Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.08K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Oh no!
πŸ—£jmcmurry


πŸŽ–@malwr
πŸ“πŸ“πŸ“Please forward posts to the other groups πŸ“πŸ“πŸ“
πŸ‘3
Malware News pinned Β«πŸ“πŸ“πŸ“Please forward posts to the other groups πŸ“πŸ“πŸ“Β»
This media is not supported in your browser
VIEW IN TELEGRAM
If you need to dump credentials from lsass.exe on a machine with defender ATP on it, or generally want to execute #mimikatz for another operation on that machine, check out the following POC from @zux0x3a (All creds to him).

https://github.com/0xsp-SRD/mortar

#redteam #pentest #bypass
πŸ—£VirtualAllocEx


πŸŽ–@malwr
Our paper on emulating basebands for security analysis has been accepted at NDSS! We found multiple critical pre-auth vulnerabilities in the 2G and 4G implementations on Samsung and MediaTek basebands.

Check out the paper or keep reading to learn more🧡https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
πŸ—£Digital_Cold


πŸŽ–@malwr
πŸƒJust published a new research analyzing the #SysJoker backdoor.

SysJoker targets Windows, Linux and macOS.

Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->

https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/

@NicoleFishi19 @MhicRoibin
πŸ—£AbbyMCH


πŸŽ–@malwr
πŸ‘1
yara: match x86 that appears to manually traverse the TEB/PEB/LDR data.

#100DaysofYARA

https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
πŸ—£williballenthin


πŸŽ–@malwr
which one are you?
πŸ—£nixcraft


πŸŽ–@malwr
Useful logs for Incident Responders

Bigger format: https://github.com/corelight/bro-cheatsheets
πŸ—£LetsDefendIO


πŸŽ–@malwr
Procdump works against Defender with a simple rename. It quarantines the generated .dmp file but you have a few seconds to make a copy of it before it's removed.

I've seen other security solutions that do this, try to copy the file quickly before it's removed.
πŸ—£mrd0x


πŸŽ–@malwr
Windows Defender AV allows Everyone to read the configured exclusions on the system 🀦

reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
πŸ—£splinter_code


πŸŽ–@malwr
New #SysJoker backdoor targets Windows, Linux and macOS

Discovered during an active attack on a Linux-based web server

Linux and Mac versions are fully undetected in VirusTotal 🚷

http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
πŸ—£IntezerLabs


πŸŽ–@malwr