malware-and-exploitdev-resources : It serves as a list of resources, and other things that aid in malware analysis / dev and exploit dev
https://github.com/evilbuffer/malware-and-exploitdev-resources
π£binitamshah
π@malwr
https://github.com/evilbuffer/malware-and-exploitdev-resources
π£binitamshah
π@malwr
π1
curl-impersonate : A special compilation of curl that makes it impersonate Chrome & Firefox : https://github.com/lwthiker/curl-impersonate
Making curl impersonate Firefox : https://lwthiker.com/reversing/2022/02/17/curl-impersonate-firefox.html
Impersonating Chrome, too : https://lwthiker.com/reversing/2022/02/20/impersonating-chrome-too.html
π£binitamshah
π@malwr
Making curl impersonate Firefox : https://lwthiker.com/reversing/2022/02/17/curl-impersonate-firefox.html
Impersonating Chrome, too : https://lwthiker.com/reversing/2022/02/20/impersonating-chrome-too.html
π£binitamshah
π@malwr
VMProtect Devirtualization: An experimental dynamic approach to devirtualize pure functions protected by VMProtect 3.x
https://github.com/JonathanSalwan/VMProtect-devirtualization
π£JonathanSalwan
π@malwr
https://github.com/JonathanSalwan/VMProtect-devirtualization
π£JonathanSalwan
π@malwr
GitHub
GitHub - JonathanSalwan/VMProtect-devirtualization: Playing with the VMProtect software protection. Automatic deobfuscation ofβ¦
Playing with the VMProtect software protection. Automatic deobfuscation of pure functions using symbolic execution and LLVM. - JonathanSalwan/VMProtect-devirtualization
π1
In Depth Analysis of HermeticWiper - New Destructive Malware (Used In Cyber Attacks on Ukraine ) :https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/ credits @juanandres_gs
Threat Advisory : HermeticWiper : credits @asheermalhotra
https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/
π£binitamshah
π@malwr
Threat Advisory : HermeticWiper : credits @asheermalhotra
https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/
π£binitamshah
π@malwr
SentinelOne
HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine
A new malware is attacking Ukrainian organizations and erasing Windows devices. In this early analysis, we provide technical details, IOCS and hunting rules.
Make a USB Rubber Ducky with less than $3
'The best thing is, USB Rubber Ducky is not detected as a flash drive, but as a keyboard.'
#infosec #redteam #pentest
https://infosecwriteups.com/make-usb-rubber-ducky-with-less-than-3-fa72dac9e4de
π£CyberWarship
π@malwr
'The best thing is, USB Rubber Ducky is not detected as a flash drive, but as a keyboard.'
#infosec #redteam #pentest
https://infosecwriteups.com/make-usb-rubber-ducky-with-less-than-3-fa72dac9e4de
π£CyberWarship
π@malwr
Threat updates β A new IcedID GZipLoader variant
https://threatray.com/blog/a-new-icedid-gziploader-variant/
βΉοΈ Sent from one of our channel members
π@malwr
https://threatray.com/blog/a-new-icedid-gziploader-variant/
βΉοΈ Sent from one of our channel members
π@malwr
Threatray
Threat updates: A new IcedID GZipLoader variant | Threatray
IcedId is a modular banking Trojan discovered in 2017.
#Emotet strikes with new TTPs π¨
Project X elevated to Project Y
#DFIR analysis report covers the new infection flow:
Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
https://www.cynet.com/attack-techniques-hands-on/new-wave-of-emotet-when-project-x-turns-into-y/
π£Max_Mal_
π@malwr
Project X elevated to Project Y
#DFIR analysis report covers the new infection flow:
Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
https://www.cynet.com/attack-techniques-hands-on/new-wave-of-emotet-when-project-x-turns-into-y/
π£Max_Mal_
π@malwr
Cynet XDR | Autonomous Breach Protection
New Wave of Emotet - When Project X Turns Into Y - Cynet XDR | Autonomous Breach Protection
#Emotet 2022-02-23 The Top 30 domains statistic π
On the Top 30 there are a lot of generic domains (like gmail etc), but also corporate domains. In the Real Sender there are russian domains...
