Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.07K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
To people who asked me few minutes ago about how would be the IDA Pro's reversed code of the shellcode from previous message, few pictures follow. There isn't analysis here (not time to do it), but only structures and API hash resolving.

#malware #reversing
πŸ—£ale_sp_brazil


πŸŽ–@malwr
πŸ‘1
Took a quick look at Stage1.exe malware, as reported by Microsoft. Whipped up a quick (and simple) yara rule for it. #100DaysofYARA
πŸ—£CD_R0M_


πŸŽ–@malwr
A few more tricks when dealing with string literals in IDA:

https://hex-rays.com/blog/igors-tip-of-the-week-72-more-string-literals/

#IgorsTipOfTheWeek #IDAtips #IDAPro #HexraysDecompiler
πŸ—£HexRaysSA


πŸŽ–@malwr
πŸ‘1
More samples of WhisperGate, the MBR Overwriter targeting Ukraine

Stage 2 downloads a Stage 3 binary from Discord. Stage 3 is reversed binary. Stage 3 is reversed and it becomes a DLL module

Special thanks to silascutler & ffforward

Download it here: https://www.vx-underground.org/apts.html#2022
πŸ—£vxunderground


πŸŽ–@malwr
Jak and Daxter decompiled to GOAL and ported to the PC
πŸ—£corysama

Supporting custom language/ tools during crunch time at a game company must have come with a ton of stress for the poor individuals supporting it
πŸ‘€tnavda

Not my project. https://news.ycombinator.com/submitted?id=msk-lywenn might be related. They also posted https://blog.jakspeedruns.com/opengoal-project-update-september-2020/ to HN a while back
πŸ‘€corysama


πŸŽ–@malwr
Wine 7.0 released.
πŸ—£KindOne

WoW64 thunks are implemented for most Unix libraries, enabling a 32-bit PE module to call a 64-bit Unix library. Once the remaining modules are converted to PE, this will make it possible to run 32-bit applications without installing 32-bit Unix libraries.



πŸŽ–@malwr