FAST FLUX
https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/fast-flux/
ℹ️ Sent from one of our members
🎖@malwr
https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/fast-flux/
ℹ️ Sent from one of our members
🎖@malwr
Outpost24
Fast flux | Outpost 24 blog
In this post we want to share details about a study that we have carried out on a Fast Flux network operated by the creators of the Ursnif malware. Our main objective is to shed some light on this type of network and what kind of activities are developed…
Investigating a unique "form" of email delivery for IcedID malware - Microsoft Security
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
Microsoft Security Blog
Investigating a unique "form" of email delivery for IcedID malware | Microsoft Security Blog
Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence…
Justice Department Announces Court-Authorized Effort to Disrupt Exploitation of Microsoft Exchange Server Vulnerabilities | OPA
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
www.justice.gov
Justice Department Announces Court-Authorized Effort to Disrupt
The Justice Department today announced a court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable computers in the United States running on-premises versions of Microsoft Exchange Server, software used to provide enterprise…
Exploit for pwn2own Chrome zeroday released by third party researcher
🗣digicat
this is a patch gap risk..
👤digicat
🎖@malwr
🗣digicat
this is a patch gap risk..
👤digicat
🎖@malwr
[Video Makop Ransomware - Decrypting the Encrypted Section](https://youtu.be/mlIRoGrxrmA)
🗣Struppigel
Cool stuff. Thanks for the info and please post more!
👤skully_kiddo
🎖@malwr
🗣Struppigel
Cool stuff. Thanks for the info and please post more!
👤skully_kiddo
🎖@malwr
YouTube
Makop Ransomware - Decrypting the Encrypted Section
SHA256: bc0ed3e73b8d1fdc839f2e8ed3578ca3221dba4eb984e581cb00dfb4cdfb7d49
Complete Malware Analysis VM Image
Complete Malware Analysis VM Image
is there a complate malware analysis vm image that contains most of the decompilers, PE analysers, debuggers, monitoring tools, etc..
thanks!!
p.s. i know that there is flare VM that is free to install but it seems not complete.
🗣darkalimdor18
There’s no “complete” and “most perfect” image, new tools and plugins are published every day and no one can keep up with them all.
You should be able to customize your own image based on your own needs and most importantly skills, there’s no need to downloaded tons of tools and you barely know anything about most of them.
👤MO12400
I would do two things: install something like Remnux and use it as a “wall”. Then install something like Flare to start learning what you like. Eventually either tweak it to your liking, or build an image with your own stuff. Knowing how to install it and configure it is invaluable knowledge. Plus you can then learn other apps to auto-build VMs of your choice with customizations you need for types of malware you are analyzing.
Route all traffic through Remnux. You can then drop traffic outbound but still capture traffic, use Burpe Suite and other tools to dynamically identify C2 and communications safely.
👤FlaccidKraken
Yeah I second REMnux, it’s native Linux but there’s also a Windows version if you can find someone who has taken the GREM. The Windows one is called REMnux Workstation.
👤Th3_Pr0f3ss0r
🎖@malwr
Complete Malware Analysis VM Image
is there a complate malware analysis vm image that contains most of the decompilers, PE analysers, debuggers, monitoring tools, etc..
thanks!!
p.s. i know that there is flare VM that is free to install but it seems not complete.
🗣darkalimdor18
There’s no “complete” and “most perfect” image, new tools and plugins are published every day and no one can keep up with them all.
You should be able to customize your own image based on your own needs and most importantly skills, there’s no need to downloaded tons of tools and you barely know anything about most of them.
👤MO12400
I would do two things: install something like Remnux and use it as a “wall”. Then install something like Flare to start learning what you like. Eventually either tweak it to your liking, or build an image with your own stuff. Knowing how to install it and configure it is invaluable knowledge. Plus you can then learn other apps to auto-build VMs of your choice with customizations you need for types of malware you are analyzing.
Route all traffic through Remnux. You can then drop traffic outbound but still capture traffic, use Burpe Suite and other tools to dynamically identify C2 and communications safely.
👤FlaccidKraken
Yeah I second REMnux, it’s native Linux but there’s also a Windows version if you can find someone who has taken the GREM. The Windows one is called REMnux Workstation.
