Can You Trust a Fileβs Digital Signature? New Zloader Campaign exploits Microsoftβs Signature Verification putting users at risk - Check Point Research
π£dmchell
π@malwr
π£dmchell
π@malwr
Check Point Research
Can You Trust a Fileβs Digital Signature? New Zloader Campaign exploits Microsoftβs Signature Verification putting users at riskβ¦
Research by: Golan Cohen Introduction Last seen in August 2021, Zloader, a banking malware designed to steal user credentials and private information, is back with a simple yet sophisticated infection chain. Previous Zloader campaigns, which were seen inβ¦
Another simple .NET executable to create and add a backdoor user
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful for privilege escalations on Windows (i.e. unquoted service path)
Repo: https://github.com/notdodo/LocalAdminSharp
π£d_o_d_o_
π@malwr
Another simple but useful .NET executable that creates and adds an arbitrary user or domain user to the Local Administrators groups. Very useful for privilege escalations on Windows (i.e. unquoted service path)
Repo: https://github.com/notdodo/LocalAdminSharp
π£d_o_d_o_
π@malwr
GitHub
GitHub - notdodo/LocalAdminSharp: .NET executable to use when dealing with privilege escalation on Windows to gain local administratorβ¦
.NET executable to use when dealing with privilege escalation on Windows to gain local administrator access - notdodo/LocalAdminSharp
New Konni Campaign Kicks Off the New Year by Targeting Russian Ministry of Foreign Affairs
π£digicat
π@malwr
π£digicat
π@malwr
Lumen Blog
New Konni Campaign Kicks Off the New Year by Targeting Russian Ministry of Foreign Affairs
Black Lotus Labs, the Lumen threat research team, uncovered a series of targeted actions against the Russian Ministry of Foreign Affairs.
My blogs on EDR bypasses & evasions + fuzzing FoxitReader 9.7 + Emulating File I/O for snapshot-fuzzing have been migrated to my new site:
New posts coming soon
https://www.signal-labs.com/blog
π£Kharosx0
π@malwr
New posts coming soon
https://www.signal-labs.com/blog
π£Kharosx0
π@malwr
Signal Labs
Blog | Advanced Offensive Cybersecurity Training Articles | Signal Labs
Offensive cybersecurity blog topics on fuzzing, vulnerability research, EDRs, advanced offensive (red-team) tooling, reverse engineering & more.
Bypass Defender AV static detection:
If you name a malicious file DumpStack.log Defender doesn't scan it.
π£mrd0x
π@malwr
If you name a malicious file DumpStack.log Defender doesn't scan it.
π£mrd0x
π@malwr
Here is code that will detect threads which are impersonating on Windows via the TIB/TEB.
Turns out not many threads impersonate other users on Windows 10 it would seem.
The technique can be integrated in EDR sweeps as a indicator for implant injects.
https://gist.github.com/olliencc/df200e0049fa17036d9f867e024f57ad
π£ollieatnccgroup
π@malwr
Turns out not many threads impersonate other users on Windows 10 it would seem.
The technique can be integrated in EDR sweeps as a indicator for implant injects.
https://gist.github.com/olliencc/df200e0049fa17036d9f867e024f57ad
π£ollieatnccgroup
π@malwr
How do you approach investigating computer security incidents?
Some useful tools worth having your IT staff get familiar with.
ProcMon
ProcessExplorer
AutoRuns
Wireshark
Log-MD
ProcDOT
#infosec #cybersecurity #MalwareAnalysis #DFIR
π£shaktavist
π@malwr
Some useful tools worth having your IT staff get familiar with.
ProcMon
ProcessExplorer
AutoRuns
Wireshark
Log-MD
ProcDOT
#infosec #cybersecurity #MalwareAnalysis #DFIR
π£shaktavist
π@malwr
Small diagram on my malware analysis workflow, using @unpacme, @IntezerLabs, @virustotal, @abuse_ch, @Mandiant capa rules and my dear #Ghidra.
π£4rchib4ld
π@malwr
π£4rchib4ld
π@malwr
π1
For those interested in Reverse Engineering, I wrote an article 2 years ago about how to analyze a "Portable Executable File (exe)" using WinDbg: https://nutcrackerssecurity.github.io/PE-file.html
π£T3jv1l
π@malwr
π£T3jv1l
π@malwr
π€©1
Some awesome Win32k analysis for your Wednesday afternoon - what else? Great work by @w3knight
https://www.mcafee.com/blogs/enterprise/mcafee-enterprise-atr/technical-analysis-of-cve-2021-1732/
π£spovolny
π@malwr
https://www.mcafee.com/blogs/enterprise/mcafee-enterprise-atr/technical-analysis-of-cve-2021-1732/
π£spovolny
π@malwr
McAfee Blog
Technical Analysis of CVE-2021-1732
Introduction In February 2021, the company Dbappsecurity discovered a sample in the wild that exploited a zero-day vulnerability on Windows 10 x64. The
RE tip of the day: In malicious RTFs, the objects stored in the \objdata argument of the \object control word can be of various data types specified using \objclass:
* OLE2 (example: "Word.Document.8")
* OOXML
* PDFs
and others
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
* OLE2 (example: "Word.Document.8")
* OOXML
* PDFs
and others
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
A curated list of Frida resources!
https://github.com/dweinstein/awesome-frida
#frida #android #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/dweinstein/awesome-frida
#frida #android #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
Short writeup on incident response case management, DFIR-IRIS (by @AirbusCyber / @White_Kernel ) and a bit of MISP ( @MISPProject ) #DFIR #CSIRT
https://www.vanimpe.eu/2022/01/05/incident-response-case-management-dfir-iris-and-misp/
π£cudeso
π@malwr
https://www.vanimpe.eu/2022/01/05/incident-response-case-management-dfir-iris-and-misp/
π£cudeso
π@malwr
www.vanimpe.eu
Incident response case management, DFIR-IRIS and a bit of MISP
Incident response case management, DFIR-IRIS and a bit of MISP - Koen Van Impe - vanimpe.eu - Incident response case management A good case management is indispensable for CSIRTs. There are a number of excellent case management tools available but
Check Medusa's New script additions for SSL Unpinning / Dex Dump from Memory / Log4j test / Dex Class Loader hooks
https://github.com/Ch0pin/medusa
π£Ch0pin
π@malwr
https://github.com/Ch0pin/medusa
π£Ch0pin
π@malwr
GitHub
GitHub - Ch0pin/medusa: Mobile Edge-Dynamic Unified Security Analysis
Mobile Edge-Dynamic Unified Security Analysis. Contribute to Ch0pin/medusa development by creating an account on GitHub.
I've been maintaining a repo for interesting malware samples, artifacts and even exercises! Check it out on Github!
π https://github.com/jstrosch/malware-samples
π£jstrosch
π@malwr
π https://github.com/jstrosch/malware-samples
π£jstrosch
π@malwr