is OK for small businesses but is severely limited for anything bigger in my opinion. We had a look at it and it proved to be very basic and not always very reliable.
π€norfolkench4nts
π@malwr
π£digicat
Kuiper is OK for small businesses but is severely limited for anything bigger in my opinion. We had a look at it and it proved to be very basic and not always very reliable.
π€norfolkench4nts
π@malwr
GitHub
GitHub - DFIRKuiper/Kuiper: Digital Forensics Investigation Platform
Digital Forensics Investigation Platform. Contribute to DFIRKuiper/Kuiper development by creating an account on GitHub.
Exchange ProxyLogon SSRF RCE Vuln POC Mordor data set to validate detections etc.
π£digicat
π@malwr
π£digicat
π@malwr
Mordordatasets
Exchange ProxyLogon SSRF RCE Vuln POC
Exchange ProxyLogon SSRF RCE Vuln POC Metadata Author Roberto Rodriguez @Cyb3rWard0g Creation Date 2021/03/14 Modification Date 2021/03/14 Tacti
Trapdoor - A serverless HTTP honeypot/honeytoken
Available in the AWS Serverless Application Repository, Trapdoor is an open-source honeytoken platform with alerting, client fingerprinting and history tracking.
Github: [https://github.com/3CORESec/Trapdoor](https://github.com/3CORESec/Trapdoor)
Blog: https://blog.3coresec.com/2021/03/trapdoor-serverless-http-honeypot.html
I would love feedback from the community in case someone wants to chat about it.
π£0x229
π@malwr
Available in the AWS Serverless Application Repository, Trapdoor is an open-source honeytoken platform with alerting, client fingerprinting and history tracking.
Github: [https://github.com/3CORESec/Trapdoor](https://github.com/3CORESec/Trapdoor)
Blog: https://blog.3coresec.com/2021/03/trapdoor-serverless-http-honeypot.html
I would love feedback from the community in case someone wants to chat about it.
π£0x229
π@malwr
GitHub
GitHub - 3CORESec/Trapdoor: Serverless honeytoken π΅π»ββοΈ
Serverless honeytoken π΅π»ββοΈ. Contribute to 3CORESec/Trapdoor development by creating an account on GitHub.
IDA Pro 7.6 released
π£KindOne
The pricing has always confused me - Yes, its definitely worth that much, but i'd have to make at least the price of this software purely by what the program offers, and that will never be the case for anything I can imagine.
Not to even mention that there is an educational license, but they dont give it to students, that there is a home license which doesnt include the literal reason people use IDA over Ghidra, etc.
I really wonder if dropping a zero on those prices and getting a few thousand new customers would be so terrible.
π€LeeHide
The situation is still as pathetic as ever for non-commercial users. Cloud-based decompilers are a step backward into the always-online DRM of the 2000s. IDA Home feels less like a legitimate attempt to enter the hobbyist market than an excuse for Ilfak to keep whining when people keep pirating the pro version. "They could have used IDA Home instead!"... yeah, maybe if it wasn't crippleware.
π€Immediate_Sun_7906
π@malwr
π£KindOne
The pricing has always confused me - Yes, its definitely worth that much, but i'd have to make at least the price of this software purely by what the program offers, and that will never be the case for anything I can imagine.
Not to even mention that there is an educational license, but they dont give it to students, that there is a home license which doesnt include the literal reason people use IDA over Ghidra, etc.
I really wonder if dropping a zero on those prices and getting a few thousand new customers would be so terrible.
π€LeeHide
The situation is still as pathetic as ever for non-commercial users. Cloud-based decompilers are a step backward into the always-online DRM of the 2000s. IDA Home feels less like a legitimate attempt to enter the hobbyist market than an excuse for Ilfak to keep whining when people keep pirating the pro version. "They could have used IDA Home instead!"... yeah, maybe if it wasn't crippleware.
π€Immediate_Sun_7906
π@malwr
Cuckoo Sandbox with Docker
Hello guys,
I want to ask if anyone has used cuckoo sandbox in Docker container? I've checked some github repos but cannot find something useful.
π£serhattsnmz
Just use pip in python
π€gbdavidx
I've had difficulty getting it working in the past. Dunno if capev2 or panda.re have docker options (panda.re is qemu based so I doubt they do, possibly capev2)
π€3lpsy
Thatβs the reason i used cuckoo.cert.ee
π€Kantry123
π@malwr
Hello guys,
I want to ask if anyone has used cuckoo sandbox in Docker container? I've checked some github repos but cannot find something useful.