👤Th3_Pr0f3ss0r
🎖@malwr
reddit
Complete Malware Analysis VM Image
**Complete Malware Analysis VM Image** is there a complate malware analysis vm image that contains most of the decompilers, PE analysers,...
Open Source Archive of Legal Threats Made Against Genuine Security Researchers (Creative Commons!)
🗣docker-osx
Add Steam to that list for the recent issue brought up.
👤drimgere
Let this be a wakeup call to everyone to always keep in mind that companies can and might screw you over despite your good intentions and protect yourselves accordingly.
👤267aa37673a9fa659490
This list has to be taken with a huge grain of salt as researcher sometimes try to paint themselves in a much nicer way that what really happened. The Skytech entry is a pretty example of this as I know a little bit the inside of it. The "researcher" received threat from the company not because he disclosed a vulnerability, but because he DoSed the company system from the Dawson network connection. The fact that he disclosed a vulnerability before had nothing to do with the threat he received. Also a lot of the threat he received where not from Skytech, but from Dawson. The reason ? He continued to "test" the school internal system (that didn't belong to Skytech) after being told to stop.
👤Cold-Mix357
🎖@malwr
🗣docker-osx
Add Steam to that list for the recent issue brought up.
👤drimgere
Let this be a wakeup call to everyone to always keep in mind that companies can and might screw you over despite your good intentions and protect yourselves accordingly.
👤267aa37673a9fa659490
This list has to be taken with a huge grain of salt as researcher sometimes try to paint themselves in a much nicer way that what really happened. The Skytech entry is a pretty example of this as I know a little bit the inside of it. The "researcher" received threat from the company not because he disclosed a vulnerability, but because he DoSed the company system from the Dawson network connection. The fact that he disclosed a vulnerability before had nothing to do with the threat he received. Also a lot of the threat he received where not from Skytech, but from Dawson. The reason ? He continued to "test" the school internal system (that didn't belong to Skytech) after being told to stop.
👤Cold-Mix357
🎖@malwr
GitHub
GitHub - disclose/research-threats: Collection of legal threats against good faith Security Researchers; vulnerability disclosure…
Collection of legal threats against good faith Security Researchers; vulnerability disclosure gone wrong. A continuation of work started by @attritionorg - disclose/research-threats
Microsoft 365 Dev subscriptions free with Dev Essentials (also free)
🗣cryolithic
I’m going to make so many word documents it will be like a 730 day trial
👤Jaimz22
Only 90 day trial
👤xxbiohazrdxx
I saw they added what seems like a slew of additional freebies.
👤nameandfaceless
🎖@malwr
🗣cryolithic
I’m going to make so many word documents it will be like a 730 day trial
👤Jaimz22
Only 90 day trial
👤xxbiohazrdxx
I saw they added what seems like a slew of additional freebies.
👤nameandfaceless
🎖@malwr
ATT SMS record analysis
I've been asked to provide some analysis of SMS records which were subpoenaed from the carrier but am having a little trouble resolving a few things. There are several messages from a two digit phone number and several instances where two or three messages were sent by the phone at the exact same time (down to the second). It appears to me that the messages sent at the same time were likely long messages broken up into 2 or 3 messages due to character limits, but I can't really come up with anything that would allow a two digit phone number to deliver messages. Any help would be greatly appreciated.
🗣kstewart0x00
I often find that those records reflect carrier services, like paying a bill, checking data plan current usage, and messages regarding the account.
If you received this data in a subpoena return, there should be a document explaining these numbers. When in doubt, I usually call the division that supplied the records.
👤chilledquesadilla
Could they be something that came from AT&T?
Is it from a service? or is it a conversation?
Here's someone asking AT&T the same question about messages on their bill. And AT&T providing stellar customer service, too.
https://forums.att.com/conversations/wireless-account/2-digit-phone-number/5defd200bad5f2f606f76a5c
👤technologite
🎖@malwr
I've been asked to provide some analysis of SMS records which were subpoenaed from the carrier but am having a little trouble resolving a few things. There are several messages from a two digit phone number and several instances where two or three messages were sent by the phone at the exact same time (down to the second). It appears to me that the messages sent at the same time were likely long messages broken up into 2 or 3 messages due to character limits, but I can't really come up with anything that would allow a two digit phone number to deliver messages. Any help would be greatly appreciated.
🗣kstewart0x00
I often find that those records reflect carrier services, like paying a bill, checking data plan current usage, and messages regarding the account.
