Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.08K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
[Tooling βš”οΈ] Updated DInjector with 'RemoteThreadKernelCB' technique for shellcode invocation by spoofing the fnCOPYDATA value in kernel callback table based on @SoumyadeepBas12’s gist. Thread execution via SendMessageA. Works for GUI processes βš™οΈ https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadKernelCB.cs
πŸ—£snovvcrash


πŸŽ–@malwr
Signature evasion...
πŸ—£MalwareJake


πŸŽ–@malwr
😁1
Today's quick #malware analysis with #SecurityOnion: #TA551 / #SHATHAK / #IcedID / #BOKBOT pcap from 2022-01-06!

Thanks to @malware_traffic for sharing this pcap!

More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
πŸ—£securityonion


πŸŽ–@malwr
I updated #IdaIFL plugin (v1.4.3): https://github.com/hasherezade/ida_ifl/releases/ - now you can load "*.imports.txt" report from #PEsieve into your IDB
πŸ—£hasherezade


πŸŽ–@malwr
Lazy phishing attempt of the decade. Better luck next time.
πŸ—£campuscodi


πŸŽ–@malwr
πŸ”We publish 6⃣ #Yara rules to detect πŸͺ“#HackTools that read / modifyπŸ–₯️ #RDP system settings. The rules are deliberately not only limited to detect PE files since these modifications may also take place in scripts etc.

https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar

#100DaysofYARA

- via @tbarabosch
πŸ—£DTCERT


πŸŽ–@malwr
Today's quick #malware analysis with #SecurityOnion: #Emotet pcap from 2022-01-11!

Thanks to malware_traffic for sharing this pcap!

More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-emotet-pcap-from.html
πŸ—£securityonion


πŸŽ–@malwr
dfirt: Collect information of Windows PC when doing incident response

#infosec #pentest #redteam
https://github.com/mamun-sec/dfirt
πŸ—£CyberWarship


πŸŽ–@malwr
Sentinel Labs' Amitai Ben Shushan Ehrlich looks into recent activity of the MuddyWater APT and presents the evolution of the PowGoop malware family, the usage of tunnelling tools, and the targeting of Exchange servers in high-profile organizations. https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/
πŸ—£virusbtn


πŸŽ–@malwr