My analysis blog for #Rook #Ransomware is out!
Check out how this new ransomware uses the Mbed TLS library for encryption and its relationship with #Babuk!
https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/
S/o to @demonslay335 for the crypto help cause Mbed TLS got me trippin ππ©
π£cPeterr
π@malwr
Check out how this new ransomware uses the Mbed TLS library for encryption and its relationship with #Babuk!
https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/
S/o to @demonslay335 for the crypto help cause Mbed TLS got me trippin ππ©
π£cPeterr
π@malwr
Happy new year, everyone! We start out the year with a small update: introducing the MISP report format as an export, also accessible via the API. Example: https://www.filescan.io/uploads/61d83f6e02e388f9fdb30dee/reports/517c82d9-6299-414d-a6b6-ce8b590efaee/overview annot: STIX/HTML/PDF will be following soon!
π£filescan_itsec
π@malwr
π£filescan_itsec
π@malwr
I've been part of @Google's Detection & Response team for almost 12 years now (π±) -- the 2 biggest advancements in my time, hands down: 1) remote live forensics ( and 2) enriched & automated investigations, which I hope to talk about more at some point.
https://github.com/google/grr
π£methodtim
π@malwr
https://github.com/google/grr
π£methodtim
π@malwr
GitHub
GitHub - google/grr: GRR Rapid Response: remote live forensics for incident response
GRR Rapid Response: remote live forensics for incident response - google/grr
New research! Unpacking CVE-2021-40444: A Deep Technical Analysis of an Office RCE Exploit
https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce
π£BillDemirkapi
π@malwr
https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce
π£BillDemirkapi
π@malwr
Bill Demirkapi's Blog
Unpacking CVE-2021-40444: A Deep Technical Analysis of an Office RCE Exploit
In the middle of August 2021, a special Word document was uploaded to VirusTotal by a user from Argentina. Although it was only detected by a single antivirus engine at the time, this sample turned out to be exploiting a zero day vulnerability in Microsoftβ¦
Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.
https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
#hacking #graphql #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
#hacking #graphql #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
(I know many do this) If you're jamming on YARA locally, I recommend using VS Code & the awesome YARA extension which helps do syntax stuff, highlighting and more. Then use the integrated terminal to test and tweak your rules. Super fun.
#100DaysofYARA
https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
π£stvemillertime
π@malwr
#100DaysofYARA
https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
π£stvemillertime
π@malwr
Rook Ransomware https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/
π£ptracesecurity
π@malwr
π£ptracesecurity
π@malwr
MalAPIReader: Python-enabled PE parsing to identify malicious API calls π
@SquiblydooBlog and I collaborated on this project that parses portable executables and looks up API calls on @mrd0x's
https://malapi.io
https://github.com/HuskyHacks/MalAPIReader
π£HuskyHacksMK
π@malwr
@SquiblydooBlog and I collaborated on this project that parses portable executables and looks up API calls on @mrd0x's
https://malapi.io
https://github.com/HuskyHacks/MalAPIReader
π£HuskyHacksMK
π@malwr
GitHub
GitHub - HuskyHacks/MalAPIReader: Reads and prints information from the website MalAPI.io
Reads and prints information from the website MalAPI.io - HuskyHacks/MalAPIReader
RE tip of the day: In malicious RTF docs, there are multiple ways how to obfuscate embedded objects to complicate the payload extraction:
* inserting {\object} in the middle
* inserting \bin[num]
* using spaces between digits
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
* inserting {\object} in the middle
* inserting \bin[num]
* using spaces between digits
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
π1
Breaking the Nespresso Vertuo Barcodes
π£TBD_electronique
Great work. I use the PCBite for probing, really good kit. Probably that STM32F1 is susceptible to a glitching attack.
π€andreixc
π@malwr
π£TBD_electronique
Great work. I use the PCBite for probing, really good kit. Probably that STM32F1 is susceptible to a glitching attack.
π€andreixc
π@malwr
Reddit
From the nespresso community on Reddit: Breaking the Nespresso Vertuo Barcodes (part 2)
Explore this post and more from the nespresso community
An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-42278. Nice blog post from TrustedSec on detection engineering. Some nice SPL queries.
π£munrobotic
π@malwr
π£munrobotic
π@malwr
TrustedSec
An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-42278
Figure 1 - CVE 2021-42287 and 2021-42278 Attack Path 1 Diagram While each detection strives for high fidelity and may be able stand on its own accord,β¦
π1
Introduction to x64 Linux Binary Exploitation (Part 1)
@mobilesecurity_
https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-1-14ad4a27aeef
π£Ch0pin
π@malwr
@mobilesecurity_
https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-1-14ad4a27aeef
π£Ch0pin
π@malwr
Medium
Introduction to x64 Linux Binary Exploitation (Part 1)
Basic Buffer Overflow (BoF)
RCLocals - Linux Startup Analyzer
http://www.kitploit.com/2022/01/rclocals-linux-startup-analyzer.html
π£Dinosn
π@malwr
http://www.kitploit.com/2022/01/rclocals-linux-startup-analyzer.html
π£Dinosn
π@malwr
KitPloit - PenTest & Hacking Tools
RCLocals - Linux Startup Analyzer
π1
Network Forensics, Part 1: Wireshark Basics #wireshark #networkforensics #cybersecurity #cyberwarrior
https://www.hackers-arise.com/post/2018/09/24/Network-Forensics-Wireshark-Basics-Part-1
#cyberwarrior #wireshark
π£three_cube
π@malwr
https://www.hackers-arise.com/post/2018/09/24/Network-Forensics-Wireshark-Basics-Part-1
#cyberwarrior #wireshark
π£three_cube
π@malwr
π5