WHAT?! ๐
If you provide /FS:FILESYSTEM parameter to the format[.]com utility, the resulting process will try to load ("U"+FILESYSTEM).DLL using the default search path...
The weirdest custom DLL launcher I have meet so far :D
๐ฃ0gtweet
๐@malwr
If you provide /FS:FILESYSTEM parameter to the format[.]com utility, the resulting process will try to load ("U"+FILESYSTEM).DLL using the default search path...
The weirdest custom DLL launcher I have meet so far :D
๐ฃ0gtweet
๐@malwr
Introducing inject-assembly! Execute a .NET assembly in any existing process, including your current Beacon, and retrieve the output!
- Patches Environment.Exit()
- PE header stomping
- Random pipe name generation
- No blocking of the current Beacon
https://github.com/kyleavery/inject-assembly
๐ฃkyleavery_
๐@malwr
- Patches Environment.Exit()
- PE header stomping
- Random pipe name generation
- No blocking of the current Beacon
https://github.com/kyleavery/inject-assembly
๐ฃkyleavery_
๐@malwr
GitHub
GitHub - kyleavery/inject-assembly: Inject .NET assemblies into an existing process
Inject .NET assemblies into an existing process. Contribute to kyleavery/inject-assembly development by creating an account on GitHub.
Reverse Engineering Resources About All Platforms(Windows/Linux/macOS/Android/iOS/IoT) (use translate if you cannot read the original)
https://github.com/alphaSeclab/awesome-reverse-engineering
๐ฃDinosn
๐@malwr
https://github.com/alphaSeclab/awesome-reverse-engineering
๐ฃDinosn
๐@malwr
GitHub
GitHub - alphaSeclab/awesome-reverse-engineering: Reverse Engineering Resources About All Platforms(Windows/Linux/macOS/Android/iOS/IoT)โฆ
Reverse Engineering Resources About All Platforms(Windows/Linux/macOS/Android/iOS/IoT) And Every Aspect! (More than 3500 open source tools and 2300 posts&videos) - alphaSeclab/awesome-rever...
๐2
๐ฅ2
Keeping the ball rolling on blog posts! MalwareBazaar is giving me lots of material to work with and I like walking through my thought process #malware
https://forensicitguy.github.io/a-tale-of-two-dropper-scripts/
๐ฃForensicITGuy
๐@malwr
https://forensicitguy.github.io/a-tale-of-two-dropper-scripts/
๐ฃForensicITGuy
๐@malwr
forensicitguy.github.io
A Tale of Two Dropper Scripts for Agent Tesla
In this post I want to look at two script files that drop Agent Tesla stealers on affected systems and show how adversary decisions affect malware analysis and detection. If you want to follow alon...
PPTShots - Unintentionally shared data in PowerPoint presentations
๐ฃdf_works
This project was nowhere near as fruitful as I thought it was going to be and there are probably other tools out there but feel free to check out a notebook I have shared on github. PPTshots scans the internet for cropped images in powerpoint presentations and returns locations of "unseen" or "trimmed" areas. The larger the % area, presumably the greater potential for data leaks and other interesting info.
It is actually pretty rare to find anything interesting, after several days only one presentation contained 'sensitive' information. In this instance an "unnamed US federal government executive branch organization" had unintentionally left some PII in a Facebook screenshot. I reported this to them and the presentation is no longer publicly facing.
Other less sensitive information included browser tabs and OS information from the screen peripheries which could be of minor value to an attacker but nothing too exciting. Interestingly, on a few occasions where screenshots had been taken with dual monitors there was an entire extra screen to examine - I didn't identify anything more valuable than a half filled in timesheet but there is potential for sizeable data to have been exposed if a spreadsheet or similar had been open.
๐คdf_works
๐@malwr
๐ฃdf_works
This project was nowhere near as fruitful as I thought it was going to be and there are probably other tools out there but feel free to check out a notebook I have shared on github. PPTshots scans the internet for cropped images in powerpoint presentations and returns locations of "unseen" or "trimmed" areas. The larger the % area, presumably the greater potential for data leaks and other interesting info.
It is actually pretty rare to find anything interesting, after several days only one presentation contained 'sensitive' information. In this instance an "unnamed US federal government executive branch organization" had unintentionally left some PII in a Facebook screenshot. I reported this to them and the presentation is no longer publicly facing.
Other less sensitive information included browser tabs and OS information from the screen peripheries which could be of minor value to an attacker but nothing too exciting. Interestingly, on a few occasions where screenshots had been taken with dual monitors there was an entire extra screen to examine - I didn't identify anything more valuable than a half filled in timesheet but there is potential for sizeable data to have been exposed if a spreadsheet or similar had been open.
๐คdf_works
๐@malwr
GitHub
GitHub - dfaram7/pptshots: Finding sensitive information in the trimmed parts of cropped images
Finding sensitive information in the trimmed parts of cropped images - dfaram7/pptshots
Automated approach to Memory Analysis
Hello all,
So weโre on a Project and being the sole one to do the task, I was wondering if thereโs to some extent we can automate the Memory Analysis part!
