Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
A Detailed Analysis of the LockBit Ransomware : https://lifars.com/wp-content/uploads/2022/02/LockBitRansomware_Whitepaper.pdf (pdf)
πŸ—£binitamshah


πŸŽ–@malwr
I was honored to present on Program Analysis with Ghidra for @sergeybratus's @DartmouthCS course, "Basics of Reverse Engineering" yesterday -

Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -

Slides:


πŸ²πŸ’»
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
πŸ—£0xAlexei


πŸŽ–@malwr
πŸ‘3
ContiLeaks continues to leak data from Conti... they have released source code - the Trickbot Command Dispatcher & Trickbot Data Collector. They have also doxxed one of the developers of Conti.

You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
πŸ—£vxunderground


πŸŽ–@malwr
πŸ”₯1
My iOS QEMU fork is just published.
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation

The repo is at https://github.com/TrungNguyen1909/qemu-t8030

Tutorial/status can be found in the wiki section.
It is still very far from a usable device
πŸ—£ntrung03


πŸŽ–@malwr
You can also send your researches to the channel.
Ping me: @SirMalware
Reversing embedded device bootloader (U-Boot) & decrypt the firmware - (Part
1 - Shielder ) : https://www.shielder.it/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ credits
@zi0Black @Th3Zer0
πŸ—£binitamshah


πŸŽ–@malwr
πŸ‘1
http://phishstats.info detected 111 new websites hosting #phishing | new today: 788 | #infosec #cybersecurity #malware
πŸ—£PhishStats


πŸŽ–@malwr
Malfrat's OSINT Map is live on https://map.malfrats.industries !

We forked http://osintframework.com since this is no longer maintained, so you can easily contribute on our repo.
Thanks for their original work.
πŸ—£MalfratsInd


πŸŽ–@malwr
If you're looking to practice your #malware #analysis skills, I have several exercises available:

πŸŽ“ https://github.com/jstrosch/malware-samples

These include challenge tasks and detailed walk-throughs. You'll also find them as CTF challenges at CyberDefenders

πŸ‘‰ https://cyberdefenders.org/blueteam-ctf-challenges/
πŸ—£jstrosch


πŸŽ–@malwr
Day 78 #100DaysofYARA - fun with the dotnet module

looking for user strings (typically wide strings) that imply command execution. Why look in this way vs just as strings?

Well this rule tells us immediately that the file is a dotnet executable
πŸ—£greglesnewich


πŸŽ–@malwr