π¦ EtwTi-Syscall-Hook
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
π€ NinjaParanoid
β 79 (+15)
π C
A simple program to hook the current process t...
https://github.com/paranoidninja/EtwTi-Syscall-Hook
π£gh_trending_
π@malwr
GitHub
GitHub - paranoidninja/Process-Instrumentation-Syscall-Hook: A simple program to hook the current process to identify the manualβ¦
A simple program to hook the current process to identify the manual syscall executions on windows - paranoidninja/Process-Instrumentation-Syscall-Hook
[Tooling βοΈ] Updated DInjector with 'RemoteThreadKernelCB' technique for shellcode invocation by spoofing the fnCOPYDATA value in kernel callback table based on @SoumyadeepBas12βs gist. Thread execution via SendMessageA. Works for GUI processes βοΈ https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadKernelCB.cs
π£snovvcrash
π@malwr
π£snovvcrash
π@malwr
Today's quick #malware analysis with #SecurityOnion: #TA551 / #SHATHAK / #IcedID / #BOKBOT pcap from 2022-01-06!
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr
Here's a #dfir #malware analysis of the Dridex anti-analysis methods of obfuscating API calls with hashing and vector exception handling
#cybersecurity #infosec
https://www.0ffset.net/reverse-engineering/malware-analysis/dridex-veh-api-obfuscation/?s=09
π£AGDCservices
π@malwr
#cybersecurity #infosec
https://www.0ffset.net/reverse-engineering/malware-analysis/dridex-veh-api-obfuscation/?s=09
π£AGDCservices
π@malwr
0ffset Training Solutions | Practical and Affordable Cyber Security Training
DRIDEX: Analysing API Obfuscation Through VEH | 0ffset
DRIDEX is one of the most famous and prevalent banking Trojans that dates back to around late 2014. Throughout its improvement and variations, DRIDEX has been successful in targeting the financial services sector to steal banking information and crucial userβ¦
I updated #IdaIFL plugin (v1.4.3): https://github.com/hasherezade/ida_ifl/releases/ - now you can load "*.imports.txt" report from #PEsieve into your IDB
π£hasherezade
π@malwr
π£hasherezade
π@malwr
πWe publish 6β£ #Yara rules to detect πͺ#HackTools that read / modifyπ₯οΈ #RDP system settings. The rules are deliberately not only limited to detect PE files since these modifications may also take place in scripts etc.
https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar
#100DaysofYARA
- via @tbarabosch
π£DTCERT
π@malwr
https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar
#100DaysofYARA
- via @tbarabosch
π£DTCERT
π@malwr
Today's quick #malware analysis with #SecurityOnion: #Emotet pcap from 2022-01-11!
Thanks to malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-emotet-pcap-from.html
π£securityonion
π@malwr
Thanks to malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-emotet-pcap-from.html
π£securityonion
π@malwr
XELFViewer - ELF file viewer/editor for Windows, Linux and MacOS.
0.04
[+] CMAKE build system
[+] New info file widget
[+] Many bugs have been fixed
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix
https://github.com/horsicq/XELFViewer
π£horsicq
π@malwr
0.04
[+] CMAKE build system
[+] New info file widget
[+] Many bugs have been fixed
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix
https://github.com/horsicq/XELFViewer
π£horsicq
π@malwr
GitHub
GitHub - horsicq/XELFViewer: ELF file viewer/editor for Windows, Linux and MacOS.
ELF file viewer/editor for Windows, Linux and MacOS. - horsicq/XELFViewer
dfirt: Collect information of Windows PC when doing incident response
#infosec #pentest #redteam
https://github.com/mamun-sec/dfirt
π£CyberWarship
π@malwr
#infosec #pentest #redteam
https://github.com/mamun-sec/dfirt
π£CyberWarship
π@malwr
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password
https://github.com/ihebski/DefaultCreds-cheat-sheet
π£Dinosn
π@malwr
https://github.com/ihebski/DefaultCreds-cheat-sheet
π£Dinosn
π@malwr
GitHub
GitHub - ihebski/DefaultCreds-cheat-sheet: One place for all the default credentials to assist the Blue/Red teamers identifyingβ¦
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password π‘οΈ - ihebski/DefaultCreds-cheat-sheet
Sentinel Labs' Amitai Ben Shushan Ehrlich looks into recent activity of the MuddyWater APT and presents the evolution of the PowGoop malware family, the usage of tunnelling tools, and the targeting of Exchange servers in high-profile organizations. https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/
π£virusbtn
π@malwr
π£virusbtn
π@malwr