Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.07K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Exploring Windows UAC Bypasses : Techniques and Detection Strategies :
https://elastic.github.io/security-research/whitepapers/2022/02/03.exploring-windows-uac-bypass-techniques-detection-strategies/article/
πŸ—£binitamshah


πŸŽ–@malwr
RE tip of the day: There are many PDF entries that can be misused by malware. For example, /Action with a /Launch argument can be used to execute an application specified with a /F entry. Arguments can be added using /P entry.
#infosec #cybersecurity #malware #reverseengineering
πŸ—£re_and_more


πŸŽ–@malwr
The MISP cheat sheet has been updated with a representation overview showing how MISP is used to model a security incident. It's a usually a nifty overview when you don't have the time to read all of the documentation. #CTI #ThreatIntelligence

https://www.misp-project.org/misp-training/cheatsheet.pdf
πŸ—£MISPProject


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
WATCH: Discover the social engineering tactics employed by #APT36 or #EarthKarkaddan actors in our latest video.

Read our full report here:
https://research.trendmicro.com/EarthKarkaddan
πŸ—£TrendMicroRSRCH


πŸŽ–@malwr
New #PEsieve/#HollowsHunter (v0.3.4): https://github.com/hasherezade/pe-sieve/releases/ & https://github.com/hasherezade/hollows_hunter/releases - with threads' callstack scan. Check it out!
πŸ—£hasherezade


πŸŽ–@malwr
CinaRAT Delivered Through HTML ID Attributes https://i5c.us/d28330
πŸ—£sans_isc


πŸŽ–@malwr
BinDiff export is finally on its way : I hope to be able to publish an update in a week or two…
πŸ—£bSr43


πŸŽ–@malwr
The Microsoft Cybersecurity Reference Architecture.
πŸ—£FrankMcG


πŸŽ–@malwr
RE tip of the day: UPX structures are publically available, for example, https://buff.ly/3uAYU3L The most common ways how IoT malware authors modify them in samples is changing l_magic (UPX! signature) and p_filesize and p_blocksize fields
#infosec #malware #reverseengineering
πŸ—£re_and_more


πŸŽ–@malwr
❀1
Abusing LNK "Features" for Initial Access and Persistence

#infosec #redteam #pentest
https://v3ded.github.io/redteam/abusing-lnk-features-for-initial-access-and-persistence
πŸ—£CyberWarship


πŸŽ–@malwr
CinaRAT via HTML IDs; Protecting LSASS; Blocking Facebook Credential Exposure
https://i5c.us/p7878
πŸ—£sans_isc


πŸŽ–@malwr