Today's quick #malware analysis with #SecurityOnion: #Emotet pcap from 2022-01-11!
Thanks to malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-emotet-pcap-from.html
π£securityonion
π@malwr
Thanks to malware_traffic for sharing this pcap!
More screenshots:
https://blog.securityonion.net/2022/01/quick-malware-analysis-emotet-pcap-from.html
π£securityonion
π@malwr
XELFViewer - ELF file viewer/editor for Windows, Linux and MacOS.
0.04
[+] CMAKE build system
[+] New info file widget
[+] Many bugs have been fixed
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix
https://github.com/horsicq/XELFViewer
π£horsicq
π@malwr
0.04
[+] CMAKE build system
[+] New info file widget
[+] Many bugs have been fixed
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix
https://github.com/horsicq/XELFViewer
π£horsicq
π@malwr
GitHub
GitHub - horsicq/XELFViewer: ELF file viewer/editor for Windows, Linux and MacOS.
ELF file viewer/editor for Windows, Linux and MacOS. - horsicq/XELFViewer
dfirt: Collect information of Windows PC when doing incident response
#infosec #pentest #redteam
https://github.com/mamun-sec/dfirt
π£CyberWarship
π@malwr
#infosec #pentest #redteam
https://github.com/mamun-sec/dfirt
π£CyberWarship
π@malwr
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password
https://github.com/ihebski/DefaultCreds-cheat-sheet
π£Dinosn
π@malwr
https://github.com/ihebski/DefaultCreds-cheat-sheet
π£Dinosn
π@malwr
GitHub
GitHub - ihebski/DefaultCreds-cheat-sheet: One place for all the default credentials to assist the Blue/Red teamers identifyingβ¦
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password π‘οΈ - ihebski/DefaultCreds-cheat-sheet
Sentinel Labs' Amitai Ben Shushan Ehrlich looks into recent activity of the MuddyWater APT and presents the evolution of the PowGoop malware family, the usage of tunnelling tools, and the targeting of Exchange servers in high-profile organizations. https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/
π£virusbtn
π@malwr
π£virusbtn
π@malwr
Ukraine's MFA, MOD, State Emergency Service, Cabinet of Ministers, and Ministry of Education sites all hacked/defaced https://ru.interfax.com.ua/news/general/791451.html
π£pwnallthethings
π@malwr
π£pwnallthethings
π@malwr
Scemu - X86 32bits Emulator, For Securely Emulating Shellcodes
http://www.kitploit.com/2022/01/scemu-x86-32bits-emulator-for-securely.html
π£Dinosn
π@malwr
http://www.kitploit.com/2022/01/scemu-x86-32bits-emulator-for-securely.html
π£Dinosn
π@malwr
KitPloit - PenTest & Hacking Tools
Scemu - X86 32bits Emulator, For Securely Emulating Shellcodes
Forwarded from Intel Slava
π·πΊπΊπ² The FSB, after an appeal from the United States, detained a group of REvil hackers who sent out viruses to extort money.
At 25 addresses of places of stay, 14 members of the organized criminal community seized over 426 million rubles, including in cryptocurrency, 600 thousand dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars, acquired with money obtained by criminal means.
At 25 addresses of places of stay, 14 members of the organized criminal community seized over 426 million rubles, including in cryptocurrency, 600 thousand dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars, acquired with money obtained by criminal means.
3DO M2 Giant SDK Source Code Dump! The Cancelled 3DO M2 Laid Bare with Files, Details and More!
π£chicagogamecollector
already proving very fruitful to some of our reverse engineering projects. If anyone is into rare gaming lmk. Always need more people in the community :)
π€chicagogamecollector
π@malwr
π£chicagogamecollector
already proving very fruitful to some of our reverse engineering projects. If anyone is into rare gaming lmk. Always need more people in the community :)
π€chicagogamecollector
π@malwr
YouTube
3DO M2 Giant Source Code Dump! The Cancelled 3DO M2 Laid Bare with Files, Details and More!
Well well well...what do we have here? the 3DO M2 SDK source code? Details on how the 3DO M2 is actually technically backwards compatible with the OG 3DO? The public and private keys? The entire keys to the M2 kingdom for everyone to have? That and a lotβ¦
FirmWire/FirmWire: FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares
π£igor_sk
Is this not based on the Qiling framework? (For those of you who haven't clicked through to the repo, they haven't published the code yet)
π€Jonathan-Todd
π@malwr
π£igor_sk
Is this not based on the Qiling framework? (For those of you who haven't clicked through to the repo, they haven't published the code yet)
π€Jonathan-Todd
π@malwr
GitHub
GitHub - FirmWire/FirmWire: FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-causeβ¦
FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares - FirmWire/FirmWire
π1
While I'm still writing the 2nd article of Malware Analysis Series (MAS), which I'm on page 43 and far from the end, I dropped a short and simple write-up on malicious document to help beginners on threat analysis.
https://exploitreversing.com/2022/01/14/malicious-document-analysis-example-2/
#maldoc #threatanalysis
π£ale_sp_brazil
π@malwr
https://exploitreversing.com/2022/01/14/malicious-document-analysis-example-2/
#maldoc #threatanalysis
π£ale_sp_brazil
π@malwr
Use of Alternate Data Streams in Research Scans for index.jsp. #ntfs #ads #jsp https://i5c.us/d28240
π£sans_isc
π@malwr
π£sans_isc
π@malwr
Project Ares is a PoC loader written in C/C++ based on the Transacted Hollowing technique. It features:
* PPID spoofing
* Dynamic function resolution with API hashing
* NTDLL unhooking
* AES256 CBC Encryption
and more!
https://github.com/Cerbersec/Ares
π£cerbersec
π@malwr
* PPID spoofing
* Dynamic function resolution with API hashing
* NTDLL unhooking
* AES256 CBC Encryption
and more!
https://github.com/Cerbersec/Ares
π£cerbersec
π@malwr
GitHub
GitHub - Cerbersec/Ares: Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique
Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique - Cerbersec/Ares
Just released my DLL Injection blog post. The post covers:
1. How to use LoadLibrary to inject a DLL
2. How to load a DLL into memory, parse the headers, load sections, perform relocations, resolve imports, and finally inject the DLL into another process
https://kasimir123.github.io/blog-posts/DLL%20Injection.html
π£Abraxus7331
π@malwr
1. How to use LoadLibrary to inject a DLL
2. How to load a DLL into memory, parse the headers, load sections, perform relocations, resolve imports, and finally inject the DLL into another process
https://kasimir123.github.io/blog-posts/DLL%20Injection.html
π£Abraxus7331
π@malwr
kasimir123.github.io
From LoadLibrary to Manually Mapping, the Art of DLL Injection - DLL Injection
π1
π‘οΈ Awesome Cloud Security Resources βοΈ
https://github.com/4ndersonLin/awesome-cloud-security
#cloudhacking #cybersecurity #appsec #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/4ndersonLin/awesome-cloud-security
#cloudhacking #cybersecurity #appsec #bughunting
π£0xAsm0d3us
π@malwr