@58_158_177_102 @sugimu_sec @ValeryMarchive @guelfoweb @bomccss
π£VirITeXplorer
π@malwr
On the Top 30 there are a lot of generic domains (like gmail etc), but also corporate domains. In the Real Sender there are russian domains...
@58_158_177_102 @sugimu_sec @ValeryMarchive @guelfoweb @bomccss
π£VirITeXplorer
π@malwr
@Namecheap pls revoke the deceptive #phishing domain targeting Iranian Supreme Court and spreading malicious apk
/edu-center.eu/Ω Ψ΄Ψ§ΩΨ―Ω_Ψ§Ψ¨ΩΨ§ΨΊΫΩ.apk
#malware
π£illegalFawn
π@malwr
/edu-center.eu/Ω Ψ΄Ψ§ΩΨ―Ω_Ψ§Ψ¨ΩΨ§ΨΊΫΩ.apk
#malware
π£illegalFawn
π@malwr
The Bvp47 - a Top-tier Backdoor of US NSA Equation Group : https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf (pdf)
π£binitamshah
π@malwr
π£binitamshah
π@malwr
A Detailed Analysis of the LockBit Ransomware : https://lifars.com/wp-content/uploads/2022/02/LockBitRansomware_Whitepaper.pdf (pdf)
π£binitamshah
π@malwr
π£binitamshah
π@malwr
If you're looking at #Golang binaries in IDA @SentinelOne's is by far one of the most useful tools. (cc: @LabsSentinel, @juanandres_gs @JusticeRage )
https://github.com/SentineLabs/AlphaGolang
π£silascutler
π@malwr
https://github.com/SentineLabs/AlphaGolang
π£silascutler
π@malwr
GitHub
GitHub - SentineLabs/AlphaGolang: IDApython Scripts for Analyzing Golang Binaries
IDApython Scripts for Analyzing Golang Binaries. Contribute to SentineLabs/AlphaGolang development by creating an account on GitHub.
#HermeticWiper is a #malware targeting #Ukraine by wiping every machine disk on its path. Here the @zlab_team dissection and analysis ππ
https://yoroi.company/research/diskkill-hermeticwiper-a-disruptive-cyber-weapon-targeting-ukraines-critical-infrastructures/
π£Marco_Ramilli
π@malwr
https://yoroi.company/research/diskkill-hermeticwiper-a-disruptive-cyber-weapon-targeting-ukraines-critical-infrastructures/
π£Marco_Ramilli
π@malwr
New Jetpack Site
DiskKill/HermeticWiper, a disruptive cyber-weapon targeting Ukraineβs critical infrastructures - New Jetpack Site
Introduction During the early hours of Thursday 24 February 2022, Russia launched an attack on the country of Ukraine due to the ongoing dispute over its possible inclusion within NATO countries. This event has led to a tense geo-political climate withinβ¦
I was honored to present on Program Analysis with Ghidra for @sergeybratus's @DartmouthCS course, "Basics of Reverse Engineering" yesterday -
Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -
Slides:
π²π»
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
π£0xAlexei
π@malwr
Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -
Slides:
π²π»
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
π£0xAlexei
π@malwr
GitHub
RE-basics-W22/GHIDRA-For-Dartmouth.pdf at main Β· sergeybratus/RE-basics-W22
Basics of Reverse Engineering Winter 2022. Contribute to sergeybratus/RE-basics-W22 development by creating an account on GitHub.
π3
ContiLeaks continues to leak data from Conti... they have released source code - the Trickbot Command Dispatcher & Trickbot Data Collector. They have also doxxed one of the developers of Conti.
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
π£vxunderground
π@malwr
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
π£vxunderground
π@malwr
π₯1
My iOS QEMU fork is just published.
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
π£ntrung03
π@malwr
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
π£ntrung03
π@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
#CVE-2022-22947 Spring Cloud Gateway SpEL Remote Code Execution
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
π£pyn3rd
π@malwr
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
π£pyn3rd
π@malwr
Android Malware Research (aka the team I'm on :) is looking for an experienced Android malware reverse engineer in NYC!
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
π£maldr0id
π@malwr
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
π£maldr0id
π@malwr
Google
Build for Everyone - Google Careers
Careers at Google - find a job at Google. Look inside engineering jobs at Google.