Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.08K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Had some free time lately due to covid isolation, so I thought why not write something?
This is my new article about #BazarLoader. Similar to my previous articles, this writeup is a hybrid between a presentation and a step-by-step tutorial.
https://elis531989.medium.com/highway-to-conti-analysis-of-bazarloader-26368765689d
πŸ—£elisalem9


πŸŽ–@malwr
You can now install and run latest r2, rax2 and rasm2 in your browser or terminal thanks to webassembly! (no disk or network access, it's a sandbox! (use pc* and terminal paste to load binaries) https://wapm.io/package/pancake/r2#shell
πŸ—£radareorg


πŸŽ–@malwr
IDA Free has been upgraded to the latest IDA version 7.7SP1!
This light but powerful tool can quickly analyze the binary code samples and allow users to take a closer look at the results.
Try it out for free https://hex-rays.com/ida-free/

#IDAFreeware #Binaryanalysis #HexRays
πŸ—£HexRaysSA


πŸŽ–@malwr
πŸ”₯1
Woop Woop, good day for #CTI. @MISPProject released v2.4.153 with a lot of fixes and extra features. These new taxonomies are very interesting for state attribution ( and intrusion modeling ( See πŸ‘πŸ’―
https://www.misp-project.org/taxonomies.html#_state_responsibility
πŸ—£digihash


πŸŽ–@malwr
Fuzzing sockets: Apache HTTP, Part 3: Results
https://securitylab.github.com/research/fuzzing-apache-3/
πŸ—£kmkz_security


πŸŽ–@malwr
I wrote a Binary Ninja UI plugin for exploring Structured Exception Handlers in PEs today

https://github.com/EliseZeroTwo/SEH-Helper
πŸ—£EliseZeroTwo


πŸŽ–@malwr
RE tip of the day: Resolving imports in IDA and notice that for ntdll there are no API names? Save the resolved addresses with "Debugger->Take memory snapshot" and manually load ntdll.dll to the same base using pe_dlls.idc: https://buff.ly/34LlfAX
#infosec #cybersecurity #malware
πŸ—£re_and_more


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
Puzzled why a yara rule did or didn't match?

Let me introduce http://yaradbg.dev, a web-based #yara #debugger!

With #YaraDbg, you can see the:
1⃣ evaluation steps
2⃣ matched strings
3⃣ relationship among the rules
πŸ—£DissectMalware


πŸŽ–@malwr
πŸ‘1
Quick blog tonight on a #Monzo and #Revolut bank #phishing campaign targeting digital-only mobile users

https://blog.bushidotoken.net/2022/02/mobile-banking-phishing-campaign.html
πŸ—£BushidoToken


πŸŽ–@malwr
Blog: Detecting Karakurt – an extortion focused threat actor by NCC Group's Cyber Incident Response Team members - Simon Biggs, Richard Footman and Michael Mullen -
https://research.nccgroup.com/2022/02/17/detecting-karakurt-an-extortion-focused-threat-actor/ #Karakurt
πŸ—£NCCGroupInfosec


πŸŽ–@malwr
Added 2 PoCs for HackSys Extreme Vulnerable Driver to KernelWritePoCs.
One tries to get SYSTEM with SeCreateTokenPrivilege.
The other tries to get SYSTEM by secondary logon feature with SeCreateTokenPrivilege and SeImpersonatePrivilege.

https://github.com/daem0nc0re/PrivFu#KernelWritePoCs
πŸ—£daem0nc0re


πŸŽ–@malwr
Faking a positive COVID Test : https://labs.f-secure.com/blog/faking-a-positive-covid-test credits @Yogehi
πŸ—£binitamshah


πŸŽ–@malwr
My #BinaryNinja plugin obfuscation_detection can now identify uncommon instruction sequences (such as MBAs or weird calculations) based on stochastic n-gram analysis. Right now the feature works for x86-64; an architecture-agnostic version follows soon.

https://github.com/mrphrazer/obfuscation_detection/
πŸ—£mr_phrazer


πŸŽ–@malwr