If you received this data in a subpoena return, there should be a document explaining these numbers. When in doubt, I usually call the division that supplied the records.
👤chilledquesadilla
Could they be something that came from AT&T?
Is it from a service? or is it a conversation?
Here's someone asking AT&T the same question about messages on their bill. And AT&T providing stellar customer service, too.
https://forums.att.com/conversations/wireless-account/2-digit-phone-number/5defd200bad5f2f606f76a5c
👤technologite
🎖@malwr
reddit
ATT SMS record analysis
I've been asked to provide some analysis of SMS records which were subpoenaed from the carrier but am having a little trouble resolving a few...
Reverse Engineering Challenge (HTB) Walkthrough incl binary patching with Ghidra + PwnTools
🗣_CryptoCat23
🎖@malwr
🗣_CryptoCat23
🎖@malwr
YouTube
Anti-Flag [easy]: HackTheBox Reversing Challenge (binary patching with ghidra + pwntools)
Video walkthrough for retired @HackTheBox (HTB) Reversing challenge "Anti-Flag" [easy]: "Flag? What's a flag?" - Includes binary patching with ghidra + pwntools! Hope you enjoy 🙂
Sign up for HackTheBox: https://htb-signup.cryptocat.me
↢HackTheBox↣
http…
Sign up for HackTheBox: https://htb-signup.cryptocat.me
↢HackTheBox↣
http…
High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison for scheme that compromised tens of millions of debit and credit cards
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
Department of Justice
High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison for scheme that compromised tens of millions…
Seattle – The first high-level manager of the notorious hacking group FIN7 was sentenced today in U.S. District Court in Seattle to ten years in prison, announced Acting U.S. Attorney Tessa A. Gorman.
How to monitor in real-time for SSH sessions
Blog post on how to monitor in real-time for SSH sessions: https://cryptsus.com/blog/ssh-security-siem-dashboard-kibana.html
🗣krabelize
🎖@malwr
Blog post on how to monitor in real-time for SSH sessions: https://cryptsus.com/blog/ssh-security-siem-dashboard-kibana.html
🗣krabelize
🎖@malwr
Endpoint Discovery - Navigating your way through unmanaged devices
🗣digicat
This is pretty awesome.
👤m0wax
🎖@malwr
🗣digicat
This is pretty awesome.
👤m0wax
🎖@malwr
TECHCOMMUNITY.MICROSOFT.COM
Endpoint Discovery - Navigating your way through unmanaged devices
Unmanaged endpoint discovery is a new feature that has been added to the Public Preview for Microsoft Defender for Endpoint. In this blog we describe its..
Disables the Windows Platform Binary Table (WPBT) in your firmware. This program use a non-permenant, non-destructive method to remove the table from system memory, so it should be executed every time the computer is rebooted before Windows bootloader starts. - sophisticated UEFI implant mitigation
🗣digicat
This would be such a pain in the ass to deploy on one machine, let alone an entire enterprise
👤edward_snowedin
>Because this feature provides the ability to persistently execute system software in the context of Windows, it becomes critical that WPBT-based solutions are as secure as possible and do not expose Windows users to exploitable conditions. In particular, WPBT solutions must not include malware (i.e., malicious software or unwanted software installed without adequate user consent).
Basically this is a catch-22 situation. This tablet could be used for legitimate purposes like loading antitheft software OR it could be used to load malware persistently
👤CrowGrandFather
🎖@malwr
🗣digicat
This would be such a pain in the ass to deploy on one machine, let alone an entire enterprise
👤edward_snowedin
>Because this feature provides the ability to persistently execute system software in the context of Windows, it becomes critical that WPBT-based solutions are as secure as possible and do not expose Windows users to exploitable conditions. In particular, WPBT solutions must not include malware (i.e., malicious software or unwanted software installed without adequate user consent).
Basically this is a catch-22 situation. This tablet could be used for legitimate purposes like loading antitheft software OR it could be used to load malware persistently
👤CrowGrandFather
🎖@malwr
GitHub
GitHub - Jamesits/dropWPBT: Disables the Windows Platform Binary Table (WPBT) in your UEFI firmware.
Disables the Windows Platform Binary Table (WPBT) in your UEFI firmware. - Jamesits/dropWPBT