Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.07K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Here is my post about orphan file name entries found on exFAT volumes written using Linux or macOS. This means that file names (or their parts) of deleted files having their directory entries partially overwritten can be recovered. #DFIR
https://dfir.ru/2022/02/11/exfat-orphan-file-name-entries/
πŸ—£errno_fail


πŸŽ–@malwr
Exploring Windows UAC Bypasses : Techniques and Detection Strategies :
https://elastic.github.io/security-research/whitepapers/2022/02/03.exploring-windows-uac-bypass-techniques-detection-strategies/article/
πŸ—£binitamshah


πŸŽ–@malwr
RE tip of the day: There are many PDF entries that can be misused by malware. For example, /Action with a /Launch argument can be used to execute an application specified with a /F entry. Arguments can be added using /P entry.
#infosec #cybersecurity #malware #reverseengineering
πŸ—£re_and_more


πŸŽ–@malwr
The MISP cheat sheet has been updated with a representation overview showing how MISP is used to model a security incident. It's a usually a nifty overview when you don't have the time to read all of the documentation. #CTI #ThreatIntelligence

https://www.misp-project.org/misp-training/cheatsheet.pdf
πŸ—£MISPProject


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
WATCH: Discover the social engineering tactics employed by #APT36 or #EarthKarkaddan actors in our latest video.

Read our full report here:
https://research.trendmicro.com/EarthKarkaddan
πŸ—£TrendMicroRSRCH


πŸŽ–@malwr
New #PEsieve/#HollowsHunter (v0.3.4): https://github.com/hasherezade/pe-sieve/releases/ & https://github.com/hasherezade/hollows_hunter/releases - with threads' callstack scan. Check it out!
πŸ—£hasherezade


πŸŽ–@malwr
CinaRAT Delivered Through HTML ID Attributes https://i5c.us/d28330
πŸ—£sans_isc


πŸŽ–@malwr
BinDiff export is finally on its way : I hope to be able to publish an update in a week or two…
πŸ—£bSr43


πŸŽ–@malwr
The Microsoft Cybersecurity Reference Architecture.
πŸ—£FrankMcG


πŸŽ–@malwr
RE tip of the day: UPX structures are publically available, for example, https://buff.ly/3uAYU3L The most common ways how IoT malware authors modify them in samples is changing l_magic (UPX! signature) and p_filesize and p_blocksize fields
#infosec #malware #reverseengineering
πŸ—£re_and_more


πŸŽ–@malwr
❀1
Abusing LNK "Features" for Initial Access and Persistence

#infosec #redteam #pentest
https://v3ded.github.io/redteam/abusing-lnk-features-for-initial-access-and-persistence
πŸ—£CyberWarship


πŸŽ–@malwr