Releasing My first repo in months, using thread description to hide the shellcode, xor encryption, thread stack spoofing, and more ...
#bypassav #cobaltstrike #imbacm
https://github.com/ORCA666/T.D.P
π£ORCA6665
π@malwr
#bypassav #cobaltstrike #imbacm
https://github.com/ORCA666/T.D.P
π£ORCA6665
π@malwr
released another poc on KernelCallbackTable hijacking to run your shellcode, inspired by this paper here: https://blog.malwarebytes.com/threat-intelligence/2022/01/north-koreas-lazarus-apt-leverages-windows-update-client-github-in-latest-campaign/
the repo can be found here:
https://github.com/ORCA666/KCTHIJACK
#bypassav #shellcode #poc
π£ORCA6665
π@malwr
the repo can be found here:
https://github.com/ORCA666/KCTHIJACK
#bypassav #shellcode #poc
π£ORCA6665
π@malwr
ThreatDown by Malwarebytes
North Koreaβs Lazarus APT leverages Windows Update client, GitHub in latest campaign
How one of North Koreaβs most sophisticated APTs tries to avoid detection by using legitiate tools during its attacks.
Mandiant's FLARE team is hiring malware reverse engineers!
https://jobs.smartrecruiters.com/Mandiant/743999802041669
π£mrdurakovich
π@malwr
https://jobs.smartrecruiters.com/Mandiant/743999802041669
π£mrdurakovich
π@malwr
EvilSelenium - This project weaponizes Selenium to attack Chrome. Dump saved credentials, cookies, take (authenticated) screenshots, dump emails from gmail/o365 or chats from Whatsapp and exfiltrate & download files. ENJOY.
https://github.com/mrd0x/EvilSelenium
π£mrd0x
π@malwr
https://github.com/mrd0x/EvilSelenium
π£mrd0x
π@malwr
GitHub
GitHub - mrd0x/EvilSelenium: EvilSelenium is a tool that weaponizes Selenium to attack Chromium based browsers.
EvilSelenium is a tool that weaponizes Selenium to attack Chromium based browsers. - mrd0x/EvilSelenium
I did a bit of research and learning and have blogged about it an released some code. I wanted to understand Nirvana Hooks, specifically in x86. So I did a thing:
https://blog.xenoscr.net/2022/01/17/x86-Nirvana-Hooks.html
π£xenosCR
π@malwr
https://blog.xenoscr.net/2022/01/17/x86-Nirvana-Hooks.html
π£xenosCR
π@malwr
MBR Wipers starting to be very popular after the Ukrainian thing. Another one based on WobbyChip code. Some tips in screenshots.
Sample + My IDB + BOCHS Image ready for you, very good sample for education:π€
https://github.com/Dump-GUY/Malware_TEMP/blob/main/MBRWiper_%20a0195c08fbfe459520423bf0a7c20504.7z
https://www.virustotal.com/gui/file/95a2cfb0da507b544ae915d6fd2a8d4fd8acb2456310e11d1bc066b531449ea9/detection
π£vinopaljiri
π@malwr
Sample + My IDB + BOCHS Image ready for you, very good sample for education:π€
https://github.com/Dump-GUY/Malware_TEMP/blob/main/MBRWiper_%20a0195c08fbfe459520423bf0a7c20504.7z
https://www.virustotal.com/gui/file/95a2cfb0da507b544ae915d6fd2a8d4fd8acb2456310e11d1bc066b531449ea9/detection
π£vinopaljiri
π@malwr
TIL.. want all images from a docx? Rename it .zip and extract the media folder.
π£Jean_Maes_1994
π@malwr
π£Jean_Maes_1994
π@malwr
Detect It Easy, or abbreviated "DIE" is a program for determining types of files.
3.04
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix #macos #detectiteasy #android #cybersecurity
https://github.com/horsicq/Detect-It-Easy
π£horsicq
π@malwr
3.04
#hacker #infosec #malware #hacking #programming #reversing #opensource #linux #linuxsecurity #unix #macos #detectiteasy #android #cybersecurity
https://github.com/horsicq/Detect-It-Easy
π£horsicq
π@malwr
GitHub
GitHub - horsicq/Detect-It-Easy: Program for determining types of files for Windows, Linux and MacOS.