Currently, I do it using Volatility Framework! I came across Volatility Bot, but saw it was last pushed 5 years back, so step aside!
Any leads could really help me in!
Thanks
๐ฃGloryHunter9
I usually keep a shell script to run the volatility commands I know Iโll need to run and save the output. Itโs also easy to tell volatility to save in a format that you can upload to other tools for analysis. VolDiff used to have a malware-checks option that also did some cool automation, but itโs older at this point.
๐คsumdude1849
Hi!
Check Crowdstrike SuperMem. I use my own script and havenโt used SuperMem like a lot but Iโd say it extracts pretty much everything you need in order for you to analyze.
๐คdelerium46
๐@malwr
Hello all,
So weโre on a Project and being the sole one to do the task, I was wondering if thereโs to some extent we can automate the Memory Analysis part!
Currently, I do it using Volatility Framework! I came across Volatility Bot, but saw it was last pushed 5 years back, so step aside!
Any leads could really help me in!
Thanks
๐ฃGloryHunter9
I usually keep a shell script to run the volatility commands I know Iโll need to run and save the output. Itโs also easy to tell volatility to save in a format that you can upload to other tools for analysis. VolDiff used to have a malware-checks option that also did some cool automation, but itโs older at this point.
๐คsumdude1849
Hi!
Check Crowdstrike SuperMem. I use my own script and havenโt used SuperMem like a lot but Iโd say it extracts pretty much everything you need in order for you to analyze.
๐คdelerium46
๐@malwr
reddit
Automated approach to Memory Analysis
Hello all, So weโre on a Project and being the sole one to do the task, I was wondering if thereโs to some extent we can automate the Memory...
๐1
Staging Cobalt Strike with mTLS using Caddy โ blegh - client cert auth from beacons - will frustrate discovery if adopted
๐ฃdigicat
๐@malwr
๐ฃdigicat
๐@malwr
itm8.dk
Skal vi skabe nutidens og fremtidens IT sammen? itm8
Hvad er en itm8? Vi er prรฆcis, hvad navnet siger: Din m8* (*mate), der er ekspert i IT. Vi er din partner til 360 graders IT.
New Zloader Campaign exploits Microsoftโs Signature Verification putting users at risk
๐ฃdigicat
Dang that's dangerous
๐คItsMiggity
๐@malwr
๐ฃdigicat
Dang that's dangerous
๐คItsMiggity
๐@malwr
Check Point Research
Can You Trust a Fileโs Digital Signature? New Zloader Campaign exploits Microsoftโs Signature Verification putting users at riskโฆ
Research by: Golan Cohen Introduction Last seen in August 2021, Zloader, a banking malware designed to steal user credentials and private information, is back with a simple yet sophisticated infection chain. Previous Zloader campaigns, which were seen inโฆ
NY Attorney General James Alerts 17 Companies to โCredential Stuffingโ Cyberattacks Impacting More Than 1.1 Million Consumers
๐ฃdigicat
๐@malwr
๐ฃdigicat
๐@malwr
New York State Attorney General
Attorney General James Alerts 17 Companies to โCredential Stuffingโ Cyberattacks Impacting More Than 1.1 Million Consumers
Click to read more.
Excited to share Part 1 of Malware RE for Beginners!
Learn about basic computing terms and assembly language from 0x0
https://www.intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/
@IntezerLabs
๐ฃAbbyMCH
๐@malwr
Learn about basic computing terms and assembly language from 0x0
https://www.intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/
@IntezerLabs
๐ฃAbbyMCH
๐@malwr
๐ฅ2
Analysis of #Evilnum new attack activity (report is in chinese ๐จ๐ณ)
http://blog.nsfocus.net/agentvxapt-evilnum/
๐ฃCyber_O51NT
๐@malwr
http://blog.nsfocus.net/agentvxapt-evilnum/
๐ฃCyber_O51NT
๐@malwr
๐๐พ Just published my annual "Mac Malware of the Year" report, for 2021:
An in-depth technical analysis of the year's new Mac malware, covering each:
๐ Infection vector
๐พ Persistence mechanism
๐ฐ Payload and capabilities
+ samples for download! ๐ฆ
https://objective-see.com/blog/blog_0x6B.html
๐ฃpatrickwardle
๐@malwr
An in-depth technical analysis of the year's new Mac malware, covering each:
๐ Infection vector
๐พ Persistence mechanism
๐ฐ Payload and capabilities
+ samples for download! ๐ฆ
https://objective-see.com/blog/blog_0x6B.html
๐ฃpatrickwardle
๐@malwr
๐1
Subdomain enumeration on your phone?
1. Install Termux.
2. pkg update && pkg insta findomain -y
3. findomain -t example.tld
You can use the same options such as -i, -r, --http-status or even perform monitoring from there.
#bugbountytips #infosec #hacking #osint #automation
๐ฃFindomainApp
๐@malwr
1. Install Termux.
2. pkg update && pkg insta findomain -y
3. findomain -t example.tld
You can use the same options such as -i, -r, --http-status or even perform monitoring from there.
#bugbountytips #infosec #hacking #osint #automation
๐ฃFindomainApp
๐@malwr