Malware News
15.6K subscribers
1.64K photos
7 videos
130 files
8.06K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
[1/n] Today I'm sharing the details of a research done by vaber_b, legezo, Ilya Borisov and myself on a UEFI firmware implant found in the wild, dubbed #MoonBounce. We assess that this formerly unknown threat is the work of the infamous #APT41. A ๐Ÿงต
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
๐Ÿ—ฃ_marklech_


๐ŸŽ–@malwr
3.0: The Next Chapter. Today, weโ€™re proud to announce the release of Binary Ninja 3.0. More than 6 months in the making, Binary Ninja 3.0 represents a huge leap forward in analysis and usability. Pseudo C decompilation, stack view and an overhauled UI https://binary.ninja/2022/01/27/3.0-the-next-chapter.html
๐Ÿ—ฃvector35


๐ŸŽ–@malwr
65 page history of REvil looks really nice
https://t.co/4hvdloS9Vo?s=09
๐Ÿ—ฃmaldr0id


๐ŸŽ–@malwr
Day 29 #100DaysofYARA using maths; counting the number of resources in a PE that have MZ headers!

I can only count to 5 on one hand so thats why the counter went this high

https://github.com/g-les/100DaysofYARA/blob/main/100_days_of_yara.yar
๐Ÿ—ฃgreglesnewich


๐ŸŽ–@malwr
I published a set of Python scripts that I use to integrate @dfir_iris , @MISPProject and @TimesketchProj #DFIR #CSIRT https://github.com/cudeso/dfir-iris-misp-timesketch
๐Ÿ—ฃcudeso


๐ŸŽ–@malwr
#MalwareAnalysis: Detecting Process Hollowing
The first pattern to look for are any calls to create processes in a suspended state:

> CreateProcessA
"dwCreationFlags" set 0x04 CREATE_SUSPENDED

Purpose is to disguise malicious code in a legit exe by replacing the contents.

Following the process being started in a suspended state... (usually svchost.exe but who's counting). Then there are API calls to native/non native APIs:

> ZwUnmapviewofsection
> virtualallocex
> writeprocessmemory
> setthreadcontext
> NTgetcontextthread
> ntreadvirtualmemory

Other ones:
> NTResumethread
> NTwritevirtualmemory
> ntsetcontextthread

The logic is to look for signs of processes being started in suspended state - then the process being hollowed, replaced with "malicious" contents and resuming of execution.

๐Ÿ—ฃinversecos


๐ŸŽ–@malwr
Have you noticed that IDA sometimes renames and marks up local variables automatically? Read up on how Parameter identification and tracking aka PIT works:

https://hex-rays.com/blog/igors-tip-of-the-week-74-parameter-identification-and-tracking-pit/

#IgorsTipOfTheWeek #IDAtips #IDAPro
๐Ÿ—ฃHexRaysSA


๐ŸŽ–@malwr
Weekend Reading (or viewing) - a pretty clever set of C2 mechanisms, steganography and backdoors targeting Japan from @TeamT5_Official

might be a new favorite cluster Thinking face

check it out!

https://jsac.jpcert.or.jp/archive/2022/pdf/JSAC2022_7_leon-niwa-ishimaru_en.pdf
๐Ÿ—ฃgreglesnewich


๐ŸŽ–@malwr
๐Ÿ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
I wrote a C++ library to parse Windows minidumps (.dump /mx) for another project; go check it out ๐Ÿ™๐Ÿฝ!
https://github.com/0vercl0k/udmp-parser/
๐Ÿ—ฃ0vercl0k


๐ŸŽ–@malwr
As a YuGiOh fan I couldn't resist reverse engineering the new "Master Duel" game :)

I used Cpp2Il to generate the C# DLL and used the symbols to import the functions into GameAssembly.dll.

If you want to tag along, here's my current 1.0.1 script: https://github.com/ioncodes/master-duel
๐Ÿ—ฃlayle_ctf


๐ŸŽ–@malwr
Curious how to dump the WhisperGate wiper? This blog provides a step-by-step analysis, and shows how to load the third stage, since the original URL does not contain the payload anymore.

Link: https://maxkersten.nl/binary-analysis-course/malware-analysis/dumping-whispergates-wiper-from-an-eazfuscator-obfuscated-loader/

โ„น๏ธ Sent from one of our channel members


๐ŸŽ–@malwr
Releasing My first repo in months, using thread description to hide the shellcode, xor encryption, thread stack spoofing, and more ...
#bypassav #cobaltstrike #imbacm
https://github.com/ORCA666/T.D.P
๐Ÿ—ฃORCA6665


๐ŸŽ–@malwr