Scemu - X86 32bits Emulator, For Securely Emulating Shellcodes
http://www.kitploit.com/2022/01/scemu-x86-32bits-emulator-for-securely.html
π£Dinosn
π@malwr
http://www.kitploit.com/2022/01/scemu-x86-32bits-emulator-for-securely.html
π£Dinosn
π@malwr
KitPloit - PenTest & Hacking Tools
Scemu - X86 32bits Emulator, For Securely Emulating Shellcodes
Forwarded from Intel Slava
π·πΊπΊπ² The FSB, after an appeal from the United States, detained a group of REvil hackers who sent out viruses to extort money.
At 25 addresses of places of stay, 14 members of the organized criminal community seized over 426 million rubles, including in cryptocurrency, 600 thousand dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars, acquired with money obtained by criminal means.
At 25 addresses of places of stay, 14 members of the organized criminal community seized over 426 million rubles, including in cryptocurrency, 600 thousand dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars, acquired with money obtained by criminal means.
3DO M2 Giant SDK Source Code Dump! The Cancelled 3DO M2 Laid Bare with Files, Details and More!
π£chicagogamecollector
already proving very fruitful to some of our reverse engineering projects. If anyone is into rare gaming lmk. Always need more people in the community :)
π€chicagogamecollector
π@malwr
π£chicagogamecollector
already proving very fruitful to some of our reverse engineering projects. If anyone is into rare gaming lmk. Always need more people in the community :)
π€chicagogamecollector
π@malwr
YouTube
3DO M2 Giant Source Code Dump! The Cancelled 3DO M2 Laid Bare with Files, Details and More!
Well well well...what do we have here? the 3DO M2 SDK source code? Details on how the 3DO M2 is actually technically backwards compatible with the OG 3DO? The public and private keys? The entire keys to the M2 kingdom for everyone to have? That and a lotβ¦
FirmWire/FirmWire: FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares
π£igor_sk
Is this not based on the Qiling framework? (For those of you who haven't clicked through to the repo, they haven't published the code yet)
π€Jonathan-Todd
π@malwr
π£igor_sk
Is this not based on the Qiling framework? (For those of you who haven't clicked through to the repo, they haven't published the code yet)
π€Jonathan-Todd
π@malwr
GitHub
GitHub - FirmWire/FirmWire: FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-causeβ¦
FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares - FirmWire/FirmWire
π1
While I'm still writing the 2nd article of Malware Analysis Series (MAS), which I'm on page 43 and far from the end, I dropped a short and simple write-up on malicious document to help beginners on threat analysis.
https://exploitreversing.com/2022/01/14/malicious-document-analysis-example-2/
#maldoc #threatanalysis
π£ale_sp_brazil
π@malwr
https://exploitreversing.com/2022/01/14/malicious-document-analysis-example-2/
#maldoc #threatanalysis
π£ale_sp_brazil
π@malwr
Use of Alternate Data Streams in Research Scans for index.jsp. #ntfs #ads #jsp https://i5c.us/d28240
π£sans_isc
π@malwr
π£sans_isc
π@malwr
Project Ares is a PoC loader written in C/C++ based on the Transacted Hollowing technique. It features:
* PPID spoofing
* Dynamic function resolution with API hashing
* NTDLL unhooking
* AES256 CBC Encryption
and more!
https://github.com/Cerbersec/Ares
π£cerbersec
π@malwr
* PPID spoofing
* Dynamic function resolution with API hashing
* NTDLL unhooking
* AES256 CBC Encryption
and more!
https://github.com/Cerbersec/Ares
π£cerbersec
π@malwr
GitHub
GitHub - Cerbersec/Ares: Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique
Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique - Cerbersec/Ares
Just released my DLL Injection blog post. The post covers:
1. How to use LoadLibrary to inject a DLL
2. How to load a DLL into memory, parse the headers, load sections, perform relocations, resolve imports, and finally inject the DLL into another process
https://kasimir123.github.io/blog-posts/DLL%20Injection.html
π£Abraxus7331
π@malwr
1. How to use LoadLibrary to inject a DLL
2. How to load a DLL into memory, parse the headers, load sections, perform relocations, resolve imports, and finally inject the DLL into another process
https://kasimir123.github.io/blog-posts/DLL%20Injection.html
π£Abraxus7331
π@malwr
kasimir123.github.io
From LoadLibrary to Manually Mapping, the Art of DLL Injection - DLL Injection
π1
π‘οΈ Awesome Cloud Security Resources βοΈ
https://github.com/4ndersonLin/awesome-cloud-security
#cloudhacking #cybersecurity #appsec #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/4ndersonLin/awesome-cloud-security
#cloudhacking #cybersecurity #appsec #bughunting
π£0xAsm0d3us
π@malwr
OH SHIT HERE WE GOOOOOO
https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
π£jfslowik
π@malwr
https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
π£jfslowik
π@malwr
Microsoft News
Destructive malware targeting Ukrainian organizations
Microsoft Threat Intelligence Center (MSTIC) has identified evidence of a destructive malware operation targeting multiple organizations in Ukraine.
This media is not supported in your browser
VIEW IN TELEGRAM
Released VeraCryptThief which is an exercise of mine of playing with API hooking to capture clear-text VeraCrypt passwords and save them on disk π Features: hooking via Detours, reflective DLL shellcode via sRDI, process injection via D/Invoke in C# π₯ https://github.com/snovvcrash/VeraCryptThief
π£snovvcrash
π@malwr
π£snovvcrash
π@malwr
π2
To people who asked me few minutes ago about how would be the IDA Pro's reversed code of the shellcode from previous message, few pictures follow. There isn't analysis here (not time to do it), but only structures and API hash resolving.
#malware #reversing
π£ale_sp_brazil
π@malwr
#malware #reversing
π£ale_sp_brazil
π@malwr
π1
Took a quick look at Stage1.exe malware, as reported by Microsoft. Whipped up a quick (and simple) yara rule for it. #100DaysofYARA
π£CD_R0M_
π@malwr
π£CD_R0M_
π@malwr
A few more tricks when dealing with string literals in IDA:
https://hex-rays.com/blog/igors-tip-of-the-week-72-more-string-literals/
#IgorsTipOfTheWeek #IDAtips #IDAPro #HexraysDecompiler
π£HexRaysSA
π@malwr
https://hex-rays.com/blog/igors-tip-of-the-week-72-more-string-literals/
#IgorsTipOfTheWeek #IDAtips #IDAPro #HexraysDecompiler
π£HexRaysSA
π@malwr
π1
IOCTLDump https://github.com/Kharos102/IOCTLDump #pentesting #CyberSecurity #Infosec
π£ptracesecurity
π@malwr
π£ptracesecurity
π@malwr