Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.08K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
My #BinaryNinja plugin obfuscation_detection can now identify uncommon instruction sequences (such as MBAs or weird calculations) based on stochastic n-gram analysis. Right now the feature works for x86-64; an architecture-agnostic version follows soon.

https://github.com/mrphrazer/obfuscation_detection/
πŸ—£mr_phrazer


πŸŽ–@malwr
malware-and-exploitdev-resources : It serves as a list of resources, and other things that aid in malware analysis / dev and exploit dev
https://github.com/evilbuffer/malware-and-exploitdev-resources
πŸ—£binitamshah


πŸŽ–@malwr
πŸ‘1
curl-impersonate : A special compilation of curl that makes it impersonate Chrome & Firefox : https://github.com/lwthiker/curl-impersonate

Making curl impersonate Firefox : https://lwthiker.com/reversing/2022/02/17/curl-impersonate-firefox.html

Impersonating Chrome, too : https://lwthiker.com/reversing/2022/02/20/impersonating-chrome-too.html
πŸ—£binitamshah


πŸŽ–@malwr
Make a USB Rubber Ducky with less than $3

'The best thing is, USB Rubber Ducky is not detected as a flash drive, but as a keyboard.'

#infosec #redteam #pentest

https://infosecwriteups.com/make-usb-rubber-ducky-with-less-than-3-fa72dac9e4de
πŸ—£CyberWarship


πŸŽ–@malwr
#Emotet strikes with new TTPs 🚨

Project X elevated to Project Y

#DFIR analysis report covers the new infection flow:

Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
https://www.cynet.com/attack-techniques-hands-on/new-wave-of-emotet-when-project-x-turns-into-y/
πŸ—£Max_Mal_


πŸŽ–@malwr
#Emotet 2022-02-23 The Top 30 domains statistic πŸ“ˆ
On the Top 30 there are a lot of generic domains (like gmail etc), but also corporate domains. In the Real Sender there are russian domains...

@58_158_177_102 @sugimu_sec @ValeryMarchive @guelfoweb @bomccss
πŸ—£VirITeXplorer


πŸŽ–@malwr
@Namecheap pls revoke the deceptive #phishing domain targeting Iranian Supreme Court and spreading malicious apk

/edu-center.eu/Ω…Ψ΄Ψ§Ω‡Ψ―Ω‡_Ψ§Ψ¨Ω„Ψ§ΨΊΫŒΩ‡.apk

#malware
πŸ—£illegalFawn


πŸŽ–@malwr
The Bvp47 - a Top-tier Backdoor of US NSA Equation Group : https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf (pdf)
πŸ—£binitamshah


πŸŽ–@malwr
A Detailed Analysis of the LockBit Ransomware : https://lifars.com/wp-content/uploads/2022/02/LockBitRansomware_Whitepaper.pdf (pdf)
πŸ—£binitamshah


πŸŽ–@malwr
I was honored to present on Program Analysis with Ghidra for @sergeybratus's @DartmouthCS course, "Basics of Reverse Engineering" yesterday -

Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -

Slides:


πŸ²πŸ’»
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
πŸ—£0xAlexei


πŸŽ–@malwr
πŸ‘3
ContiLeaks continues to leak data from Conti... they have released source code - the Trickbot Command Dispatcher & Trickbot Data Collector. They have also doxxed one of the developers of Conti.

You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
πŸ—£vxunderground


πŸŽ–@malwr
πŸ”₯1
My iOS QEMU fork is just published.
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation

The repo is at https://github.com/TrungNguyen1909/qemu-t8030

Tutorial/status can be found in the wiki section.
It is still very far from a usable device
πŸ—£ntrung03


πŸŽ–@malwr