Program for determining types of files for Windows, Linux and MacOS. - horsicq/Detect-It-Easy
π1
The second article of MAS (Malware Analysis Series) is available for reading! The PDF version (96 pages) can be downloaded from:
https://exploitreversing.com/2022/02/03/malware-analysis-series-mas-article-2/
Have an excellent day.
#malware #malwareanalysis #reverseengineering #programming #threathunting
π£ale_sp_brazil
π@malwr
https://exploitreversing.com/2022/02/03/malware-analysis-series-mas-article-2/
Have an excellent day.
#malware #malwareanalysis #reverseengineering #programming #threathunting
π£ale_sp_brazil
π@malwr
π1
Published a new Repo Today, first one on gitlab ;) combining more than more tech to bypass av products:
u can check it here:
#bypassav #shellcode #payload
https://gitlab.com/ORCA666/3in1
π£ORCA6665
π@malwr
u can check it here:
#bypassav #shellcode #payload
https://gitlab.com/ORCA666/3in1
π£ORCA6665
π@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
Is it possible to start a process as SYSTEM using only CreateFile and WriteFile? Yes
Spoiler: Write a custom RPC client and create a temporary service using \\.\pipe\ntsvcs π
https://www.x86matthew.com/view_post?id=create_svc_rpc
π£x86matthew
π@malwr
Spoiler: Write a custom RPC client and create a temporary service using \\.\pipe\ntsvcs π
https://www.x86matthew.com/view_post?id=create_svc_rpc
π£x86matthew
π@malwr
Great report by threatintel
- The TA leveraged PowerShell, WMIC, ProcDump, LSASS, PsExec, AnyDesk, Winrar, and there is even evidence of it leveraging EternalBlue exploits in the backdoor.
- The campaign lasted around 18 months
*Yara rules included
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/china-apt-antlion-taiwan-financial-attacks
π£nas_bench
π@malwr
- The TA leveraged PowerShell, WMIC, ProcDump, LSASS, PsExec, AnyDesk, Winrar, and there is even evidence of it leveraging EternalBlue exploits in the backdoor.
- The campaign lasted around 18 months
*Yara rules included
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/china-apt-antlion-taiwan-financial-attacks
π£nas_bench
π@malwr
Security
Antlion: Chinese APT Uses Custom Backdoor to Target Financial Institutions in Taiwan
The attackers spent a significant amount of time on victim networks.
This media is not supported in your browser
VIEW IN TELEGRAM
EmbedExeLnk - Embedding an EXE inside a LNK with automatic execution
https://www.x86matthew.com/view_post?id=embed_exe_lnk
π£x86matthew
π@malwr
https://www.x86matthew.com/view_post?id=embed_exe_lnk
π£x86matthew
π@malwr
We recently discovered an APT group leveraging a 0-day in Zimbra to try and steal e-mails from targeted user. We just shared details on the @Volexity blog. This is an interesting case where an XSS vulnerability is being used to facilitate cyber espionage.
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
π£stevenadair
π@malwr
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
π£stevenadair
π@malwr
Volexity
Operation EmailThief: Active Exploitation of Zero-day XSS Vulnerability in Zimbra
[UPDATE] On February 4, 2022, Zimbra provided an update regarding this zero-day exploit vulnerability and reported that a hotfix for 8.8.15 P30 would be available on February 5, 2022. This vulnerability [β¦]
Reversing Go Tip 0x0001. Here is an Assembler view of a simple, "Hello, world!" and "Hello, world again!" bin. Notice with modern Go the values about to be passed into Fprintln are in r8 on x64.
π£mytechnotalent
π@malwr
π£mytechnotalent
π@malwr
My latest msdt uac bypass has been added to UACME. Thx @hFireF0X!
https://github.com/hfiref0x/UACME
π£EmericNasi
π@malwr
https://github.com/hfiref0x/UACME
π£EmericNasi
π@malwr
GitHub
GitHub - hfiref0x/UACME: Defeating Windows User Account Control
Defeating Windows User Account Control. Contribute to hfiref0x/UACME development by creating an account on GitHub.