Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.08K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Windows Defender AV allows Everyone to read the configured exclusions on the system 🀦

reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
πŸ—£splinter_code


πŸŽ–@malwr
New #SysJoker backdoor targets Windows, Linux and macOS

Discovered during an active attack on a Linux-based web server

Linux and Mac versions are fully undetected in VirusTotal 🚷

http://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker
πŸ—£IntezerLabs


πŸŽ–@malwr
Technical details on APT35 attempts to exploit Log4j vulnerability:
πŸ’£Both targeted attacks and mass-scanning
πŸ’ŽCharmPower: still-in-development Powershell-based modular toolkit
🧩Shared infrastructure with previous mobile and ransomware campaigns.

https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit
πŸ—£_CPResearch_


πŸŽ–@malwr
Anyone else aware that .asd files can contain macros? Literally just found out.

Added to Filesec:
https://filesec.io/asd
https://filesec.io/wbk
πŸ—£mrd0x


πŸŽ–@malwr
[Tooling βš”οΈ] Updated DInjector with 'RemoteThreadKernelCB' technique for shellcode invocation by spoofing the fnCOPYDATA value in kernel callback table based on @SoumyadeepBas12’s gist. Thread execution via SendMessageA. Works for GUI processes βš™οΈ https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadKernelCB.cs
πŸ—£snovvcrash


πŸŽ–@malwr
Signature evasion...
πŸ—£MalwareJake


πŸŽ–@malwr
😁1
Today's quick #malware analysis with #SecurityOnion: #TA551 / #SHATHAK / #IcedID / #BOKBOT pcap from 2022-01-06!

Thanks to @malware_traffic for sharing this pcap!

More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
πŸ—£securityonion


πŸŽ–@malwr
I updated #IdaIFL plugin (v1.4.3): https://github.com/hasherezade/ida_ifl/releases/ - now you can load "*.imports.txt" report from #PEsieve into your IDB
πŸ—£hasherezade


πŸŽ–@malwr
Lazy phishing attempt of the decade. Better luck next time.
πŸ—£campuscodi


πŸŽ–@malwr
πŸ”We publish 6⃣ #Yara rules to detect πŸͺ“#HackTools that read / modifyπŸ–₯️ #RDP system settings. The rules are deliberately not only limited to detect PE files since these modifications may also take place in scripts etc.

https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar

#100DaysofYARA

- via @tbarabosch
πŸ—£DTCERT


πŸŽ–@malwr