Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.07K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
The Microsoft Cybersecurity Reference Architecture.
πŸ—£FrankMcG


πŸŽ–@malwr
RE tip of the day: UPX structures are publically available, for example, https://buff.ly/3uAYU3L The most common ways how IoT malware authors modify them in samples is changing l_magic (UPX! signature) and p_filesize and p_blocksize fields
#infosec #malware #reverseengineering
πŸ—£re_and_more


πŸŽ–@malwr
❀1
Abusing LNK "Features" for Initial Access and Persistence

#infosec #redteam #pentest
https://v3ded.github.io/redteam/abusing-lnk-features-for-initial-access-and-persistence
πŸ—£CyberWarship


πŸŽ–@malwr
CinaRAT via HTML IDs; Protecting LSASS; Blocking Facebook Credential Exposure
https://i5c.us/p7878
πŸ—£sans_isc


πŸŽ–@malwr
So the first part of the blog post on OneDrive Logs (ODL) is finally posted, and so is the python script to parse it! πŸ‘‡
and
https://www.swiftforensics.com/2022/02/reading-onedrive-logs.html
πŸ—£SwiftForensics


πŸŽ–@malwr
πŸ‘1
Hot girls study malware analysis on Valentine's day. Believe me πŸ™πŸ˜‰


πŸŽ–@malwr
πŸŽ‰5😁2🀯1
frida typescript trick : if you want to hook functions with reserverd names such as toString(), encode the string and get function with [""]

Instead of jsonObj.toString.implementation
use jsonObj[b64decode("dG9TdHJpbmc=")]
:D
πŸ—£0xabc0


πŸŽ–@malwr
My write up for CVE-2021-43893, a vulnerability that allowed a remote attacker to upload files to a Domain Controller, just got posted 😍
https://www.rapid7.com/blog/post/2022/02/14/dropping-files-on-a-domain-controller-using-cve-2021-43893/
πŸ—£Junior_Baines


πŸŽ–@malwr
dronesploit : Drone pentesting framework console : https://github.com/dhondta/dronesploit credits @alex_dhondt
πŸ—£binitamshah


πŸŽ–@malwr