Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.07K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Time to chip in for #100DaysofYARA, this rule is a (fun) example that looks for a structure (#Regin VFS) instead of data.
Structures (often config) are useful to validate your understanding of malware functionality and for more resilient rules. But be careful with boundaries :)
πŸ—£Int2e_


πŸŽ–@malwr
Forwarded from CVE Notify
🚨 CVE-2022-0173
radare2 is vulnerable to Out-of-bounds Read

πŸŽ–@cveNotify
We do not possess any samples from Lockbit Ransomware group. A new sample from Lockbit has not appeared on @abuse_ch since December, 2021.

We asked Lockbit for a new sample - they have provided us with a sample directly from their panel.

Download here: https://samples.vx-underground.org/samples/Families/
πŸ—£vxunderground


πŸŽ–@malwr
About the WhisperGate, it's quite simple to setup the IDA Pro + Bochs to examine the MBR and I showed it step-by-step few slides in an introductory talk at HTIB Amsterdam 2019. Just it case you want to check slides:

https://exploitreversing.files.wordpress.com/2021/12/hitb_ams_2019-1.pdf

#malware #idapro
πŸ—£ale_sp_brazil


πŸŽ–@malwr
Are you an admin with EXE blocked by #AppLocker? You can bypass the protection without any execution traces in the AppLocker Log! Load your DLL, steal the token from spooler and create the child process.
C source code and the compiled binary, as usual: https://github.com/gtworek/PSBits/tree/master/AppLockerBypass
πŸ—£0gtweet


πŸŽ–@malwr
Best searchπŸ”Žengines for Pentesters and Security Professionals.

β†’ google .com
β†’ Shodan .io
β†’ Censys .io
β†’ Hunter .io
β†’ redhuntlabs .com
β†’ fullhunt .io
β†’ onyphe .io
β†’ fofa .so
β†’ socradar .io
β†’ synapsint .com
β†’ binaryedge .io
β†’ ivre .rocks
β†’ crt .sh
β†’ spyse .com
β†’ vulners .com
β†’ PublicWWW .com
β†’ Pulsedive .com
β†’ ZoomEye .org
β†’ intelx .io
β†’ WiGLE .net
β†’ reposify .com
β†’ viz. greynoise .io

πŸ—£NandanLohitaksh


πŸŽ–@malwr
For those following the news, the WhisperGate campaign (as initially described by Microsoft) has been quite impactful. Today, my blog for corporate has gone live regarding this wiper campaign, with the analysis of all four stages. Additionally, I uploaded the binary of stage 4 to VirusTotal, MalShare, and MalwareBazaar, making it accessible for all. The links are given below.

Link: https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/return-of-pseudo-ransomware.html


ℹ️ Sent from one of our members


πŸŽ–@malwr
An old sample of the Lamberts (probably #WhiteLambert) appeared on VirusTotal.
This driver file intel440x.sys is also mentioned by name on the infamous drv_list.txt from The Shadow Brokers' leak. The logic itself is contained inside a compressed resource.
https://www.virustotal.com/gui/file/1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b
πŸ—£_CPResearch_


πŸŽ–@malwr
[1/n] Today I'm sharing the details of a research done by vaber_b, legezo, Ilya Borisov and myself on a UEFI firmware implant found in the wild, dubbed #MoonBounce. We assess that this formerly unknown threat is the work of the infamous #APT41. A 🧡
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
πŸ—£_marklech_


πŸŽ–@malwr
3.0: The Next Chapter. Today, we’re proud to announce the release of Binary Ninja 3.0. More than 6 months in the making, Binary Ninja 3.0 represents a huge leap forward in analysis and usability. Pseudo C decompilation, stack view and an overhauled UI https://binary.ninja/2022/01/27/3.0-the-next-chapter.html
πŸ—£vector35


πŸŽ–@malwr
65 page history of REvil looks really nice
https://t.co/4hvdloS9Vo?s=09
πŸ—£maldr0id


πŸŽ–@malwr
Day 29 #100DaysofYARA using maths; counting the number of resources in a PE that have MZ headers!

I can only count to 5 on one hand so thats why the counter went this high

https://github.com/g-les/100DaysofYARA/blob/main/100_days_of_yara.yar
πŸ—£greglesnewich


πŸŽ–@malwr
I published a set of Python scripts that I use to integrate @dfir_iris , @MISPProject and @TimesketchProj #DFIR #CSIRT https://github.com/cudeso/dfir-iris-misp-timesketch
πŸ—£cudeso


πŸŽ–@malwr