VMProtect Devirtualization: An experimental dynamic approach to devirtualize pure functions protected by VMProtect 3.x
https://github.com/JonathanSalwan/VMProtect-devirtualization
π£JonathanSalwan
π@malwr
https://github.com/JonathanSalwan/VMProtect-devirtualization
π£JonathanSalwan
π@malwr
GitHub
GitHub - JonathanSalwan/VMProtect-devirtualization: Playing with the VMProtect software protection. Automatic deobfuscation ofβ¦
Playing with the VMProtect software protection. Automatic deobfuscation of pure functions using symbolic execution and LLVM. - JonathanSalwan/VMProtect-devirtualization
π1
In Depth Analysis of HermeticWiper - New Destructive Malware (Used In Cyber Attacks on Ukraine ) :https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/ credits @juanandres_gs
Threat Advisory : HermeticWiper : credits @asheermalhotra
https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/
π£binitamshah
π@malwr
Threat Advisory : HermeticWiper : credits @asheermalhotra
https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/
π£binitamshah
π@malwr
SentinelOne
HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine
A new malware is attacking Ukrainian organizations and erasing Windows devices. In this early analysis, we provide technical details, IOCS and hunting rules.
Make a USB Rubber Ducky with less than $3
'The best thing is, USB Rubber Ducky is not detected as a flash drive, but as a keyboard.'
#infosec #redteam #pentest
https://infosecwriteups.com/make-usb-rubber-ducky-with-less-than-3-fa72dac9e4de
π£CyberWarship
π@malwr
'The best thing is, USB Rubber Ducky is not detected as a flash drive, but as a keyboard.'
#infosec #redteam #pentest
https://infosecwriteups.com/make-usb-rubber-ducky-with-less-than-3-fa72dac9e4de
π£CyberWarship
π@malwr
Threat updates β A new IcedID GZipLoader variant
https://threatray.com/blog/a-new-icedid-gziploader-variant/
βΉοΈ Sent from one of our channel members
π@malwr
https://threatray.com/blog/a-new-icedid-gziploader-variant/
βΉοΈ Sent from one of our channel members
π@malwr
Threatray
Threat updates: A new IcedID GZipLoader variant | Threatray
IcedId is a modular banking Trojan discovered in 2017.
#Emotet strikes with new TTPs π¨
Project X elevated to Project Y
#DFIR analysis report covers the new infection flow:
Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
https://www.cynet.com/attack-techniques-hands-on/new-wave-of-emotet-when-project-x-turns-into-y/
π£Max_Mal_
π@malwr
Project X elevated to Project Y
#DFIR analysis report covers the new infection flow:
Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
https://www.cynet.com/attack-techniques-hands-on/new-wave-of-emotet-when-project-x-turns-into-y/
π£Max_Mal_
π@malwr
Cynet XDR | Autonomous Breach Protection
New Wave of Emotet - When Project X Turns Into Y - Cynet XDR | Autonomous Breach Protection
#Emotet 2022-02-23 The Top 30 domains statistic π
On the Top 30 there are a lot of generic domains (like gmail etc), but also corporate domains. In the Real Sender there are russian domains...
@58_158_177_102 @sugimu_sec @ValeryMarchive @guelfoweb @bomccss
π£VirITeXplorer
π@malwr
On the Top 30 there are a lot of generic domains (like gmail etc), but also corporate domains. In the Real Sender there are russian domains...
@58_158_177_102 @sugimu_sec @ValeryMarchive @guelfoweb @bomccss
π£VirITeXplorer
π@malwr
@Namecheap pls revoke the deceptive #phishing domain targeting Iranian Supreme Court and spreading malicious apk
/edu-center.eu/Ω Ψ΄Ψ§ΩΨ―Ω_Ψ§Ψ¨ΩΨ§ΨΊΫΩ.apk
#malware
π£illegalFawn
π@malwr
/edu-center.eu/Ω Ψ΄Ψ§ΩΨ―Ω_Ψ§Ψ¨ΩΨ§ΨΊΫΩ.apk
#malware
π£illegalFawn
π@malwr
The Bvp47 - a Top-tier Backdoor of US NSA Equation Group : https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf (pdf)
π£binitamshah
π@malwr
π£binitamshah
π@malwr
A Detailed Analysis of the LockBit Ransomware : https://lifars.com/wp-content/uploads/2022/02/LockBitRansomware_Whitepaper.pdf (pdf)
π£binitamshah
π@malwr
π£binitamshah
π@malwr
If you're looking at #Golang binaries in IDA @SentinelOne's is by far one of the most useful tools. (cc: @LabsSentinel, @juanandres_gs @JusticeRage )
https://github.com/SentineLabs/AlphaGolang
π£silascutler
π@malwr
https://github.com/SentineLabs/AlphaGolang
π£silascutler
π@malwr
GitHub
GitHub - SentineLabs/AlphaGolang: IDApython Scripts for Analyzing Golang Binaries
IDApython Scripts for Analyzing Golang Binaries. Contribute to SentineLabs/AlphaGolang development by creating an account on GitHub.
