Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.06K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
I've updated the Antivirus Event Analysis Cheat Sheet to v1.9.0

- updates in all sections
- MS Exchange exploitation related indicators
- updated identifiers

Could @SophosLabs please fix the spelling of Webshel+l?

https://www.nextron-systems.com/2022/02/06/antivirus-event-analysis-cheat-sheet-v1-9-0/
πŸ—£cyb3rops


πŸŽ–@malwr
IDACode - An Integration For IDA And VS Code Which Connects Both To Easily Execute And Debug IDAPython Scripts https://ift.tt/9jM4DvH #cybersecurity #bugbountytips #hacking #tools
πŸ—£santosomar


πŸŽ–@malwr
πŸ”₯4
The Walmart Global Tech security team write about the Sugar ransomware operation, which appears to actively target individual computers rather than entire enterprises. https://medium.com/walmartglobaltech/sugar-ransomware-a-new-raas-a5d94d58d9fb
πŸ—£virusbtn


πŸŽ–@malwr
Me watching somebody try to decrease Emotet AV detection by uploading stuff to VirusTotal πŸ˜…
πŸ—£GossiTheDog


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
Just released a new, fast-paced, interactive binary patching plugin for IDA Pro. Check out a small blurb about it on the @HexRaysSA blog: https://hex-rays.com/blog/introducing-the-patching-plugin/

Code: https://github.com/gaasedelen/patching
πŸ—£ret2systems


πŸŽ–@malwr
Microsoft blocks VBA macros originating from Internet based on MOTW flag.

I'm now sharing a tool presenting risk for MOTW bypasses, which will play crucial role in evading MS default setting and smuggle macros back in.

Threat Actors already do that.

https://github.com/mgeeky/PackMyPayload
πŸ—£mariuszbit


πŸŽ–@malwr
πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
How can we run arbitrary code without allocating/overwriting executable memory? We "borrow" (abuse) instructions from ntdll.dll!

https://www.x86matthew.com/view_post?id=windows_no_exec
πŸ—£x86matthew


πŸŽ–@malwr
Good news for all the infosec community. Now you can Export/Import VT Collections into/from MISP Events πŸŽ‰ by
@thetravelr https://blog.virustotal.com/2022/02/misp-and-vt-collections.html
πŸ—£virustotal


πŸŽ–@malwr
Rewrote Simple Process Injection using HellsGate in C# for fun and learning :)
It involved parsing ntdll to find and map the syscall ids for the involved functions and use the syscall numbers to directly invoke the the corresponding syscall.
Github repo: https://github.com/sbasu7241/HellsGate
πŸ—£SoumyadeepBas12


πŸŽ–@malwr
Here is my post about orphan file name entries found on exFAT volumes written using Linux or macOS. This means that file names (or their parts) of deleted files having their directory entries partially overwritten can be recovered. #DFIR
https://dfir.ru/2022/02/11/exfat-orphan-file-name-entries/
πŸ—£errno_fail


πŸŽ–@malwr
Exploring Windows UAC Bypasses : Techniques and Detection Strategies :
https://elastic.github.io/security-research/whitepapers/2022/02/03.exploring-windows-uac-bypass-techniques-detection-strategies/article/
πŸ—£binitamshah


πŸŽ–@malwr