ContiLeaks continues to leak data from Conti... they have released source code - the Trickbot Command Dispatcher & Trickbot Data Collector. They have also doxxed one of the developers of Conti.
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
🗣vxunderground
🎖@malwr
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
🗣vxunderground
🎖@malwr
🔥1
My iOS QEMU fork is just published.
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
🗣ntrung03
🎖@malwr
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
🗣ntrung03
🎖@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
#CVE-2022-22947 Spring Cloud Gateway SpEL Remote Code Execution
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
🗣pyn3rd
🎖@malwr
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
🗣pyn3rd
🎖@malwr
Android Malware Research (aka the team I'm on :) is looking for an experienced Android malware reverse engineer in NYC!
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
🗣maldr0id
🎖@malwr
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
🗣maldr0id
🎖@malwr
Google
Build for Everyone - Google Careers
Careers at Google - find a job at Google. Look inside engineering jobs at Google.
Announcing Windows 11 Insider Preview Build 22567
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
🗣windowsblog
🎖@malwr
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
🗣windowsblog
🎖@malwr
Windows Insider Blog
Announcing Windows 11 Insider Preview Build 22567
UPDATE 3/7: We are starting to roll out Cumulative Update Build 22567.200 (KB5012432). This update does not include anything new and is designed to test our servicing pipeline for builds in the Dev Channel.
NOTE: Windows Insider
NOTE: Windows Insider
A deep dive into HermeticWiper's internals
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
ℹ️ Sent from one of our channel members
🎖@malwr
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
ℹ️ Sent from one of our channel members
🎖@malwr
Trellix
Digging into HermeticWiper
The HermeticWiper malware aims to destroy the boot sectors of any (removable) disk on the infected machine, with the help of a benign partition manager driver.
Find out how two flaws in NETGEAR DGND3700v2 devices allow remote unauthenticated attackers to trigger bypass the authentication mechanism and run commands as root
🗣SSDisclosure
🎖@malwr
🗣SSDisclosure
🎖@malwr
SSD Secure Disclosure
SSD Advisory – NETGEAR DGND3700v2 PreAuth Root Access - SSD Secure Disclosure
Find out how a vulnerability in multiple Uniview devices allow remote unauthenticated attackers to trigger a remote code execution vulnerability in the products the company offers.
Reversing embedded device bootloader (U-Boot) & decrypt the firmware - (Part
1 - Shielder ) : https://www.shielder.it/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ credits
@zi0Black @Th3Zer0
🗣binitamshah
🎖@malwr
1 - Shielder ) : https://www.shielder.it/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ credits
@zi0Black @Th3Zer0
🗣binitamshah
🎖@malwr
👍1
http://phishstats.info detected 111 new websites hosting #phishing | new today: 788 | #infosec #cybersecurity #malware
🗣PhishStats
🎖@malwr
🗣PhishStats
🎖@malwr
Malfrat's OSINT Map is live on https://map.malfrats.industries !
We forked http://osintframework.com since this is no longer maintained, so you can easily contribute on our repo.
Thanks for their original work.
🗣MalfratsInd
🎖@malwr
We forked http://osintframework.com since this is no longer maintained, so you can easily contribute on our repo.
Thanks for their original work.
🗣MalfratsInd
🎖@malwr
If you're looking to practice your #malware #analysis skills, I have several exercises available:
🎓 https://github.com/jstrosch/malware-samples
These include challenge tasks and detailed walk-throughs. You'll also find them as CTF challenges at CyberDefenders
👉 https://cyberdefenders.org/blueteam-ctf-challenges/
🗣jstrosch
🎖@malwr
🎓 https://github.com/jstrosch/malware-samples
These include challenge tasks and detailed walk-throughs. You'll also find them as CTF challenges at CyberDefenders
👉 https://cyberdefenders.org/blueteam-ctf-challenges/
🗣jstrosch
🎖@malwr
Day 78 #100DaysofYARA - fun with the dotnet module
looking for user strings (typically wide strings) that imply command execution. Why look in this way vs just as strings?
Well this rule tells us immediately that the file is a dotnet executable
🗣greglesnewich
🎖@malwr
looking for user strings (typically wide strings) that imply command execution. Why look in this way vs just as strings?
Well this rule tells us immediately that the file is a dotnet executable
🗣greglesnewich
🎖@malwr
A nice bit of #HermeticWiper reversing by @eln0ty–
https://eln0ty.github.io/malware%20analysis/HermeticWiper/
🗣juanandres_gs
🎖@malwr
https://eln0ty.github.io/malware%20analysis/HermeticWiper/
🗣juanandres_gs
🎖@malwr
eln0ty
HermeticWiper/FoxBlade Analysis (in-depth)
The malware which targeting Ukrainian infrastructure (Specially windows devices) has since been observed in the neighboring countries of Latvia and Lithuania and manipulating the MBR resulting in subsequent boot failure.
Full Reverse Engineering of Sony Memory Stick
🗣dmitrygr
Is there any easy way to spoof the card serial number?
A MCU acting as man-in-the-middle, or something else?
I need it to unbrick a PSP 2000.
👤RainyShadow
Nice!
Sony, the king of proprietary mediums. What a nightmare for consumers and devs alike.
👤usernamenottakenwooh
MagicGate still holding up?
👤TailSpinBowler
🎖@malwr
🗣dmitrygr
Is there any easy way to spoof the card serial number?
A MCU acting as man-in-the-middle, or something else?
I need it to unbrick a PSP 2000.
👤RainyShadow
Nice!
Sony, the king of proprietary mediums. What a nightmare for consumers and devs alike.
👤usernamenottakenwooh
MagicGate still holding up?
👤TailSpinBowler
🎖@malwr
Dmitry.GR
Sony Memory Stick - Dmitry.GR
Dmitry.GR: The first complete documentation of Sony Memory Stick from HW to DATA
Debugger and analyzer for ELF executables named "donna" made by me . Im still a HS student so any help would be appreciated. Made in C++ btw.
🗣suibex
Writing a debugger in high school? Color me impressed.
👤jameson71
Suggestion: remove all the random empty lines you have littered throughout the code or just run you code through a formatter.
👤magion
🎖@malwr
🗣suibex
Writing a debugger in high school? Color me impressed.
👤jameson71
Suggestion: remove all the random empty lines you have littered throughout the code or just run you code through a formatter.
👤magion
🎖@malwr
GitHub
GitHub - suibex/donna: Debugger and analyzer for ARM ELF executables.
Debugger and analyzer for ARM ELF executables. Contribute to suibex/donna development by creating an account on GitHub.
Suspected Conti Ransomware Activity in the Auto Manufacturing Sector - looks like they used Netflow to understand who the victims were
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
Dragos
Suspected Conti Ransomware Activity in the Auto Manufacturing Sector
Dragos is observing evidence of multiple automotive manufacturers compromised by Emotet. A malware strain & a cybercrime operation.