Malware News
15.6K subscribers
1.64K photos
7 videos
130 files
8.06K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Mandiant's FLARE team is hiring malware reverse engineers!

https://jobs.smartrecruiters.com/Mandiant/743999802041669
πŸ—£mrdurakovich


πŸŽ–@malwr
EvilSelenium - This project weaponizes Selenium to attack Chrome. Dump saved credentials, cookies, take (authenticated) screenshots, dump emails from gmail/o365 or chats from Whatsapp and exfiltrate & download files. ENJOY.
https://github.com/mrd0x/EvilSelenium
πŸ—£mrd0x


πŸŽ–@malwr
I did a bit of research and learning and have blogged about it an released some code. I wanted to understand Nirvana Hooks, specifically in x86. So I did a thing:
https://blog.xenoscr.net/2022/01/17/x86-Nirvana-Hooks.html
πŸ—£xenosCR


πŸŽ–@malwr
MBR Wipers starting to be very popular after the Ukrainian thing. Another one based on WobbyChip code. Some tips in screenshots.
Sample + My IDB + BOCHS Image ready for you, very good sample for education:🀠
https://github.com/Dump-GUY/Malware_TEMP/blob/main/MBRWiper_%20a0195c08fbfe459520423bf0a7c20504.7z
https://www.virustotal.com/gui/file/95a2cfb0da507b544ae915d6fd2a8d4fd8acb2456310e11d1bc066b531449ea9/detection
πŸ—£vinopaljiri


πŸŽ–@malwr
TIL.. want all images from a docx? Rename it .zip and extract the media folder.
πŸ—£Jean_Maes_1994


πŸŽ–@malwr
The second article of MAS (Malware Analysis Series) is available for reading! The PDF version (96 pages) can be downloaded from:

https://exploitreversing.com/2022/02/03/malware-analysis-series-mas-article-2/

Have an excellent day.

#malware #malwareanalysis #reverseengineering #programming #threathunting
πŸ—£ale_sp_brazil


πŸŽ–@malwr
πŸ‘1
Published a new Repo Today, first one on gitlab ;) combining more than more tech to bypass av products:
u can check it here:
#bypassav #shellcode #payload
https://gitlab.com/ORCA666/3in1
πŸ—£ORCA6665


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
Is it possible to start a process as SYSTEM using only CreateFile and WriteFile? Yes

Spoiler: Write a custom RPC client and create a temporary service using \\.\pipe\ntsvcs πŸ™‚

https://www.x86matthew.com/view_post?id=create_svc_rpc
πŸ—£x86matthew


πŸŽ–@malwr
Great report by threatintel

- The TA leveraged PowerShell, WMIC, ProcDump, LSASS, PsExec, AnyDesk, Winrar, and there is even evidence of it leveraging EternalBlue exploits in the backdoor.
- The campaign lasted around 18 months

*Yara rules included
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/china-apt-antlion-taiwan-financial-attacks
πŸ—£nas_bench


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
EmbedExeLnk - Embedding an EXE inside a LNK with automatic execution

https://www.x86matthew.com/view_post?id=embed_exe_lnk
πŸ—£x86matthew


πŸŽ–@malwr
The ultimate backdoor doesn't exi-
πŸ—£DuchyRE


πŸŽ–@malwr
a tiny DNS resolver
full program: https://github.com/jvns/tiny-resolver
πŸ—£b0rk


πŸŽ–@malwr
Reversing Go Tip 0x0001. Here is an Assembler view of a simple, "Hello, world!" and "Hello, world again!" bin. Notice with modern Go the values about to be passed into Fprintln are in r8 on x64.
πŸ—£mytechnotalent


πŸŽ–@malwr
For quite some time I wanted a command-line tool to calculate the entropy of files that was fast and supported Windows. I ended up coding my own.πŸ™‚ It could be useful for people in #malwareanalysis, #forensics, etc.
https://github.com/merces/entropy
πŸ—£mer0x36


πŸŽ–@malwr