Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.09K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
RE tip of the day: In malicious RTFs, the objects stored in the \objdata argument of the \object control word can be of various data types specified using \objclass:
* OLE2 (example: "Word.Document.8")
* OOXML
* PDFs
and others
#infosec #cybersecurity #malware #reverseengineering
πŸ—£re_and_more


πŸŽ–@malwr
A curated list of Frida resources!

https://github.com/dweinstein/awesome-frida

#frida #android #cybersecurity #bughunting
πŸ—£0xAsm0d3us


πŸŽ–@malwr
I've been maintaining a repo for interesting malware samples, artifacts and even exercises! Check it out on Github!

πŸŽ“ https://github.com/jstrosch/malware-samples
πŸ—£jstrosch


πŸŽ–@malwr
#infosec
πŸ—£johnjhacking


πŸŽ–@malwr
Bcdedit /set {default} hypervisorloadoptions "EARLYKDINIT" this command allowed me to attach windbg to hyper-v successfully after struggling with win11. Incase it helps anyone..
πŸ—£Essb33


πŸŽ–@malwr
Did you ever want to load dbk64.sys yourself and abuse the fact that it's a signed driver?
Maybe call the builtin kernel read/write (and many more!) routines because you don't have a driver signing certificate?
You can do that now! Check it out ;)

GitHub: https://github.com/ioncodes/ceload
πŸ—£layle_ctf


πŸŽ–@malwr
Paper &Code of LiveOverflow and my ROOTS paper about fuzzing of Smart Contract VMs is out!

Peak Web 3.0: A Memory corruption in a VM _written in C#_ πŸ‘€

https://github.com/fgsect/NeoDiff/blob/main/roots21-2.pdf
πŸ—£domenuk


πŸŽ–@malwr
My analysis blog for #Rook #Ransomware is out!

Check out how this new ransomware uses the Mbed TLS library for encryption and its relationship with #Babuk!

https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/

S/o to @demonslay335 for the crypto help cause Mbed TLS got me trippin πŸ’€πŸ˜©
πŸ—£cPeterr


πŸŽ–@malwr
Happy new year, everyone! We start out the year with a small update: introducing the MISP report format as an export, also accessible via the API. Example: https://www.filescan.io/uploads/61d83f6e02e388f9fdb30dee/reports/517c82d9-6299-414d-a6b6-ce8b590efaee/overview annot: STIX/HTML/PDF will be following soon!
πŸ—£filescan_itsec


πŸŽ–@malwr
I've been part of @Google's Detection & Response team for almost 12 years now (😱) -- the 2 biggest advancements in my time, hands down: 1) remote live forensics ( and 2) enriched & automated investigations, which I hope to talk about more at some point.
https://github.com/google/grr
πŸ—£methodtim


πŸŽ–@malwr
Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.

https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application

#hacking #graphql #cybersecurity #bughunting
πŸ—£0xAsm0d3us


πŸŽ–@malwr
(I know many do this) If you're jamming on YARA locally, I recommend using VS Code & the awesome YARA extension which helps do syntax stuff, highlighting and more. Then use the integrated terminal to test and tweak your rules. Super fun.

#100DaysofYARA

https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
πŸ—£stvemillertime


πŸŽ–@malwr