Use of Alternate Data Streams in Research Scans for index.jsp. #ntfs #ads #jsp https://i5c.us/d28240
π£sans_isc
π@malwr
π£sans_isc
π@malwr
Project Ares is a PoC loader written in C/C++ based on the Transacted Hollowing technique. It features:
* PPID spoofing
* Dynamic function resolution with API hashing
* NTDLL unhooking
* AES256 CBC Encryption
and more!
https://github.com/Cerbersec/Ares
π£cerbersec
π@malwr
* PPID spoofing
* Dynamic function resolution with API hashing
* NTDLL unhooking
* AES256 CBC Encryption
and more!
https://github.com/Cerbersec/Ares
π£cerbersec
π@malwr
GitHub
GitHub - Cerbersec/Ares: Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique
Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique - Cerbersec/Ares
Just released my DLL Injection blog post. The post covers:
1. How to use LoadLibrary to inject a DLL
2. How to load a DLL into memory, parse the headers, load sections, perform relocations, resolve imports, and finally inject the DLL into another process
https://kasimir123.github.io/blog-posts/DLL%20Injection.html
π£Abraxus7331
π@malwr
1. How to use LoadLibrary to inject a DLL
2. How to load a DLL into memory, parse the headers, load sections, perform relocations, resolve imports, and finally inject the DLL into another process
https://kasimir123.github.io/blog-posts/DLL%20Injection.html
π£Abraxus7331
π@malwr
kasimir123.github.io
From LoadLibrary to Manually Mapping, the Art of DLL Injection - DLL Injection
π1
π‘οΈ Awesome Cloud Security Resources βοΈ
https://github.com/4ndersonLin/awesome-cloud-security
#cloudhacking #cybersecurity #appsec #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/4ndersonLin/awesome-cloud-security
#cloudhacking #cybersecurity #appsec #bughunting
π£0xAsm0d3us
π@malwr
OH SHIT HERE WE GOOOOOO
https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
π£jfslowik
π@malwr
https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
π£jfslowik
π@malwr
Microsoft News
Destructive malware targeting Ukrainian organizations
Microsoft Threat Intelligence Center (MSTIC) has identified evidence of a destructive malware operation targeting multiple organizations in Ukraine.
This media is not supported in your browser
VIEW IN TELEGRAM
Released VeraCryptThief which is an exercise of mine of playing with API hooking to capture clear-text VeraCrypt passwords and save them on disk π Features: hooking via Detours, reflective DLL shellcode via sRDI, process injection via D/Invoke in C# π₯ https://github.com/snovvcrash/VeraCryptThief
π£snovvcrash
π@malwr
π£snovvcrash
π@malwr
π2
To people who asked me few minutes ago about how would be the IDA Pro's reversed code of the shellcode from previous message, few pictures follow. There isn't analysis here (not time to do it), but only structures and API hash resolving.
#malware #reversing
π£ale_sp_brazil
π@malwr
#malware #reversing
π£ale_sp_brazil
π@malwr
π1
Took a quick look at Stage1.exe malware, as reported by Microsoft. Whipped up a quick (and simple) yara rule for it. #100DaysofYARA
π£CD_R0M_
π@malwr
π£CD_R0M_
π@malwr
A few more tricks when dealing with string literals in IDA:
https://hex-rays.com/blog/igors-tip-of-the-week-72-more-string-literals/
#IgorsTipOfTheWeek #IDAtips #IDAPro #HexraysDecompiler
π£HexRaysSA
π@malwr
https://hex-rays.com/blog/igors-tip-of-the-week-72-more-string-literals/
#IgorsTipOfTheWeek #IDAtips #IDAPro #HexraysDecompiler
π£HexRaysSA
π@malwr
π1
IOCTLDump https://github.com/Kharos102/IOCTLDump #pentesting #CyberSecurity #Infosec
π£ptracesecurity
π@malwr
π£ptracesecurity
π@malwr
More samples of WhisperGate, the MBR Overwriter targeting Ukraine
Stage 2 downloads a Stage 3 binary from Discord. Stage 3 is reversed binary. Stage 3 is reversed and it becomes a DLL module
Special thanks to silascutler & ffforward
Download it here: https://www.vx-underground.org/apts.html#2022
π£vxunderground
π@malwr
Stage 2 downloads a Stage 3 binary from Discord. Stage 3 is reversed binary. Stage 3 is reversed and it becomes a DLL module
Special thanks to silascutler & ffforward
Download it here: https://www.vx-underground.org/apts.html#2022
π£vxunderground
π@malwr
Jak and Daxter decompiled to GOAL and ported to the PC
π£corysama
Supporting custom language/ tools during crunch time at a game company must have come with a ton of stress for the poor individuals supporting it
π€tnavda
Not my project. https://news.ycombinator.com/submitted?id=msk-lywenn might be related. They also posted https://blog.jakspeedruns.com/opengoal-project-update-september-2020/ to HN a while back
π€corysama
π@malwr
π£corysama
Supporting custom language/ tools during crunch time at a game company must have come with a ton of stress for the poor individuals supporting it
π€tnavda
Not my project. https://news.ycombinator.com/submitted?id=msk-lywenn might be related. They also posted https://blog.jakspeedruns.com/opengoal-project-update-september-2020/ to HN a while back
π€corysama
π@malwr
GitHub
GitHub - open-goal/jak-project: Reviving the language that brought us the Jak & Daxter Series
Reviving the language that brought us the Jak & Daxter Series - open-goal/jak-project
Wine 7.0 released.
π£KindOne
WoW64 thunks are implemented for most Unix libraries, enabling a 32-bit PE module to call a 64-bit Unix library. Once the remaining modules are converted to PE, this will make it possible to run 32-bit applications without installing 32-bit Unix libraries.
π@malwr
π£KindOne
WoW64 thunks are implemented for most Unix libraries, enabling a 32-bit PE module to call a 64-bit Unix library. Once the remaining modules are converted to PE, this will make it possible to run 32-bit applications without installing 32-bit Unix libraries.
π@malwr
WineHQ
The Wine team is proud to announce that the stable release Wine 7.0
Operation Falcon II: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Ring Members
π£quellaman
π@malwr
π£quellaman
π@malwr
Unit 42
Operation Falcon II: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Ring Members
Operation Falcon II, championed by INTERPOL and The Nigeria Police Force, led to the arrest of Nigerian business email compromise actors.