Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
[Report M-Trends 2021](https://content.fireeye.com/m-trends/rpt-m-trends-2021)
πŸ—£digicat


πŸŽ–@malwr
Microsoft 365 Dev subscriptions free with Dev Essentials (also free)
πŸ—£cryolithic

I’m going to make so many word documents it will be like a 730 day trial
πŸ‘€Jaimz22

Only 90 day trial
πŸ‘€xxbiohazrdxx

I saw they added what seems like a slew of additional freebies.
πŸ‘€nameandfaceless


πŸŽ–@malwr
Tails OS - secure and anonymous OS
πŸ—£Emergency_Dramatic


πŸŽ–@malwr
ATT SMS record analysis
I've been asked to provide some analysis of SMS records which were subpoenaed from the carrier but am having a little trouble resolving a few things. There are several messages from a two digit phone number and several instances where two or three messages were sent by the phone at the exact same time (down to the second). It appears to me that the messages sent at the same time were likely long messages broken up into 2 or 3 messages due to character limits, but I can't really come up with anything that would allow a two digit phone number to deliver messages. Any help would be greatly appreciated.
πŸ—£kstewart0x00

I often find that those records reflect carrier services, like paying a bill, checking data plan current usage, and messages regarding the account.

If you received this data in a subpoena return, there should be a document explaining these numbers. When in doubt, I usually call the division that supplied the records.
πŸ‘€chilledquesadilla

Could they be something that came from AT&T?

Is it from a service? or is it a conversation?

Here's someone asking AT&T the same question about messages on their bill. And AT&T providing stellar customer service, too.

https://forums.att.com/conversations/wireless-account/2-digit-phone-number/5defd200bad5f2f606f76a5c
πŸ‘€technologite


πŸŽ–@malwr
How to monitor in real-time for SSH sessions
Blog post on how to monitor in real-time for SSH sessions: https://cryptsus.com/blog/ssh-security-siem-dashboard-kibana.html
πŸ—£krabelize


πŸŽ–@malwr
Disables the Windows Platform Binary Table (WPBT) in your firmware. This program use a non-permenant, non-destructive method to remove the table from system memory, so it should be executed every time the computer is rebooted before Windows bootloader starts. - sophisticated UEFI implant mitigation
πŸ—£digicat

This would be such a pain in the ass to deploy on one machine, let alone an entire enterprise
πŸ‘€edward_snowedin

>Because this feature provides the ability to persistently execute system software in the context of Windows, it becomes critical that WPBT-based solutions are as secure as possible and do not expose Windows users to exploitable conditions. In particular, WPBT solutions must not include malware (i.e., malicious software or unwanted software installed without adequate user consent).

Basically this is a catch-22 situation. This tablet could be used for legitimate purposes like loading antitheft software OR it could be used to load malware persistently
πŸ‘€CrowGrandFather


πŸŽ–@malwr
Compromised Linux VM for DF training?
Does anyone have a vmdk of a compromised Linux host (perhaps from a Honeypot?) they'd be willing to share? I'd like to have my blue team try their hand at manual forensics as a table-top / Forensics Capture-the-Flag exercise

Plans:
\- Have them import it into Virtualbox (they all use Ubuntu as their workstations)
\- Browse around the host and see what they can find manually first
\- Utilize something like Plaso / log2timeline and import it into a log tool like Splunk
πŸ—£AbracaBOOYAH

Not exactly what you are looking for but I was just at a competition last week and it had some forensic CTFs. Found them here, might be what you are interested in.
πŸ‘€AppCompatCache-SI-TS

Just infect a Linux vm
πŸ‘€Stofers

The Great Hal Pomeranz made a course, with resources from Ali Hadi/Champlain College, that might help you out:
https://archive.org/download/HalLinuxForensics
https://github.com/ashemery/LinuxForensics
πŸ‘€awk_warden


πŸŽ–@malwr
Getting Started Reverse Engineering Bare Metal Kernel Images - (Part 1/Setup) | This is a series, more will be released soon.
πŸ—£ragnarsecurity

Arent all kernels bare metal kernels? Iv not seen one that is specifically designed to run in a VM. I dont doubt that one may exist, but ive never seen one.
πŸ‘€AllenKll

Hey man, good write up :)

Can I ask what do you refer to as a "kernel"? In my experience, kernel is generally only used to refer to a component of an OS.

I'd generally describe a bare metal firmware as having no kernel. And the built application is just a binary, or a firmware image.
πŸ‘€Palantir555


πŸŽ–@malwr