Are you an admin with EXE blocked by #AppLocker? You can bypass the protection without any execution traces in the AppLocker Log! Load your DLL, steal the token from spooler and create the child process.
C source code and the compiled binary, as usual: https://github.com/gtworek/PSBits/tree/master/AppLockerBypass
π£0gtweet
π@malwr
C source code and the compiled binary, as usual: https://github.com/gtworek/PSBits/tree/master/AppLockerBypass
π£0gtweet
π@malwr
Best searchπengines for Pentesters and Security Professionals.
β google .com
β Shodan .io
β Censys .io
β Hunter .io
β redhuntlabs .com
β fullhunt .io
β onyphe .io
β fofa .so
β socradar .io
β synapsint .com
β binaryedge .io
β ivre .rocks
β crt .sh
β spyse .com
β vulners .com
β PublicWWW .com
β Pulsedive .com
β ZoomEye .org
β intelx .io
β WiGLE .net
β reposify .com
β viz. greynoise .io
π£NandanLohitaksh
π@malwr
β google .com
β Shodan .io
β Censys .io
β Hunter .io
β redhuntlabs .com
β fullhunt .io
β onyphe .io
β fofa .so
β socradar .io
β synapsint .com
β binaryedge .io
β ivre .rocks
β crt .sh
β spyse .com
β vulners .com
β PublicWWW .com
β Pulsedive .com
β ZoomEye .org
β intelx .io
β WiGLE .net
β reposify .com
β viz. greynoise .io
π£NandanLohitaksh
π@malwr
For those following the news, the WhisperGate campaign (as initially described by Microsoft) has been quite impactful. Today, my blog for corporate has gone live regarding this wiper campaign, with the analysis of all four stages. Additionally, I uploaded the binary of stage 4 to VirusTotal, MalShare, and MalwareBazaar, making it accessible for all. The links are given below.
Link: https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/return-of-pseudo-ransomware.html
βΉοΈ Sent from one of our members
π@malwr
Link: https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/return-of-pseudo-ransomware.html
βΉοΈ Sent from one of our members
π@malwr
Trellix
Return of Pseudo Ransomware
Insights into the recent ransomware campaign targeting Ukraine.
An old sample of the Lamberts (probably #WhiteLambert) appeared on VirusTotal.
This driver file intel440x.sys is also mentioned by name on the infamous drv_list.txt from The Shadow Brokers' leak. The logic itself is contained inside a compressed resource.
https://www.virustotal.com/gui/file/1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b
π£_CPResearch_
π@malwr
This driver file intel440x.sys is also mentioned by name on the infamous drv_list.txt from The Shadow Brokers' leak. The logic itself is contained inside a compressed resource.
https://www.virustotal.com/gui/file/1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b
π£_CPResearch_
π@malwr
[1/n] Today I'm sharing the details of a research done by vaber_b, legezo, Ilya Borisov and myself on a UEFI firmware implant found in the wild, dubbed #MoonBounce. We assess that this formerly unknown threat is the work of the infamous #APT41. A π§΅
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
π£_marklech_
π@malwr
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
π£_marklech_
π@malwr
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
https://github.com/infosecn1nja/Red-Teaming-Toolkit
π£Dinosn
π@malwr
https://github.com/infosecn1nja/Red-Teaming-Toolkit
π£Dinosn
π@malwr
GitHub
GitHub - infosecn1nja/Red-Teaming-Toolkit: This repository contains cutting-edge open-source security tools (OST) for a red teamerβ¦
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter. - infosecn1nja/Red-Teaming-Toolkit
My research work from last year summarized in the blog post: Evolved phishing: Device registration trick adds to phishersβ toolbox for victims without MFA
https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
π£Pawp81
π@malwr
https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
π£Pawp81
π@malwr
Microsoft Security Blog
Evolved phishing: Device registration trick adds to phishersβ toolbox for victims without MFA | Microsoft Security Blog
We uncovered a large-scale, multi-phase campaign that adds a novel technique to traditional phishing tactics by joining an attacker-operated device to an organizationβs network to further propagate the campaign.
3.0: The Next Chapter. Today, weβre proud to announce the release of Binary Ninja 3.0. More than 6 months in the making, Binary Ninja 3.0 represents a huge leap forward in analysis and usability. Pseudo C decompilation, stack view and an overhauled UI https://binary.ninja/2022/01/27/3.0-the-next-chapter.html
π£vector35
π@malwr
π£vector35
π@malwr
Day 29 #100DaysofYARA using maths; counting the number of resources in a PE that have MZ headers!
I can only count to 5 on one hand so thats why the counter went this high
https://github.com/g-les/100DaysofYARA/blob/main/100_days_of_yara.yar
π£greglesnewich
π@malwr
I can only count to 5 on one hand so thats why the counter went this high
https://github.com/g-les/100DaysofYARA/blob/main/100_days_of_yara.yar
π£greglesnewich
π@malwr
Process Hollowing Alert is now in #SIGMA.
