Here is my #QuickNote - Analysis of #Pandora ransomware π€§π€’
https://kienmanowar.wordpress.com/2022/03/21/quicknote-analysis-of-pandora-ransomware/
π£kienbigmummy
π@malwr
https://kienmanowar.wordpress.com/2022/03/21/quicknote-analysis-of-pandora-ransomware/
π£kienbigmummy
π@malwr
APT35 Automates Initial Access Using ProxyShell
β‘οΈInitial Access: #ProxyShell
β‘οΈDiscovery: net, ipconfig, PowerShell, quser, etc.
β‘οΈPrivEsc: Scheduled Task
β‘οΈDefense Evasion: Real-time Monitoring & WDigest enablement
β‘οΈCredential Access: Comsvcs.dll
https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
π£TheDFIRReport
π@malwr
β‘οΈInitial Access: #ProxyShell
β‘οΈDiscovery: net, ipconfig, PowerShell, quser, etc.
β‘οΈPrivEsc: Scheduled Task
β‘οΈDefense Evasion: Real-time Monitoring & WDigest enablement
β‘οΈCredential Access: Comsvcs.dll
https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
π£TheDFIRReport
π@malwr
The DFIR Report
PHOSPHORUS Automates Initial Access Using ProxyShell
In this intrusion, we observed the initial exploitation of the ProxyShell vulnerabilities followed by some further post-exploitation activity, which included web shells, credential dumping, and specialized payloads.
π1
Threads, Threads, and More Threads http://scorpiosoftware.net/2022/03/21/threads-threads-and-more-threads/
π£zodiacon
π@malwr
π£zodiacon
π@malwr
Pavel Yosifovich
Threads, Threads, and More Threads
Looking at a typical Windows system shows thousands of threads, with process numbers in the hundreds, even though the total CPU consumption is low, meaning most of these threads are doing nothing mβ¦
Windows API - Exploring Virtual Memory and the Virtual Memory Management API, by @coder_rc
https://de-engineer.github.io/Understanding-Virtual-Memory-Paging-and-other-memory-related-concepts/
π£DirectoryRanger
π@malwr
https://de-engineer.github.io/Understanding-Virtual-Memory-Paging-and-other-memory-related-concepts/
π£DirectoryRanger
π@malwr
de engineering
Exploring Virtual Memory and the Virtual Memory Management API.
Introduction to Virtual Memory, Paging and Windows API functions that allow us to play with the virtual memory!
π4
We're hiring for the @Mandiant #AdvancedPractices Research team!π¦
β‘οΈSelf-driven defensive- and intel-oriented research
β‘οΈSupport Mandiant IRs with research and detection
β‘οΈCodify attacker methodologies
β‘οΈSurface new activity
π₯Great team/mission/dataπ₯
https://jobs.smartrecruiters.com/Mandiant/743999814012433
π£matthewdunwoody
π@malwr
β‘οΈSelf-driven defensive- and intel-oriented research
β‘οΈSupport Mandiant IRs with research and detection
β‘οΈCodify attacker methodologies
β‘οΈSurface new activity
π₯Great team/mission/dataπ₯
https://jobs.smartrecruiters.com/Mandiant/743999814012433
π£matthewdunwoody
π@malwr
Mandiant
Mandiant is looking for a Senior Security Researcher (Remote US) in Reston, VA, USA
The Role:Lay the foundation: research, model, and integrate threat dataBuild the layers: search telemetry to find new intrusions, malware and tradecraftWork the resolution: notify our clients and ...
My favorite IDA shortcut: ctrl-L lets you powerfully search across all func names & var names!
Want to find everything related to packets? Search it with Ctrl-L.
π£whtaguy
π@malwr
Want to find everything related to packets? Search it with Ctrl-L.
π£whtaguy
π@malwr
Started collecting observed/hardcoded #mutex from various #malware families.
Feel free to send PRs: https://github.com/albertzsigovits/malware-mutex/blob/main/README.md
π£albertzsigovits
π@malwr
Feel free to send PRs: https://github.com/albertzsigovits/malware-mutex/blob/main/README.md
π£albertzsigovits
π@malwr
GitHub
malware-mutex/README.md at main Β· albertzsigovits/malware-mutex
Muteces (mutexes/mutants) used by various malware families - albertzsigovits/malware-mutex
PlugX: A Talisman to Behold
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/plugx-a-talisman-to-behold.html
βΉοΈ Sent from one of our channel members
π@malwr
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/plugx-a-talisman-to-behold.html
βΉοΈ Sent from one of our channel members
π@malwr
Trellix
PlugX: A Talisman to Behold
This blog covers a PlugX variant that we have named Talisman and its rather long life since it first emerged in 2008.
RE tip of the day: In kernel mode, the system service dispatcher (aka KiSystemService/KiSystemCall64[Shadow]) is responsible for finding the requested function by its index number (SSN) passed in EAX in the SSDT table.
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
Curious about what's happening in the Windows Kernel after a Syscall?
I just wrote this post following the worfkflow from the Syscall instruction to the target kernel routine β¬οΈ
https://alice.climent-pommeret.red/posts/a-syscall-journey-in-the-windows-kernel/
Thanks again to @Set_hyx for the proofreading!
π£AliceCliment
π@malwr
I just wrote this post following the worfkflow from the Syscall instruction to the target kernel routine β¬οΈ
https://alice.climent-pommeret.red/posts/a-syscall-journey-in-the-windows-kernel/
Thanks again to @Set_hyx for the proofreading!
π£AliceCliment
π@malwr
Digital Forensics Basics : A Practical Guide for Kubernetes DFIR : https://sysdig.com/blog/guide-kubernetes-forensics-dfir/ credits @sysdig
Kubernetes Hardening Guide by @NSAGov & @CISAgov : https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF (pdf)
π£binitamshah
π@malwr
Kubernetes Hardening Guide by @NSAGov & @CISAgov : https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF (pdf)
π£binitamshah
π@malwr
Sysdig
Practical Guide for DFIR Kubernetes | Sysdig
We covered the basic best practices to perform DFIR Kubernetes. We also simulated how to inspect and respond to a breach.
my first blog post -- taking a shot at malware analysis.
https://medium.com/@mars0x/wannahusky-malware-analysis-w-yara-ttps-2069fb479909
https://medium.com/@mars0x/wannahusky-malware-analysis-w-yara-ttps-2069fb479909
π£mars0x_
π@malwr
https://medium.com/@mars0x/wannahusky-malware-analysis-w-yara-ttps-2069fb479909
https://medium.com/@mars0x/wannahusky-malware-analysis-w-yara-ttps-2069fb479909
π£mars0x_
π@malwr
Medium
WannaHusky Malware Analysis w/ YARA + TTPs
Hello! I have recently gained a new interest in threat intelligence, malware research and analysis. In response, I have been taking coursesβ¦
Live-Forensicator - Powershell Script To Aid Incidence Response And Live Forensics https://bit.ly/3jd6Y3V #ForensicsInvestigations
π£KitPloit
π@malwr
π£KitPloit
π@malwr
PE file viewer/editor for Windows, Linux and MacOS.
Version 0.03
https://github.com/horsicq/XPEViewer
#hacker #infosec #malware #hacking #programming #reversing #opensource #xpeviewer #cybersecurity #windows #linux #osx #macos #qt #pe #exe #assembler #hex
π£horsicq
π@malwr
Version 0.03
https://github.com/horsicq/XPEViewer
#hacker #infosec #malware #hacking #programming #reversing #opensource #xpeviewer #cybersecurity #windows #linux #osx #macos #qt #pe #exe #assembler #hex
π£horsicq
π@malwr
GitHub
GitHub - horsicq/XPEViewer: PE file viewer/editor for Windows, Linux and MacOS.
PE file viewer/editor for Windows, Linux and MacOS. - horsicq/XPEViewer
Did you know that 7zip can "unzip" VMware VMDKs?
Quickly build a ~"goodware" repo for testing your #100DaysofYARA rules w/ a free Windows 10 VM https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/
Unzip and uze 7zz to extract the VMDK
7zz x ~/MSEdge-Win10-VMware/MSEdge-Win10-VMware-disk1.vmdk -oMSEdge-vm
π£stvemillertime
π@malwr
Quickly build a ~"goodware" repo for testing your #100DaysofYARA rules w/ a free Windows 10 VM https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/
Unzip and uze 7zz to extract the VMDK
7zz x ~/MSEdge-Win10-VMware/MSEdge-Win10-VMware-disk1.vmdk -oMSEdge-vm
π£stvemillertime
π@malwr
#Ghidra script to handle stack strings
https://maxkersten.nl/binary-analysis-course/analysis-scripts/ghidra-script-to-handle-stack-strings/
βΉοΈ Sent from one of our channel members
π@malwr
https://maxkersten.nl/binary-analysis-course/analysis-scripts/ghidra-script-to-handle-stack-strings/
βΉοΈ Sent from one of our channel members
π@malwr
New blogpost detailing TTPs used by Zloader. It has been observed being delivered via malicious search engine ads and malicious emails. Check out the blog for more details and IOCs! #infosecurity #microsoft #cybersecurity #threatintelligence
https://www.microsoft.com/security/blog/2022/04/13/dismantling-zloader-how-malicious-ads-led-to-disabled-security-tools-and-ransomware/
π£fr0gger_
π@malwr
https://www.microsoft.com/security/blog/2022/04/13/dismantling-zloader-how-malicious-ads-led-to-disabled-security-tools-and-ransomware/
π£fr0gger_
π@malwr
Metamorphic Fuzzing of C++ Libraries
http://www.doc.ic.ac.uk/~afd/homepages/papers/pdfs/2022/ICST.pdf
π£johnregehr
π@malwr
http://www.doc.ic.ac.uk/~afd/homepages/papers/pdfs/2022/ICST.pdf
π£johnregehr
π@malwr
π1
I started to use DFIRtriage in my malware analysis, it gives you a huge amount of information regarding the malware behavior.
https://github.com/travisfoley/dfirtriage
π£fr0s7_
π@malwr
https://github.com/travisfoley/dfirtriage
π£fr0s7_
π@malwr
π1
My final blog post for varonis is now available which outlines how to get started with volatility. This tool is an absolute necessity for anybody in Incident Response and will prove invaluable when triaging compromised servers. #Malware
https://www.varonis.com/blog/how-to-use-volatility
π£0xf0x_
π@malwr
https://www.varonis.com/blog/how-to-use-volatility
π£0xf0x_
π@malwr
Varonis
How to Use Volatility for Memory Forensics and Analysis | Varonis
This article will cover what Volatility is, how to install Volatility, and most importantly how to use Volatility.
Blog post #3
In this blog, I cover the basics of the translation process of a virtual memory address into physical memory address as well as the PTE structure and usage of another WinAPI function with examples.
https://de-engineer.github.io/Virtual-Address-Translation-and-structure-of-PTE
#infosec
π£coder_rc
π@malwr
In this blog, I cover the basics of the translation process of a virtual memory address into physical memory address as well as the PTE structure and usage of another WinAPI function with examples.
https://de-engineer.github.io/Virtual-Address-Translation-and-structure-of-PTE
#infosec
π£coder_rc
π@malwr
π1