Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.07K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
IDA Free has been upgraded to the latest IDA version 7.7SP1!
This light but powerful tool can quickly analyze the binary code samples and allow users to take a closer look at the results.
Try it out for free https://hex-rays.com/ida-free/

#IDAFreeware #Binaryanalysis #HexRays
πŸ—£HexRaysSA


πŸŽ–@malwr
πŸ”₯1
Woop Woop, good day for #CTI. @MISPProject released v2.4.153 with a lot of fixes and extra features. These new taxonomies are very interesting for state attribution ( and intrusion modeling ( See πŸ‘πŸ’―
https://www.misp-project.org/taxonomies.html#_state_responsibility
πŸ—£digihash


πŸŽ–@malwr
Fuzzing sockets: Apache HTTP, Part 3: Results
https://securitylab.github.com/research/fuzzing-apache-3/
πŸ—£kmkz_security


πŸŽ–@malwr
I wrote a Binary Ninja UI plugin for exploring Structured Exception Handlers in PEs today

https://github.com/EliseZeroTwo/SEH-Helper
πŸ—£EliseZeroTwo


πŸŽ–@malwr
RE tip of the day: Resolving imports in IDA and notice that for ntdll there are no API names? Save the resolved addresses with "Debugger->Take memory snapshot" and manually load ntdll.dll to the same base using pe_dlls.idc: https://buff.ly/34LlfAX
#infosec #cybersecurity #malware
πŸ—£re_and_more


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
Puzzled why a yara rule did or didn't match?

Let me introduce http://yaradbg.dev, a web-based #yara #debugger!

With #YaraDbg, you can see the:
1⃣ evaluation steps
2⃣ matched strings
3⃣ relationship among the rules
πŸ—£DissectMalware


πŸŽ–@malwr
πŸ‘1
Quick blog tonight on a #Monzo and #Revolut bank #phishing campaign targeting digital-only mobile users

https://blog.bushidotoken.net/2022/02/mobile-banking-phishing-campaign.html
πŸ—£BushidoToken


πŸŽ–@malwr
Blog: Detecting Karakurt – an extortion focused threat actor by NCC Group's Cyber Incident Response Team members - Simon Biggs, Richard Footman and Michael Mullen -
https://research.nccgroup.com/2022/02/17/detecting-karakurt-an-extortion-focused-threat-actor/ #Karakurt
πŸ—£NCCGroupInfosec


πŸŽ–@malwr
Added 2 PoCs for HackSys Extreme Vulnerable Driver to KernelWritePoCs.
One tries to get SYSTEM with SeCreateTokenPrivilege.
The other tries to get SYSTEM by secondary logon feature with SeCreateTokenPrivilege and SeImpersonatePrivilege.

https://github.com/daem0nc0re/PrivFu#KernelWritePoCs
πŸ—£daem0nc0re


πŸŽ–@malwr
Faking a positive COVID Test : https://labs.f-secure.com/blog/faking-a-positive-covid-test credits @Yogehi
πŸ—£binitamshah


πŸŽ–@malwr
My #BinaryNinja plugin obfuscation_detection can now identify uncommon instruction sequences (such as MBAs or weird calculations) based on stochastic n-gram analysis. Right now the feature works for x86-64; an architecture-agnostic version follows soon.

https://github.com/mrphrazer/obfuscation_detection/
πŸ—£mr_phrazer


πŸŽ–@malwr
malware-and-exploitdev-resources : It serves as a list of resources, and other things that aid in malware analysis / dev and exploit dev
https://github.com/evilbuffer/malware-and-exploitdev-resources
πŸ—£binitamshah


πŸŽ–@malwr
πŸ‘1
curl-impersonate : A special compilation of curl that makes it impersonate Chrome & Firefox : https://github.com/lwthiker/curl-impersonate

Making curl impersonate Firefox : https://lwthiker.com/reversing/2022/02/17/curl-impersonate-firefox.html

Impersonating Chrome, too : https://lwthiker.com/reversing/2022/02/20/impersonating-chrome-too.html
πŸ—£binitamshah


πŸŽ–@malwr