Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Check out my analysis of #LockBit #ransomware v2.0 where I analyze all of its functionalities in IDA!

https://chuongdong.com/reverse%20engineering/2022/03/19/LockbitRansomware/

h/t to @BushidoToken for the CTI and @demonslay335 for helping with the crypto!
๐Ÿ—ฃcPeterr


๐ŸŽ–@malwr
๐Ÿ‘2
My colleague recently reminded me that Python executes zip files which of course extends to other zip-based formats and lets you do things like this.
๐Ÿ—ฃZetaTwo


๐ŸŽ–@malwr
๐Ÿ‘2๐Ÿค”1
Here is my #QuickNote - Analysis of #Pandora ransomware ๐Ÿคง๐Ÿคข
https://kienmanowar.wordpress.com/2022/03/21/quicknote-analysis-of-pandora-ransomware/
๐Ÿ—ฃkienbigmummy


๐ŸŽ–@malwr
APT35 Automates Initial Access Using ProxyShell

โžก๏ธInitial Access: #ProxyShell
โžก๏ธDiscovery: net, ipconfig, PowerShell, quser, etc.
โžก๏ธPrivEsc: Scheduled Task
โžก๏ธDefense Evasion: Real-time Monitoring & WDigest enablement
โžก๏ธCredential Access: Comsvcs.dll

https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
๐Ÿ—ฃTheDFIRReport


๐ŸŽ–@malwr
๐Ÿ‘1
We're hiring for the @Mandiant #AdvancedPractices Research team!๐Ÿฆ…

โžก๏ธSelf-driven defensive- and intel-oriented research
โžก๏ธSupport Mandiant IRs with research and detection
โžก๏ธCodify attacker methodologies
โžก๏ธSurface new activity

๐Ÿ”ฅGreat team/mission/data๐Ÿ”ฅ

https://jobs.smartrecruiters.com/Mandiant/743999814012433
๐Ÿ—ฃmatthewdunwoody


๐ŸŽ–@malwr
My favorite IDA shortcut: ctrl-L lets you powerfully search across all func names & var names!
Want to find everything related to packets? Search it with Ctrl-L.
๐Ÿ—ฃwhtaguy


๐ŸŽ–@malwr