πJust published a new research analyzing the #SysJoker backdoor.
SysJoker targets Windows, Linux and macOS.
Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
@NicoleFishi19 @MhicRoibin
π£AbbyMCH
π@malwr
SysJoker targets Windows, Linux and macOS.
Learn more about this new threat, its capabilities, behavior and (most importantly) how to detect it ->
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
@NicoleFishi19 @MhicRoibin
π£AbbyMCH
π@malwr
π1
yara: match x86 that appears to manually traverse the TEB/PEB/LDR data.
#100DaysofYARA
https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
π£williballenthin
π@malwr
#100DaysofYARA
https://gist.github.com/williballenthin/08891865082a8bd5bf921b58fa312ada#file-peb_parsing-yara
π£williballenthin
π@malwr
Useful logs for Incident Responders
Bigger format: https://github.com/corelight/bro-cheatsheets
π£LetsDefendIO
π@malwr
Bigger format: https://github.com/corelight/bro-cheatsheets
π£LetsDefendIO
π@malwr
Procdump works against Defender with a simple rename. It quarantines the generated .dmp file but you have a few seconds to make a copy of it before it's removed.
I've seen other security solutions that do this, try to copy the file quickly before it's removed.
π£mrd0x
π@malwr
I've seen other security solutions that do this, try to copy the file quickly before it's removed.
π£mrd0x
π@malwr
Linux kernel exploit development tutorial
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
ChrisTheCoolHut published this tutorial as GitBook:
https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development
π£linkersec
π@malwr
breaking-bits.gitbook.io
Linux kernel exploit development | Breaking Bits
Windows Defender AV allows Everyone to read the configured exclusions on the system π€¦
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
π£splinter_code
π@malwr
New #SysJoker backdoor targets Windows, Linux and macOS
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr
Discovered during an active attack on a Linux-based web server
Linux and Mac versions are fully undetected in VirusTotal π·
http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
π£IntezerLabs
π@malwr
Technical details on APT35 attempts to exploit Log4j vulnerability:
π£Both targeted attacks and mass-scanning
πCharmPower: still-in-development Powershell-based modular toolkit
π§©Shared infrastructure with previous mobile and ransomware campaigns.
https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
π£_CPResearch_
π@malwr
π£Both targeted attacks and mass-scanning
πCharmPower: still-in-development Powershell-based modular toolkit
π§©Shared infrastructure with previous mobile and ransomware campaigns.
https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
π£_CPResearch_
π@malwr
Malware development serie:
β’ https://0xpat.github.io/Malware_development_part_1/
β’ https://0xpat.github.io/Malware_development_part_2/
β’ https://0xpat.github.io/Malware_development_part_3/
β’ https://0xpat.github.io/Malware_development_part_4/
β’ https://0xpat.github.io/Malware_development_part_5/
β’ https://0xpat.github.io/Malware_development_part_6/
β’ https://0xpat.github.io/Malware_development_part_7/
β’ https://0xpat.github.io/Malware_development_part_8/
β’ https://0xpat.github.io/Malware_development_part_9/
π£aas_s3curity
π@malwr
β’ https://0xpat.github.io/Malware_development_part_1/
β’ https://0xpat.github.io/Malware_development_part_2/
β’ https://0xpat.github.io/Malware_development_part_3/
β’ https://0xpat.github.io/Malware_development_part_4/
β’ https://0xpat.github.io/Malware_development_part_5/
β’ https://0xpat.github.io/Malware_development_part_6/
β’ https://0xpat.github.io/Malware_development_part_7/
β’ https://0xpat.github.io/Malware_development_part_8/
β’ https://0xpat.github.io/Malware_development_part_9/
π£aas_s3curity
π@malwr
β€4π₯2π1
Signed kernel drivers β Unguarded gateway to Windowsβ core | WeLiveSecurity
https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/
π£tais9
π@malwr
https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/
π£tais9
π@malwr
Welivesecurity
Signed kernel drivers β Unguarded gateway to Windowsβ core
ESET researchers look at malware that abuses vulnerabilities in kernel drivers and outline mitigation techniques against this type of exploitation
Anyone else aware that .asd files can contain macros? Literally just found out.
Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
π£mrd0x
π@malwr
Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
π£mrd0x
π@malwr
π¦ EtwTi-Syscall-Hook
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
GitHub
GitHub - paranoidninja/Process-Instrumentation-Syscall-Hook: A simple program to hook the current process to identify the manualβ¦
A simple program to hook the current process to identify the manual syscall executions on windows - paranoidninja/Process-Instrumentation-Syscall-Hook
[Tooling βοΈ] Updated DInjector with 'RemoteThreadKernelCB' technique for shellcode invocation by spoofing the fnCOPYDATA value in kernel callback table based on @SoumyadeepBas12βs gist. Thread execution via SendMessageA. Works for GUI processes βοΈ https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadKernelCB.cs
π£snovvcrash
π@malwr
π£snovvcrash
π@malwr
Today's quick #malware analysis with #SecurityOnion: #TA551 / #SHATHAK / #IcedID / #BOKBOT pcap from 2022-01-06!
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr