Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
For the new year I started a new blog post series on HyperGuard: PatchGuard’s lesser-known sibling:
https://windows-internals.com/hyperguard-secure-kernel-patch-guard-part-1-skpg-initialization/
πŸ—£yarden_shafir


πŸŽ–@malwr
Happy New Year! 🎊🎈 πŸŽ‰
Happy New Bug! πŸ›πŸœπŸž
https://bugs.chromium.org/p/project-zero/issues/detail?id=2223

https://bugs.chromium.org/p/project-zero/issues/detail?id=2235
πŸ—£natashenka


πŸŽ–@malwr
I published a new blog post on β€œAutomated RE of Kernel Configurations”:

This also includes the release of a new BN plugin (link in blog post).
https://zznop.com/2022/01/02/automated-re-of-kernel-build-configs/
πŸ—£zznop_


πŸŽ–@malwr
Automated RE of Kernel Configurations
πŸ—£zznop_

Pretty nice but seems to be somewhat manual process. I think somewhere on Twitter(?) I saw an idea of bruteforcing/bisecting the kconfig by building multiple variations of the kernel with different kconfig settings and comparing it against the image you have.
πŸ‘€igor_sk


πŸŽ–@malwr
WHAT?! πŸ˜‚
If you provide /FS:FILESYSTEM parameter to the format[.]com utility, the resulting process will try to load ("U"+FILESYSTEM).DLL using the default search path...
The weirdest custom DLL launcher I have meet so far :D
πŸ—£0gtweet


πŸŽ–@malwr
https://adcb-kyc-update.netlify[.]app/
πŸ—£malwrhunterteam
#phishing

πŸŽ–@malwr
Introducing inject-assembly! Execute a .NET assembly in any existing process, including your current Beacon, and retrieve the output!
- Patches Environment.Exit()
- PE header stomping
- Random pipe name generation
- No blocking of the current Beacon
https://github.com/kyleavery/inject-assembly
πŸ—£kyleavery_


πŸŽ–@malwr
πŸ”₯2
PPTShots - Unintentionally shared data in PowerPoint presentations
πŸ—£df_works

This project was nowhere near as fruitful as I thought it was going to be and there are probably other tools out there but feel free to check out a notebook I have shared on github. PPTshots scans the internet for cropped images in powerpoint presentations and returns locations of "unseen" or "trimmed" areas. The larger the % area, presumably the greater potential for data leaks and other interesting info.

It is actually pretty rare to find anything interesting, after several days only one presentation contained 'sensitive' information. In this instance an "unnamed US federal government executive branch organization" had unintentionally left some PII in a Facebook screenshot. I reported this to them and the presentation is no longer publicly facing.

Other less sensitive information included browser tabs and OS information from the screen peripheries which could be of minor value to an attacker but nothing too exciting. Interestingly, on a few occasions where screenshots had been taken with dual monitors there was an entire extra screen to examine - I didn't identify anything more valuable than a half filled in timesheet but there is potential for sizeable data to have been exposed if a spreadsheet or similar had been open.
πŸ‘€df_works


πŸŽ–@malwr