Suspected Conti Ransomware Activity in the Auto Manufacturing Sector - looks like they used Netflow to understand who the victims were
π£digicat
π@malwr
π£digicat
π@malwr
Dragos
Suspected Conti Ransomware Activity in the Auto Manufacturing Sector
Dragos is observing evidence of multiple automotive manufacturers compromised by Emotet. A malware strain & a cybercrime operation.
DirtyMoe: Worming Modules - The DirtyMoe malware is deployed using various kits like PurpleFox or injected installers of Telegram Messenger that require user interaction. Complementary to this deployment, one of the modules expands the malware using worm-like techniques that require no interaction
π£digicat
π@malwr
π£digicat
π@malwr
Gendigital
DirtyMoe: Worming Modules
DirtyMoe's Rapid Worming Expansion
Frelatage: A fuzzing library to find vulnerabilities and bugs in Python applications
π£FrenchFuzzer
π@malwr
π£FrenchFuzzer
π@malwr
GitHub
GitHub - Rog3rSm1th/frelatage: Coverage-based fuzzer for python applications
Coverage-based fuzzer for python applications. Contribute to Rog3rSm1th/frelatage development by creating an account on GitHub.
A tale of EDR bypass methods
#infosec #pentest #redteam
https://s3cur3th1ssh1t.github.io/A-tale-of-EDR-bypass-methods/
π£CyberWarship
π@malwr
#infosec #pentest #redteam
https://s3cur3th1ssh1t.github.io/A-tale-of-EDR-bypass-methods/
π£CyberWarship
π@malwr
Detect strange memory regions and DLLs by using MalMemDetect by @waldoirc. For more information on this #redteamtool, head to #GitHub: https://bfx.social/3Jqt2Dl #infosec
https://bfx.social/3Jqt2Dl
π£bishopfox
π@malwr
https://bfx.social/3Jqt2Dl
π£bishopfox
π@malwr
GitHub
GitHub - waldo-irc/MalMemDetect: Detect strange memory regions and DLLs
Detect strange memory regions and DLLs. Contribute to waldo-irc/MalMemDetect development by creating an account on GitHub.
NotepadExec - Using notepad.exe to launch an EXE without code injection
(useless and unreliable but why not? π)
https://www.x86matthew.com/view_post?id=notepadexec
π£x86matthew
π@malwr
(useless and unreliable but why not? π)
https://www.x86matthew.com/view_post?id=notepadexec
π£x86matthew
π@malwr
I uploaded my #bsidesroc Computer Forensic Case Files talk to https://github.com/secshoggoth/presentations/tree/master/bsidesroc2022 @BSidesROC
https://github.com/secshoggoth/presentations/tree/master/bsidesroc2022
π£SecShoggoth
π@malwr
https://github.com/secshoggoth/presentations/tree/master/bsidesroc2022
π£SecShoggoth
π@malwr
GitHub
presentations/bsidesroc2022 at master Β· secshoggoth/presentations
Repository of the presentations that I have given and released. - presentations/bsidesroc2022 at master Β· secshoggoth/presentations
Check out my analysis of #LockBit #ransomware v2.0 where I analyze all of its functionalities in IDA!
https://chuongdong.com/reverse%20engineering/2022/03/19/LockbitRansomware/
h/t to @BushidoToken for the CTI and @demonslay335 for helping with the crypto!
π£cPeterr
π@malwr
https://chuongdong.com/reverse%20engineering/2022/03/19/LockbitRansomware/
h/t to @BushidoToken for the CTI and @demonslay335 for helping with the crypto!
π£cPeterr
π@malwr
π2
I know I said that I was gonna publish on my blog this week but I decided to just write it up tonight. All materials at the end of the blog. Enjoy friends!: https://malwaremaycry.medium.com/my-malware-analysis-journey-and-ecmap-edd37dade775 #informationsecurity #malwareanalysis #malware #certification #tech #IT
https://malwaremaycry.medium.com/my-malware-analysis-journey-and-ecmap-edd37dade775
π£MalwareMayCry1
π@malwr
https://malwaremaycry.medium.com/my-malware-analysis-journey-and-ecmap-edd37dade775
π£MalwareMayCry1
π@malwr
Medium
My Malware Analysis Journey and eCMAP
On March 19th, 2022, I passed the eCMAP(eLearnSecurity Certified Malware Professional) exam. In this post, Iβm going to talk about myβ¦
Extracting Malware from Memory with Hollows_Hunter https://securityliterate.com/extracting-malware-from-memory-with-hollows-hunter/
https://securityliterate.com/extracting-malware-from-memory-with-hollows-hunter/
π£pentest_swissky
π@malwr
https://securityliterate.com/extracting-malware-from-memory-with-hollows-hunter/
π£pentest_swissky
π@malwr
Kyle Cucci's Cyber Ramblings
Extracting Malware from Memory with Hollows_Hunter
Sometimes I come across a tool that makes me stop and think what I have been doing all my life life without it. This is how I feel about hollows_hunter. Hollows_hunter is essentially a tool for autβ¦
My colleague recently reminded me that Python executes zip files which of course extends to other zip-based formats and lets you do things like this.
π£ZetaTwo
π@malwr
π£ZetaTwo
π@malwr
π2π€1
Adversary3 v1.0 - Malware vulnerability intel tool for third-party attackers.
https://github.com/malvuln/Adversary3
π£malvuln
π@malwr
https://github.com/malvuln/Adversary3
π£malvuln
π@malwr
GitHub
GitHub - malvuln/Adversary3: Malware vulnerability intel tool for third-party attackers
Malware vulnerability intel tool for third-party attackers - malvuln/Adversary3
π1
Surtr #ransomware pays tribute to the now defunct #REvil (aka Sodinokibi) group by making a registry key change to the infected host.
https://areteir.com/surtr-ransomware-pays-tribute-to-revil/
π£TheHackersNews
π@malwr
https://areteir.com/surtr-ransomware-pays-tribute-to-revil/
π£TheHackersNews
π@malwr
Arete IR
Article: Surtr Ransomware Pays Tribute to REvil
Arete notes that developers of Surtr likely do not have a direct connection to the REvil group, but are likely leveraging their REvil tribute to gain popularity.
Digital Forensics Incident Response Cheat Sheet
Credit @sansforensics
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #cissp #CyberSec #networking #logs #CheatSheet #cyberattacks #security #vulnerabilities #forensics #dfir #incidentresponse
π£hackinarticles
π@malwr
Credit @sansforensics
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #cissp #CyberSec #networking #logs #CheatSheet #cyberattacks #security #vulnerabilities #forensics #dfir #incidentresponse
π£hackinarticles
π@malwr