Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.09K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
My analysis blog for #Rook #Ransomware is out!

Check out how this new ransomware uses the Mbed TLS library for encryption and its relationship with #Babuk!

https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/

S/o to @demonslay335 for the crypto help cause Mbed TLS got me trippin πŸ’€πŸ˜©
πŸ—£cPeterr


πŸŽ–@malwr
Happy new year, everyone! We start out the year with a small update: introducing the MISP report format as an export, also accessible via the API. Example: https://www.filescan.io/uploads/61d83f6e02e388f9fdb30dee/reports/517c82d9-6299-414d-a6b6-ce8b590efaee/overview annot: STIX/HTML/PDF will be following soon!
πŸ—£filescan_itsec


πŸŽ–@malwr
I've been part of @Google's Detection & Response team for almost 12 years now (😱) -- the 2 biggest advancements in my time, hands down: 1) remote live forensics ( and 2) enriched & automated investigations, which I hope to talk about more at some point.
https://github.com/google/grr
πŸ—£methodtim


πŸŽ–@malwr
Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.

https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application

#hacking #graphql #cybersecurity #bughunting
πŸ—£0xAsm0d3us


πŸŽ–@malwr
(I know many do this) If you're jamming on YARA locally, I recommend using VS Code & the awesome YARA extension which helps do syntax stuff, highlighting and more. Then use the integrated terminal to test and tweak your rules. Super fun.

#100DaysofYARA

https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
πŸ—£stvemillertime


πŸŽ–@malwr
MalAPIReader: Python-enabled PE parsing to identify malicious API calls 🐍

@SquiblydooBlog and I collaborated on this project that parses portable executables and looks up API calls on @mrd0x's
https://malapi.io

https://github.com/HuskyHacks/MalAPIReader
πŸ—£HuskyHacksMK


πŸŽ–@malwr
RE tip of the day: In malicious RTF docs, there are multiple ways how to obfuscate embedded objects to complicate the payload extraction:
* inserting {\object} in the middle
* inserting \bin[num]
* using spaces between digits
#infosec #cybersecurity #malware #reverseengineering
πŸ—£re_and_more


πŸŽ–@malwr
πŸ‘1
Breaking the Nespresso Vertuo Barcodes
πŸ—£TBD_electronique

Great work. I use the PCBite for probing, really good kit. Probably that STM32F1 is susceptible to a glitching attack.
πŸ‘€andreixc


πŸŽ–@malwr
Oh no!
πŸ—£jmcmurry


πŸŽ–@malwr
πŸ“πŸ“πŸ“Please forward posts to the other groups πŸ“πŸ“πŸ“
πŸ‘3