#HermeticWiper is a #malware targeting #Ukraine by wiping every machine disk on its path. Here the @zlab_team dissection and analysis ππ
https://yoroi.company/research/diskkill-hermeticwiper-a-disruptive-cyber-weapon-targeting-ukraines-critical-infrastructures/
π£Marco_Ramilli
π@malwr
https://yoroi.company/research/diskkill-hermeticwiper-a-disruptive-cyber-weapon-targeting-ukraines-critical-infrastructures/
π£Marco_Ramilli
π@malwr
New Jetpack Site
DiskKill/HermeticWiper, a disruptive cyber-weapon targeting Ukraineβs critical infrastructures - New Jetpack Site
Introduction During the early hours of Thursday 24 February 2022, Russia launched an attack on the country of Ukraine due to the ongoing dispute over its possible inclusion within NATO countries. This event has led to a tense geo-political climate withinβ¦
I was honored to present on Program Analysis with Ghidra for @sergeybratus's @DartmouthCS course, "Basics of Reverse Engineering" yesterday -
Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -
Slides:
π²π»
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
π£0xAlexei
π@malwr
Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -
Slides:
π²π»
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
π£0xAlexei
π@malwr
GitHub
RE-basics-W22/GHIDRA-For-Dartmouth.pdf at main Β· sergeybratus/RE-basics-W22
Basics of Reverse Engineering Winter 2022. Contribute to sergeybratus/RE-basics-W22 development by creating an account on GitHub.
π3
ContiLeaks continues to leak data from Conti... they have released source code - the Trickbot Command Dispatcher & Trickbot Data Collector. They have also doxxed one of the developers of Conti.
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
π£vxunderground
π@malwr
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
π£vxunderground
π@malwr
π₯1
My iOS QEMU fork is just published.
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
π£ntrung03
π@malwr
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
π£ntrung03
π@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
#CVE-2022-22947 Spring Cloud Gateway SpEL Remote Code Execution
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
π£pyn3rd
π@malwr
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
π£pyn3rd
π@malwr
Android Malware Research (aka the team I'm on :) is looking for an experienced Android malware reverse engineer in NYC!
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
π£maldr0id
π@malwr
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
π£maldr0id
π@malwr
Google
Build for Everyone - Google Careers
Careers at Google - find a job at Google. Look inside engineering jobs at Google.
Announcing Windows 11 Insider Preview Build 22567
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
π£windowsblog
π@malwr
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
π£windowsblog
π@malwr
Windows Insider Blog
Announcing Windows 11 Insider Preview Build 22567
UPDATE 3/7: We are starting to roll out Cumulative Update Build 22567.200 (KB5012432). This update does not include anything new and is designed to test our servicing pipeline for builds in the Dev Channel.
NOTE: Windows Insider
NOTE: Windows Insider
Ghidra for beginners - Pwn Zero To Hero
π£PinkDraconian
Great video as always
π€navneetmuffin
π@malwr
π£PinkDraconian
Great video as always
π€navneetmuffin
π@malwr
YouTube
Ghidra - Pwn Zero To Hero 0x02
Full Pwn Zero To Hero playlist: https://www.youtube.com/playlist?list=PLeSXUd883dhjmKkVXSRgI1nJEZUDzgLf_
Crackmes: https://crackmes.one/
βΆοΈ YouTube: https://www.youtube.com/c/PinkDraconian
π Patreon: https://www.patreon.com/PinkDraconian
π¦ Twitter: httβ¦
Crackmes: https://crackmes.one/
βΆοΈ YouTube: https://www.youtube.com/c/PinkDraconian
π Patreon: https://www.patreon.com/PinkDraconian
π¦ Twitter: httβ¦
A deep dive into HermeticWiper's internals
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
βΉοΈ Sent from one of our channel members
π@malwr
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
βΉοΈ Sent from one of our channel members
π@malwr
Trellix
Digging into HermeticWiper
The HermeticWiper malware aims to destroy the boot sectors of any (removable) disk on the infected machine, with the help of a benign partition manager driver.