This media is not supported in your browser
VIEW IN TELEGRAM
Is it possible to start a process as SYSTEM using only CreateFile and WriteFile? Yes
Spoiler: Write a custom RPC client and create a temporary service using \\.\pipe\ntsvcs π
https://www.x86matthew.com/view_post?id=create_svc_rpc
π£x86matthew
π@malwr
Spoiler: Write a custom RPC client and create a temporary service using \\.\pipe\ntsvcs π
https://www.x86matthew.com/view_post?id=create_svc_rpc
π£x86matthew
π@malwr
Great report by threatintel
- The TA leveraged PowerShell, WMIC, ProcDump, LSASS, PsExec, AnyDesk, Winrar, and there is even evidence of it leveraging EternalBlue exploits in the backdoor.
- The campaign lasted around 18 months
*Yara rules included
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/china-apt-antlion-taiwan-financial-attacks
π£nas_bench
π@malwr
- The TA leveraged PowerShell, WMIC, ProcDump, LSASS, PsExec, AnyDesk, Winrar, and there is even evidence of it leveraging EternalBlue exploits in the backdoor.
- The campaign lasted around 18 months
*Yara rules included
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/china-apt-antlion-taiwan-financial-attacks
π£nas_bench
π@malwr
Security
Antlion: Chinese APT Uses Custom Backdoor to Target Financial Institutions in Taiwan
The attackers spent a significant amount of time on victim networks.
This media is not supported in your browser
VIEW IN TELEGRAM
EmbedExeLnk - Embedding an EXE inside a LNK with automatic execution
https://www.x86matthew.com/view_post?id=embed_exe_lnk
π£x86matthew
π@malwr
https://www.x86matthew.com/view_post?id=embed_exe_lnk
π£x86matthew
π@malwr
We recently discovered an APT group leveraging a 0-day in Zimbra to try and steal e-mails from targeted user. We just shared details on the @Volexity blog. This is an interesting case where an XSS vulnerability is being used to facilitate cyber espionage.
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
π£stevenadair
π@malwr
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
π£stevenadair
π@malwr
Volexity
Operation EmailThief: Active Exploitation of Zero-day XSS Vulnerability in Zimbra
[UPDATE] On February 4, 2022, Zimbra provided an update regarding this zero-day exploit vulnerability and reported that a hotfix for 8.8.15 P30 would be available on February 5, 2022. This vulnerability [β¦]
Reversing Go Tip 0x0001. Here is an Assembler view of a simple, "Hello, world!" and "Hello, world again!" bin. Notice with modern Go the values about to be passed into Fprintln are in r8 on x64.
π£mytechnotalent
π@malwr
π£mytechnotalent
π@malwr
My latest msdt uac bypass has been added to UACME. Thx @hFireF0X!
https://github.com/hfiref0x/UACME
π£EmericNasi
π@malwr
https://github.com/hfiref0x/UACME
π£EmericNasi
π@malwr
GitHub
GitHub - hfiref0x/UACME: Defeating Windows User Account Control
Defeating Windows User Account Control. Contribute to hfiref0x/UACME development by creating an account on GitHub.
For quite some time I wanted a command-line tool to calculate the entropy of files that was fast and supported Windows. I ended up coding my own.π It could be useful for people in #malwareanalysis, #forensics, etc.
https://github.com/merces/entropy
π£mer0x36
π@malwr
https://github.com/merces/entropy
π£mer0x36
π@malwr
GitHub
GitHub - merces/entropy: CLI program to calculate the entropy of files
CLI program to calculate the entropy of files. Contribute to merces/entropy development by creating an account on GitHub.
