Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.07K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
We have a Valentine’s Day surprise for everyone - The first Kali Linux release of 2022 is posted and ready for download!

https://www.kali.org/blog/kali-linux-2022-1-release/

Included in this release is:

Visual Refresh
New Kali Everything Image
Legacy SSH support
Accessibility Features
& More!
πŸ—£kalilinux


πŸŽ–@malwr
πŸ‘1
Have Linux dev skills and want to work on Sysinternals tools for Linux?
https://careers.microsoft.com/us/en/job/1260200
πŸ—£markrussinovich


πŸŽ–@malwr
🎁 r2-5.6.2 is out! This is a security-focused release! πŸ‘€ Checkout the changes as it may be important ^^. All binary builds are available and distros will be eventually updating. https://github.com/radareorg/radare2/releases/tag/5.6.2
πŸ—£radareorg


πŸŽ–@malwr
Well, Sentinel1 is the first EDR I've seen doing this. The whole Export Address Table (EAT) is modified in memory for kernel32.dll and not just the WinAPI calls. So, if you are trying to parse kernel32 to find any export function, you will be forever stuck in a loop... lol! 🀣🀣
πŸ—£NinjaParanoid


πŸŽ–@malwr
Best python libraries for Cybersecurity
πŸ—£LetsDefendIO


πŸŽ–@malwr
Had some free time lately due to covid isolation, so I thought why not write something?
This is my new article about #BazarLoader. Similar to my previous articles, this writeup is a hybrid between a presentation and a step-by-step tutorial.
https://elis531989.medium.com/highway-to-conti-analysis-of-bazarloader-26368765689d
πŸ—£elisalem9


πŸŽ–@malwr
You can now install and run latest r2, rax2 and rasm2 in your browser or terminal thanks to webassembly! (no disk or network access, it's a sandbox! (use pc* and terminal paste to load binaries) https://wapm.io/package/pancake/r2#shell
πŸ—£radareorg


πŸŽ–@malwr
IDA Free has been upgraded to the latest IDA version 7.7SP1!
This light but powerful tool can quickly analyze the binary code samples and allow users to take a closer look at the results.
Try it out for free https://hex-rays.com/ida-free/

#IDAFreeware #Binaryanalysis #HexRays
πŸ—£HexRaysSA


πŸŽ–@malwr
πŸ”₯1
Woop Woop, good day for #CTI. @MISPProject released v2.4.153 with a lot of fixes and extra features. These new taxonomies are very interesting for state attribution ( and intrusion modeling ( See πŸ‘πŸ’―
https://www.misp-project.org/taxonomies.html#_state_responsibility
πŸ—£digihash


πŸŽ–@malwr
Fuzzing sockets: Apache HTTP, Part 3: Results
https://securitylab.github.com/research/fuzzing-apache-3/
πŸ—£kmkz_security


πŸŽ–@malwr
I wrote a Binary Ninja UI plugin for exploring Structured Exception Handlers in PEs today

https://github.com/EliseZeroTwo/SEH-Helper
πŸ—£EliseZeroTwo


πŸŽ–@malwr
RE tip of the day: Resolving imports in IDA and notice that for ntdll there are no API names? Save the resolved addresses with "Debugger->Take memory snapshot" and manually load ntdll.dll to the same base using pe_dlls.idc: https://buff.ly/34LlfAX
#infosec #cybersecurity #malware
πŸ—£re_and_more


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
Puzzled why a yara rule did or didn't match?

Let me introduce http://yaradbg.dev, a web-based #yara #debugger!

With #YaraDbg, you can see the:
1⃣ evaluation steps
2⃣ matched strings
3⃣ relationship among the rules
πŸ—£DissectMalware


πŸŽ–@malwr
πŸ‘1
Quick blog tonight on a #Monzo and #Revolut bank #phishing campaign targeting digital-only mobile users

https://blog.bushidotoken.net/2022/02/mobile-banking-phishing-campaign.html
πŸ—£BushidoToken


πŸŽ–@malwr
Blog: Detecting Karakurt – an extortion focused threat actor by NCC Group's Cyber Incident Response Team members - Simon Biggs, Richard Footman and Michael Mullen -
https://research.nccgroup.com/2022/02/17/detecting-karakurt-an-extortion-focused-threat-actor/ #Karakurt
πŸ—£NCCGroupInfosec


πŸŽ–@malwr
Added 2 PoCs for HackSys Extreme Vulnerable Driver to KernelWritePoCs.
One tries to get SYSTEM with SeCreateTokenPrivilege.
The other tries to get SYSTEM by secondary logon feature with SeCreateTokenPrivilege and SeImpersonatePrivilege.

https://github.com/daem0nc0re/PrivFu#KernelWritePoCs
πŸ—£daem0nc0re


πŸŽ–@malwr