Sysmon Event ID 25 with a type of βimage is replacedβ
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon_process_hollowing.yml
π£SecurePeacock
π@malwr
Sysmon Event ID 25 with a type of βimage is replacedβ
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon_process_hollowing.yml
π£SecurePeacock
π@malwr
GitHub
sigma/sysmon_process_hollowing.yml at master Β· SigmaHQ/sigma
Generic Signature Format for SIEM Systems. Contribute to SigmaHQ/sigma development by creating an account on GitHub.
Stop Windows Defender programmatically
https://github.com/lab52io/StopDefender
π£pentest_swissky
π@malwr
https://github.com/lab52io/StopDefender
π£pentest_swissky
π@malwr
GitHub
GitHub - lab52io/StopDefender: Stop Windows Defender programmatically
Stop Windows Defender programmatically. Contribute to lab52io/StopDefender development by creating an account on GitHub.
I published a set of Python scripts that I use to integrate @dfir_iris , @MISPProject and @TimesketchProj #DFIR #CSIRT https://github.com/cudeso/dfir-iris-misp-timesketch
π£cudeso
π@malwr
π£cudeso
π@malwr
#MalwareAnalysis: Detecting Process Hollowing
The first pattern to look for are any calls to create processes in a suspended state:
> CreateProcessA
"dwCreationFlags" set 0x04 CREATE_SUSPENDED
Purpose is to disguise malicious code in a legit exe by replacing the contents.
Following the process being started in a suspended state... (usually svchost.exe but who's counting). Then there are API calls to native/non native APIs:
> ZwUnmapviewofsection
> virtualallocex
> writeprocessmemory
> setthreadcontext
> NTgetcontextthread
> ntreadvirtualmemory
Other ones:
> NTResumethread
> NTwritevirtualmemory
> ntsetcontextthread
The logic is to look for signs of processes being started in suspended state - then the process being hollowed, replaced with "malicious" contents and resuming of execution.
π£inversecos
π@malwr
The first pattern to look for are any calls to create processes in a suspended state:
> CreateProcessA
"dwCreationFlags" set 0x04 CREATE_SUSPENDED
Purpose is to disguise malicious code in a legit exe by replacing the contents.
Following the process being started in a suspended state... (usually svchost.exe but who's counting). Then there are API calls to native/non native APIs:
> ZwUnmapviewofsection
> virtualallocex
> writeprocessmemory
> setthreadcontext
> NTgetcontextthread
> ntreadvirtualmemory
Other ones:
> NTResumethread
> NTwritevirtualmemory
> ntsetcontextthread
The logic is to look for signs of processes being started in suspended state - then the process being hollowed, replaced with "malicious" contents and resuming of execution.
π£inversecos
π@malwr
Driver loader for bypassing Windows x64 Driver Signature Enforcement. #Hack #108 (2016)
https://github.com/hfiref0x/TDL
π£OPOSEC
π@malwr
https://github.com/hfiref0x/TDL
π£OPOSEC
π@malwr
GitHub
GitHub - hfiref0x/TDL: Driver loader for bypassing Windows x64 Driver Signature Enforcement
Driver loader for bypassing Windows x64 Driver Signature Enforcement - hfiref0x/TDL
Have you noticed that IDA sometimes renames and marks up local variables automatically? Read up on how Parameter identification and tracking aka PIT works:
https://hex-rays.com/blog/igors-tip-of-the-week-74-parameter-identification-and-tracking-pit/
#IgorsTipOfTheWeek #IDAtips #IDAPro
π£HexRaysSA
π@malwr
https://hex-rays.com/blog/igors-tip-of-the-week-74-parameter-identification-and-tracking-pit/
#IgorsTipOfTheWeek #IDAtips #IDAPro
π£HexRaysSA
π@malwr
Weekend Reading (or viewing) - a pretty clever set of C2 mechanisms, steganography and backdoors targeting Japan from @TeamT5_Official
might be a new favorite cluster Thinking face
check it out!
https://jsac.jpcert.or.jp/archive/2022/pdf/JSAC2022_7_leon-niwa-ishimaru_en.pdf
π£greglesnewich
π@malwr
might be a new favorite cluster Thinking face
check it out!
https://jsac.jpcert.or.jp/archive/2022/pdf/JSAC2022_7_leon-niwa-ishimaru_en.pdf
π£greglesnewich
π@malwr
π1
This media is not supported in your browser
VIEW IN TELEGRAM
I wrote a C++ library to parse Windows minidumps (.dump /mx) for another project; go check it out ππ½!
https://github.com/0vercl0k/udmp-parser/
π£0vercl0k
π@malwr
https://github.com/0vercl0k/udmp-parser/
π£0vercl0k
π@malwr