Malware News
15.6K subscribers
1.64K photos
7 videos
130 files
8.06K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
Is it possible to start a process as SYSTEM using only CreateFile and WriteFile? Yes

Spoiler: Write a custom RPC client and create a temporary service using \\.\pipe\ntsvcs πŸ™‚

https://www.x86matthew.com/view_post?id=create_svc_rpc
πŸ—£x86matthew


πŸŽ–@malwr
Great report by threatintel

- The TA leveraged PowerShell, WMIC, ProcDump, LSASS, PsExec, AnyDesk, Winrar, and there is even evidence of it leveraging EternalBlue exploits in the backdoor.
- The campaign lasted around 18 months

*Yara rules included
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/china-apt-antlion-taiwan-financial-attacks
πŸ—£nas_bench


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
EmbedExeLnk - Embedding an EXE inside a LNK with automatic execution

https://www.x86matthew.com/view_post?id=embed_exe_lnk
πŸ—£x86matthew


πŸŽ–@malwr
The ultimate backdoor doesn't exi-
πŸ—£DuchyRE


πŸŽ–@malwr
a tiny DNS resolver
full program: https://github.com/jvns/tiny-resolver
πŸ—£b0rk


πŸŽ–@malwr
Reversing Go Tip 0x0001. Here is an Assembler view of a simple, "Hello, world!" and "Hello, world again!" bin. Notice with modern Go the values about to be passed into Fprintln are in r8 on x64.
πŸ—£mytechnotalent


πŸŽ–@malwr
For quite some time I wanted a command-line tool to calculate the entropy of files that was fast and supported Windows. I ended up coding my own.πŸ™‚ It could be useful for people in #malwareanalysis, #forensics, etc.
https://github.com/merces/entropy
πŸ—£mer0x36


πŸŽ–@malwr
Hours of troubleshooting and some more evenings went into a Nim port of reflective PE loading. Learned a lot porting that one, special thanks to @am0nsec and @_EthicalChaos_ for answering all my questions regarding to issues! πŸ€“

https://github.com/S3cur3Th1sSh1t/Nim-RunPE
πŸ—£ShitSecure


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
HijackFileHandle - Hijack a file in a remote process without code injection

A covert method of intercepting data from remote file streams (log files, etc)

https://www.x86matthew.com/view_post?id=hijack_file_handle
πŸ—£x86matthew


πŸŽ–@malwr
πŸ‘1
Indicators of Compromise Associated with LockBit 2.0
Ransomware πŸ•΅οΈπŸ‘ΎπŸ–₯οΈπŸ”

https://www.ic3.gov/Media/News/2022/220204.pdf
πŸ—£CryptoInsane


πŸŽ–@malwr
I've updated the Antivirus Event Analysis Cheat Sheet to v1.9.0

- updates in all sections
- MS Exchange exploitation related indicators
- updated identifiers

Could @SophosLabs please fix the spelling of Webshel+l?

https://www.nextron-systems.com/2022/02/06/antivirus-event-analysis-cheat-sheet-v1-9-0/
πŸ—£cyb3rops


πŸŽ–@malwr
IDACode - An Integration For IDA And VS Code Which Connects Both To Easily Execute And Debug IDAPython Scripts https://ift.tt/9jM4DvH #cybersecurity #bugbountytips #hacking #tools
πŸ—£santosomar


πŸŽ–@malwr
πŸ”₯4
The Walmart Global Tech security team write about the Sugar ransomware operation, which appears to actively target individual computers rather than entire enterprises. https://medium.com/walmartglobaltech/sugar-ransomware-a-new-raas-a5d94d58d9fb
πŸ—£virusbtn


πŸŽ–@malwr