Hours of troubleshooting and some more evenings went into a Nim port of reflective PE loading. Learned a lot porting that one, special thanks to @am0nsec and @_EthicalChaos_ for answering all my questions regarding to issues! π€
https://github.com/S3cur3Th1sSh1t/Nim-RunPE
π£ShitSecure
π@malwr
https://github.com/S3cur3Th1sSh1t/Nim-RunPE
π£ShitSecure
π@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
HijackFileHandle - Hijack a file in a remote process without code injection
A covert method of intercepting data from remote file streams (log files, etc)
https://www.x86matthew.com/view_post?id=hijack_file_handle
π£x86matthew
π@malwr
A covert method of intercepting data from remote file streams (log files, etc)
https://www.x86matthew.com/view_post?id=hijack_file_handle
π£x86matthew
π@malwr
π1
Indicators of Compromise Associated with LockBit 2.0
Ransomware π΅οΈπΎπ₯οΈπ
https://www.ic3.gov/Media/News/2022/220204.pdf
π£CryptoInsane
π@malwr
Ransomware π΅οΈπΎπ₯οΈπ
https://www.ic3.gov/Media/News/2022/220204.pdf
π£CryptoInsane
π@malwr
If anyone wants practice with packet analysis, hereβs a lab I give to my Security class each semester. Includes a real PCAP from @defcon #PcapsOrItDidntHappen
https://github.com/tuftsdev/DefenseAgainstTheDarkArts/blob/gh-pages/labs/lab02-pcaps.md
π£0xmchow
π@malwr
https://github.com/tuftsdev/DefenseAgainstTheDarkArts/blob/gh-pages/labs/lab02-pcaps.md
π£0xmchow
π@malwr
GitHub
DefenseAgainstTheDarkArts/labs/lab02-pcaps.md at gh-pages Β· tuftsdev/DefenseAgainstTheDarkArts
Contribute to tuftsdev/DefenseAgainstTheDarkArts development by creating an account on GitHub.
I've updated the Antivirus Event Analysis Cheat Sheet to v1.9.0
- updates in all sections
- MS Exchange exploitation related indicators
- updated identifiers
Could @SophosLabs please fix the spelling of Webshel+l?
https://www.nextron-systems.com/2022/02/06/antivirus-event-analysis-cheat-sheet-v1-9-0/
π£cyb3rops
π@malwr
- updates in all sections
- MS Exchange exploitation related indicators
- updated identifiers
Could @SophosLabs please fix the spelling of Webshel+l?
https://www.nextron-systems.com/2022/02/06/antivirus-event-analysis-cheat-sheet-v1-9-0/
π£cyb3rops
π@malwr
Decoding Cobalt Strike: Understanding Payloads
https://decoded.avast.io/threatintel/decoding-cobalt-strike-understanding-payloads/
π£pentest_swissky
π@malwr
https://decoded.avast.io/threatintel/decoding-cobalt-strike-understanding-payloads/
π£pentest_swissky
π@malwr
Gendigital
Decoding Cobalt Strike: Understanding payloads
Identifying and Parsing Cobalt Payloads
IDACode - An Integration For IDA And VS Code Which Connects Both To Easily Execute And Debug IDAPython Scripts https://ift.tt/9jM4DvH #cybersecurity #bugbountytips #hacking #tools
π£santosomar
π@malwr
π£santosomar
π@malwr
π₯4
The Walmart Global Tech security team write about the Sugar ransomware operation, which appears to actively target individual computers rather than entire enterprises. https://medium.com/walmartglobaltech/sugar-ransomware-a-new-raas-a5d94d58d9fb
π£virusbtn
π@malwr
π£virusbtn
π@malwr
Cuckoo and CAPE sandbox evasion in one legitimate Windows API function call? It is possible due to issues we found in Cuckoo and CAPE monitor.
@CapeSandbox @cuckoosandbox
https://research.checkpoint.com/2022/invisible-cuckoo-cape-sandbox-evasion
π£_CPResearch_
π@malwr
@CapeSandbox @cuckoosandbox
https://research.checkpoint.com/2022/invisible-cuckoo-cape-sandbox-evasion
π£_CPResearch_
π@malwr
Check Point Research
Invisible Sandbox Evasion - Check Point Research
Cuckoo and CAPE sandbox evasion in one legitimate Windows API function call? It is possible due to issues we found in Cuckoo and CAPE monitor.