Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.06K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Indicators of Compromise Associated with LockBit 2.0
Ransomware πŸ•΅οΈπŸ‘ΎπŸ–₯οΈπŸ”

https://www.ic3.gov/Media/News/2022/220204.pdf
πŸ—£CryptoInsane


πŸŽ–@malwr
I've updated the Antivirus Event Analysis Cheat Sheet to v1.9.0

- updates in all sections
- MS Exchange exploitation related indicators
- updated identifiers

Could @SophosLabs please fix the spelling of Webshel+l?

https://www.nextron-systems.com/2022/02/06/antivirus-event-analysis-cheat-sheet-v1-9-0/
πŸ—£cyb3rops


πŸŽ–@malwr
IDACode - An Integration For IDA And VS Code Which Connects Both To Easily Execute And Debug IDAPython Scripts https://ift.tt/9jM4DvH #cybersecurity #bugbountytips #hacking #tools
πŸ—£santosomar


πŸŽ–@malwr
πŸ”₯4
The Walmart Global Tech security team write about the Sugar ransomware operation, which appears to actively target individual computers rather than entire enterprises. https://medium.com/walmartglobaltech/sugar-ransomware-a-new-raas-a5d94d58d9fb
πŸ—£virusbtn


πŸŽ–@malwr
Me watching somebody try to decrease Emotet AV detection by uploading stuff to VirusTotal πŸ˜…
πŸ—£GossiTheDog


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
Just released a new, fast-paced, interactive binary patching plugin for IDA Pro. Check out a small blurb about it on the @HexRaysSA blog: https://hex-rays.com/blog/introducing-the-patching-plugin/

Code: https://github.com/gaasedelen/patching
πŸ—£ret2systems


πŸŽ–@malwr
Microsoft blocks VBA macros originating from Internet based on MOTW flag.

I'm now sharing a tool presenting risk for MOTW bypasses, which will play crucial role in evading MS default setting and smuggle macros back in.

Threat Actors already do that.

https://github.com/mgeeky/PackMyPayload
πŸ—£mariuszbit


πŸŽ–@malwr
πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
How can we run arbitrary code without allocating/overwriting executable memory? We "borrow" (abuse) instructions from ntdll.dll!

https://www.x86matthew.com/view_post?id=windows_no_exec
πŸ—£x86matthew


πŸŽ–@malwr
Good news for all the infosec community. Now you can Export/Import VT Collections into/from MISP Events πŸŽ‰ by
@thetravelr https://blog.virustotal.com/2022/02/misp-and-vt-collections.html
πŸ—£virustotal


πŸŽ–@malwr