π£serhattsnmz
Just use pip in python
π€gbdavidx
I've had difficulty getting it working in the past. Dunno if capev2 or panda.re have docker options (panda.re is qemu based so I doubt they do, possibly capev2)
π€3lpsy
Thatβs the reason i used cuckoo.cert.ee
π€Kantry123
π@malwr
reddit
Cuckoo Sandbox with Docker
Hello guys, I want to ask if anyone has used cuckoo sandbox in Docker container? I've checked some github repos but cannot find something useful.
VirusTotal Chi2
Hi all,
I'm currently teaching myself the basics of malware analysis for my final project at university and have been working on a script to automate some static analysis. In doing so I've been using the VT API and noticed some objects contain a Chi2 value. I think Chi2 is used to measure the difference in distribution of elements in a dataset, but I am unsure which distributions are being compared here? To be specific, I am referring the the Chi2 value referenced in the PEInfo Sections objects. I appreciate any help :)
π£Origin144
So I think there are two different uses of the chi squared approximation algorithm here. I'll talk about each of them separately.
For the case of virus total, it looks like they're applying the chi-squared approximation algorithm to the entire file stream. The purpose of this calculation is similar to that of entropy and that it should help you determine whether or not a file is packed, encrypted, encoded, or obfuscated. The calculation is a little bit different than entropy, so It may help some machine learning models to differentiate between various specific packing, encryption, encoding, or obfuscation techniques. I don't have an intuitive sense of what values of chi-squared are more or less indicative of malware like I do entropy.
There was another research article that was posted a while back that used the chi squared approximation calculation to measure distance between the expected PE header fields of legitimate files to the file that's currently being looked at. The assumption being that the further the distance between the two data sets, as represented by the chi squared approximation value, the more likely the file is to be malicious.
From a machine learning perspective, the chi squared approximation almost seems to be a way of doing data compression on the initial feature set. As opposed to having a separate feature for each PE header field in the machine learning model, the features are compressed into a single chi squared approximation calculation and that's what's fed into the model. The purpose of doing that would be to reduce the total number of calculations, and thus time, required to classify an individual file. For real time malware detection, extremely short analysis times are required.
Link: https://link.springer.com/chapter/10.1007/978-3-319-19578-034
π€*FusionCarcass*
[https://developers.virustotal.com/v3.0/reference#dot\net_assembly](https://developers.virustotal.com/v3.0/reference#dotnetassembly)
>chi2
: <float\> chi-squared test value of stream data.
π€eclairum115
π@malwr
Hi all,
I'm currently teaching myself the basics of malware analysis for my final project at university and have been working on a script to automate some static analysis. In doing so I've been using the VT API and noticed some objects contain a Chi2 value. I think Chi2 is used to measure the difference in distribution of elements in a dataset, but I am unsure which distributions are being compared here? To be specific, I am referring the the Chi2 value referenced in the PEInfo Sections objects. I appreciate any help :)
π£Origin144
So I think there are two different uses of the chi squared approximation algorithm here. I'll talk about each of them separately.
For the case of virus total, it looks like they're applying the chi-squared approximation algorithm to the entire file stream. The purpose of this calculation is similar to that of entropy and that it should help you determine whether or not a file is packed, encrypted, encoded, or obfuscated. The calculation is a little bit different than entropy, so It may help some machine learning models to differentiate between various specific packing, encryption, encoding, or obfuscation techniques. I don't have an intuitive sense of what values of chi-squared are more or less indicative of malware like I do entropy.
There was another research article that was posted a while back that used the chi squared approximation calculation to measure distance between the expected PE header fields of legitimate files to the file that's currently being looked at. The assumption being that the further the distance between the two data sets, as represented by the chi squared approximation value, the more likely the file is to be malicious.
From a machine learning perspective, the chi squared approximation almost seems to be a way of doing data compression on the initial feature set. As opposed to having a separate feature for each PE header field in the machine learning model, the features are compressed into a single chi squared approximation calculation and that's what's fed into the model. The purpose of doing that would be to reduce the total number of calculations, and thus time, required to classify an individual file. For real time malware detection, extremely short analysis times are required.
Link: https://link.springer.com/chapter/10.1007/978-3-319-19578-034
π€*FusionCarcass*
[https://developers.virustotal.com/v3.0/reference#dot\net_assembly](https://developers.virustotal.com/v3.0/reference#dotnetassembly)
>chi2
: <float\> chi-squared test value of stream data.
π€eclairum115
π@malwr
reddit
VirusTotal Chi2
Hi all, I'm currently teaching myself the basics of malware analysis for my final project at university and have been working on a script to...