Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.08K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Our paper on emulating basebands for security analysis has been accepted at NDSS! We found multiple critical pre-auth vulnerabilities in the 2G and 4G implementations on Samsung and MediaTek basebands.

Check out the paper or keep reading to learn more🧡https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
πŸ—£Digital_Cold


πŸŽ–@malwr
πŸƒJust published a new research analyzing the #SysJoker backdoor.

SysJoker targets Windows, Linux and macOS.

Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->

https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/

@NicoleFishi19 @MhicRoibin
πŸ—£AbbyMCH


πŸŽ–@malwr
πŸ‘1
yara: match x86 that appears to manually traverse the TEB/PEB/LDR data.

#100DaysofYARA

https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
πŸ—£williballenthin


πŸŽ–@malwr
which one are you?
πŸ—£nixcraft


πŸŽ–@malwr
Useful logs for Incident Responders

Bigger format: https://github.com/corelight/bro-cheatsheets
πŸ—£LetsDefendIO


πŸŽ–@malwr
Procdump works against Defender with a simple rename. It quarantines the generated .dmp file but you have a few seconds to make a copy of it before it's removed.

I've seen other security solutions that do this, try to copy the file quickly before it's removed.
πŸ—£mrd0x


πŸŽ–@malwr
Windows Defender AV allows Everyone to read the configured exclusions on the system 🀦

reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
πŸ—£splinter_code


πŸŽ–@malwr
New #SysJoker backdoor targets Windows, Linux and macOS

Discovered during an active attack on a Linux-based web server

Linux and Mac versions are fully undetected in VirusTotal 🚷

http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
πŸ—£IntezerLabs


πŸŽ–@malwr
Technical details on APT35 attempts to exploit Log4j vulnerability:
πŸ’£Both targeted attacks and mass-scanning
πŸ’ŽCharmPower: still-in-development Powershell-based modular toolkit
🧩Shared infrastructure with previous mobile and ransomware campaigns.

https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
πŸ—£_CPResearch_


πŸŽ–@malwr
Anyone else aware that .asd files can contain macros? Literally just found out.

Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
πŸ—£mrd0x


πŸŽ–@malwr
[Tooling βš”οΈ] Updated DInjector with 'RemoteThreadKernelCB' technique for shellcode invocation by spoofing the fnCOPYDATA value in kernel callback table based on @SoumyadeepBas12’s gist. Thread execution via SendMessageA. Works for GUI processes βš™οΈ https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadKernelCB.cs
πŸ—£snovvcrash


πŸŽ–@malwr
Signature evasion...
πŸ—£MalwareJake


πŸŽ–@malwr
😁1
Today's quick #malware analysis with #SecurityOnion: #TA551 / #SHATHAK / #IcedID / #BOKBOT pcap from 2022-01-06!

Thanks to @malware_traffic for sharing this pcap!

More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
πŸ—£securityonion


πŸŽ–@malwr