Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Excited to share Part 1 of Malware RE for Beginners!

Learn about basic computing terms and assembly language from 0x0

https://www.intezer.com/blog/malware-analysis/malware-reverse-engineering-beginners/
@IntezerLabs
๐Ÿ—ฃAbbyMCH


๐ŸŽ–@malwr
๐Ÿ”ฅ2
Analysis of #Evilnum new attack activity (report is in chinese ๐Ÿ‡จ๐Ÿ‡ณ)
http://blog.nsfocus.net/agentvxapt-evilnum/

๐Ÿ—ฃCyber_O51NT


๐ŸŽ–@malwr
๐ŸŽ๐Ÿ‘พ Just published my annual "Mac Malware of the Year" report, for 2021:

An in-depth technical analysis of the year's new Mac malware, covering each:
๐Ÿ’‰ Infection vector
๐Ÿ’พ Persistence mechanism
๐Ÿ›ฐ Payload and capabilities

+ samples for download! ๐Ÿฆ 
https://objective-see.com/blog/blog_0x6B.html
๐Ÿ—ฃpatrickwardle


๐ŸŽ–@malwr
๐Ÿ‘1
Subdomain enumeration on your phone?

1. Install Termux.
2. pkg update && pkg insta findomain -y
3. findomain -t example.tld

You can use the same options such as -i, -r, --http-status or even perform monitoring from there.

#bugbountytips #infosec #hacking #osint #automation
๐Ÿ—ฃFindomainApp


๐ŸŽ–@malwr
KQL is a powerful tool to explore data and discover patterns, identify anomalies, and more.

In this post, Microsoft DART team explained how to leverage KQL for incident response!๐Ÿค“

#DFIR #infosec cc: @DebugPrivilege @msftsecresponse

https://techcommunity.microsoft.com/t5/security-compliance-and-identity/leveraging-the-power-of-kql-in-incident-response/ba-p/3044795
๐Ÿ—ฃfr0gger_


๐ŸŽ–@malwr
Day 3 of #dailyyara for #100DaysofYARA
Malware authors often statically compile OpenSSL into Windows binaries. Let's hunt some artefacts.
https://github.com/secman-pl/yaras/blob/main/hunt_PE_openssl_statically_compiled.yar
๐Ÿ—ฃsecman_pl


๐ŸŽ–@malwr
Another simple .NET executable to create and add a backdoor user
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful for privilege escalations on Windows (i.e. unquoted service path)

Repo: https://github.com/notdodo/LocalAdminSharp
๐Ÿ—ฃd_o_d_o_


๐ŸŽ–@malwr
My blogs on EDR bypasses & evasions + fuzzing FoxitReader 9.7 + Emulating File I/O for snapshot-fuzzing have been migrated to my new site:

New posts coming soon
https://www.signal-labs.com/blog
๐Ÿ—ฃKharosx0


๐ŸŽ–@malwr
Bypass Defender AV static detection:

If you name a malicious file DumpStack.log Defender doesn't scan it.
๐Ÿ—ฃmrd0x


๐ŸŽ–@malwr
Here is code that will detect threads which are impersonating on Windows via the TIB/TEB.

Turns out not many threads impersonate other users on Windows 10 it would seem.

The technique can be integrated in EDR sweeps as a indicator for implant injects.

https://gist.github.com/olliencc/df200e0049fa17036d9f867e024f57ad
๐Ÿ—ฃollieatnccgroup


๐ŸŽ–@malwr
Shout out to the SOC team today. #infosec
๐Ÿ—ฃrootsecdev


๐ŸŽ–@malwr
How do you approach investigating computer security incidents?

Some useful tools worth having your IT staff get familiar with.

ProcMon
ProcessExplorer
AutoRuns
Wireshark
Log-MD
ProcDOT

#infosec #cybersecurity #MalwareAnalysis #DFIR
๐Ÿ—ฃshaktavist


๐ŸŽ–@malwr
Small diagram on my malware analysis workflow, using @unpacme, @IntezerLabs, @virustotal, @abuse_ch, @Mandiant capa rules and my dear #Ghidra.
๐Ÿ—ฃ4rchib4ld


๐ŸŽ–@malwr
๐Ÿ‘1