Today's quick #malware analysis with #SecurityOnion: #TA551 / #SHATHAK / #IcedID / #BOKBOT pcap from 2022-01-06!
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr
Thanks to @malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-ta551-shathak_12.html
π£securityonion
π@malwr
Here's a #dfir #malware analysis of the Dridex anti-analysis methods of obfuscating API calls with hashing and vector exception handling
#cybersecurity #infosec
https://www.0ffset.net/reverse-engineering/malware-analysis/dridex-veh-api-obfuscation/?s=09
π£AGDCservices
π@malwr
#cybersecurity #infosec
https://www.0ffset.net/reverse-engineering/malware-analysis/dridex-veh-api-obfuscation/?s=09
π£AGDCservices
π@malwr
0ffset Training Solutions | Practical and Affordable Cyber Security Training
DRIDEX: Analysing API Obfuscation Through VEH | 0ffset
DRIDEX is one of the most famous and prevalent banking Trojans that dates back to around late 2014. Throughout its improvement and variations, DRIDEX has been successful in targeting the financial services sector to steal banking information and crucial userβ¦
I updated #IdaIFL plugin (v1.4.3): https://github.com/hasherezade/ida_ifl/releases/ - now you can load "*.imports.txt" report from #PEsieve into your IDB
π£hasherezade
π@malwr
π£hasherezade
π@malwr
πWe publish 6β£ #Yara rules to detect πͺ#HackTools that read / modifyπ₯οΈ #RDP system settings. The rules are deliberately not only limited to detect PE files since these modifications may also take place in scripts etc.
https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar
#100DaysofYARA
- via @tbarabosch
π£DTCERT
π@malwr
https://github.com/telekom-security/malware_analysis/blob/main/hacktools/hacktools.yar
#100DaysofYARA
- via @tbarabosch
π£DTCERT
π@malwr
Today's quick #malware analysis with #SecurityOnion: #Emotet pcap from 2022-01-11!
Thanks to malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-emotet-pcap-from.html
π£securityonion
π@malwr
Thanks to malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-emotet-pcap-from.html
π£securityonion
π@malwr
XELFViewer - ELF file viewer/editor for Windows, Linux and MacOS.
0.04
[+] CMAKE build system
[+] New info file widget
[+] Many bugs have been fixed
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix
https://github.com/horsicq/XELFViewer
π£horsicq
π@malwr
0.04
[+] CMAKE build system
[+] New info file widget
[+] Many bugs have been fixed
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix
https://github.com/horsicq/XELFViewer
π£horsicq
π@malwr
GitHub
GitHub - horsicq/XELFViewer: ELF file viewer/editor for Windows, Linux and MacOS.
ELF file viewer/editor for Windows, Linux and MacOS. - horsicq/XELFViewer
dfirt: Collect information of Windows PC when doing incident response
#infosec #pentest #redteam
https://github.com/mamun-sec/dfirt
π£CyberWarship
π@malwr
#infosec #pentest #redteam
https://github.com/mamun-sec/dfirt
π£CyberWarship
π@malwr
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password
https://github.com/ihebski/DefaultCreds-cheat-sheet
π£Dinosn
π@malwr
https://github.com/ihebski/DefaultCreds-cheat-sheet
π£Dinosn
π@malwr
GitHub
GitHub - ihebski/DefaultCreds-cheat-sheet: One place for all the default credentials to assist the Blue/Red teamers identifyingβ¦
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password π‘οΈ - ihebski/DefaultCreds-cheat-sheet
Sentinel Labs' Amitai Ben Shushan Ehrlich looks into recent activity of the MuddyWater APT and presents the evolution of the PowGoop malware family, the usage of tunnelling tools, and the targeting of Exchange servers in high-profile organizations. https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/
π£virusbtn
π@malwr
π£virusbtn
π@malwr
Ukraine's MFA, MOD, State Emergency Service, Cabinet of Ministers, and Ministry of Education sites all hacked/defaced https://ru.interfax.com.ua/news/general/791451.html
π£pwnallthethings
π@malwr
π£pwnallthethings
π@malwr
Scemu - X86 32bits Emulator, For Securely Emulating Shellcodes
http://www.kitploit.com/2022/01/scemu-x86-32bits-emulator-for-securely.html
π£Dinosn
π@malwr
http://www.kitploit.com/2022/01/scemu-x86-32bits-emulator-for-securely.html
π£Dinosn
π@malwr
KitPloit - PenTest & Hacking Tools
Scemu - X86 32bits Emulator, For Securely Emulating Shellcodes
Forwarded from Intel Slava
π·πΊπΊπ² The FSB, after an appeal from the United States, detained a group of REvil hackers who sent out viruses to extort money.
At 25 addresses of places of stay, 14 members of the organized criminal community seized over 426 million rubles, including in cryptocurrency, 600 thousand dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars, acquired with money obtained by criminal means.
At 25 addresses of places of stay, 14 members of the organized criminal community seized over 426 million rubles, including in cryptocurrency, 600 thousand dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars, acquired with money obtained by criminal means.