Malware News
15.6K subscribers
1.64K photos
7 videos
130 files
8.06K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Day 29 #100DaysofYARA using maths; counting the number of resources in a PE that have MZ headers!

I can only count to 5 on one hand so thats why the counter went this high

https://github.com/g-les/100DaysofYARA/blob/main/100_days_of_yara.yar
πŸ—£greglesnewich


πŸŽ–@malwr
I published a set of Python scripts that I use to integrate @dfir_iris , @MISPProject and @TimesketchProj #DFIR #CSIRT https://github.com/cudeso/dfir-iris-misp-timesketch
πŸ—£cudeso


πŸŽ–@malwr
#MalwareAnalysis: Detecting Process Hollowing
The first pattern to look for are any calls to create processes in a suspended state:

> CreateProcessA
"dwCreationFlags" set 0x04 CREATE_SUSPENDED

Purpose is to disguise malicious code in a legit exe by replacing the contents.

Following the process being started in a suspended state... (usually svchost.exe but who's counting). Then there are API calls to native/non native APIs:

> ZwUnmapviewofsection
> virtualallocex
> writeprocessmemory
> setthreadcontext
> NTgetcontextthread
> ntreadvirtualmemory

Other ones:
> NTResumethread
> NTwritevirtualmemory
> ntsetcontextthread

The logic is to look for signs of processes being started in suspended state - then the process being hollowed, replaced with "malicious" contents and resuming of execution.

πŸ—£inversecos


πŸŽ–@malwr
Have you noticed that IDA sometimes renames and marks up local variables automatically? Read up on how Parameter identification and tracking aka PIT works:

https://hex-rays.com/blog/igors-tip-of-the-week-74-parameter-identification-and-tracking-pit/

#IgorsTipOfTheWeek #IDAtips #IDAPro
πŸ—£HexRaysSA


πŸŽ–@malwr
Weekend Reading (or viewing) - a pretty clever set of C2 mechanisms, steganography and backdoors targeting Japan from @TeamT5_Official

might be a new favorite cluster Thinking face

check it out!

https://jsac.jpcert.or.jp/archive/2022/pdf/JSAC2022_7_leon-niwa-ishimaru_en.pdf
πŸ—£greglesnewich


πŸŽ–@malwr
πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
I wrote a C++ library to parse Windows minidumps (.dump /mx) for another project; go check it out πŸ™πŸ½!
https://github.com/0vercl0k/udmp-parser/
πŸ—£0vercl0k


πŸŽ–@malwr
As a YuGiOh fan I couldn't resist reverse engineering the new "Master Duel" game :)

I used Cpp2Il to generate the C# DLL and used the symbols to import the functions into GameAssembly.dll.

If you want to tag along, here's my current 1.0.1 script: https://github.com/ioncodes/master-duel
πŸ—£layle_ctf


πŸŽ–@malwr
Curious how to dump the WhisperGate wiper? This blog provides a step-by-step analysis, and shows how to load the third stage, since the original URL does not contain the payload anymore.

Link: https://maxkersten.nl/binary-analysis-course/malware-analysis/dumping-whispergates-wiper-from-an-eazfuscator-obfuscated-loader/

ℹ️ Sent from one of our channel members


πŸŽ–@malwr
Releasing My first repo in months, using thread description to hide the shellcode, xor encryption, thread stack spoofing, and more ...
#bypassav #cobaltstrike #imbacm
https://github.com/ORCA666/T.D.P
πŸ—£ORCA6665


πŸŽ–@malwr
Mandiant's FLARE team is hiring malware reverse engineers!

https://jobs.smartrecruiters.com/Mandiant/743999802041669
πŸ—£mrdurakovich


πŸŽ–@malwr
EvilSelenium - This project weaponizes Selenium to attack Chrome. Dump saved credentials, cookies, take (authenticated) screenshots, dump emails from gmail/o365 or chats from Whatsapp and exfiltrate & download files. ENJOY.
https://github.com/mrd0x/EvilSelenium
πŸ—£mrd0x


πŸŽ–@malwr
I did a bit of research and learning and have blogged about it an released some code. I wanted to understand Nirvana Hooks, specifically in x86. So I did a thing:
https://blog.xenoscr.net/2022/01/17/x86-Nirvana-Hooks.html
πŸ—£xenosCR


πŸŽ–@malwr
MBR Wipers starting to be very popular after the Ukrainian thing. Another one based on WobbyChip code. Some tips in screenshots.
Sample + My IDB + BOCHS Image ready for you, very good sample for education:🀠
https://github.com/Dump-GUY/Malware_TEMP/blob/main/MBRWiper_%20a0195c08fbfe459520423bf0a7c20504.7z
https://www.virustotal.com/gui/file/95a2cfb0da507b544ae915d6fd2a8d4fd8acb2456310e11d1bc066b531449ea9/detection
πŸ—£vinopaljiri


πŸŽ–@malwr