Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.12K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Metamorphic Fuzzing of C++ Libraries
http://www.doc.ic.ac.uk/~afd/homepages/papers/pdfs/2022/ICST.pdf
πŸ—£johnregehr


πŸŽ–@malwr
πŸ‘1
I started to use DFIRtriage in my malware analysis, it gives you a huge amount of information regarding the malware behavior.

https://github.com/travisfoley/dfirtriage
πŸ—£fr0s7_


πŸŽ–@malwr
πŸ‘1
My final blog post for varonis is now available which outlines how to get started with volatility. This tool is an absolute necessity for anybody in Incident Response and will prove invaluable when triaging compromised servers. #Malware

https://www.varonis.com/blog/how-to-use-volatility
πŸ—£0xf0x_


πŸŽ–@malwr
Blog post #3

In this blog, I cover the basics of the translation process of a virtual memory address into physical memory address as well as the PTE structure and usage of another WinAPI function with examples.

https://de-engineer.github.io/Virtual-Address-Translation-and-structure-of-PTE

#infosec
πŸ—£coder_rc


πŸŽ–@malwr
πŸ‘1
Updated my ScheduleRunner to include the "hiding scheduled task" technique used by Tarrask malware. This technique can literally make your scheduled task invisible from query tools and Task Scheduler.
https://github.com/netero1010/ScheduleRunner
πŸ—£netero_1010


πŸŽ–@malwr
This repository contains a Red team Offensive Security Exploitation Tool
which uses TOR and OnionShare as long with Meterpreter Session.

https://github.com/ToxicEnvelope/SetmPloit

ℹ️ Sent from one of our channel members

πŸŽ–@malwr
πŸ‘1
New Blog! Lessons from the Conti Leaks

https://blog.bushidotoken.net/2022/04/lessons-from-conti-leaks.html
πŸ—£BushidoToken


πŸŽ–@malwr
πŸ‘1
New Trend Micro data shows that Purple Fox operators are using trojanized software packages to trick users into downloading their payloads.

Read about #PurpleFox’s infection chain and learn about its new campaign here: https://research.trendmicro.com/36x6pPz
πŸ—£TrendMicroRSRCH


πŸŽ–@malwr
πŸ‘1
Sysmon's RegistryEvent (Value Set) https://i5c.us/d28558
πŸ—£sans_isc


πŸŽ–@malwr
The FBI, CISA & US Treasury Department have released a joint advisory to highlight the threat associated with cryptocurrency thefts & tactics used by a North Korean state-sponsored APT group (Lazarus/APT38/BlueNoroff/Stardust Chollima) since at least 2020 https://www.cisa.gov/uscert/ncas/alerts/aa22-108a
πŸ—£virusbtn


πŸŽ–@malwr
Emotet Loader Technical Analysis
https://nikpx.github.io/malware/analysis/2022/04/19/Emotet_Loader.html
πŸ—£xorsthingsv2


πŸŽ–@malwr
Wtf another RAT was released on GitHub.

58d577e0a9e182dc2fedede09dfb586cf62fb56cc36e2e5fecf4280d2395abfb

https://github.com/arsium/EagleMonitorRAT

malwrhunterteam probably skiddies will roll from LimeRAT to this shit?
πŸ—£fr0s7_


πŸŽ–@malwr
πŸ₯³πŸ₯³πŸ₯³BinAbsInspector (Binary Abstract Inspector)is a static analyzer for automated reverse engineering and scanning vulnerabilities in binaries, which is a long-term research project incubated at Keenlab.
https://github.com/KeenSecurityLab/BinAbsInspector
πŸ—£keen_lab


πŸŽ–@malwr
jadx 1.3.5 got this cool split view now so you can view multiple decompilations at once!

https://github.com/skylot/jadx/releases/tag/v1.3.5
πŸ—£leonjza


πŸŽ–@malwr
🀩2πŸ‘1πŸŽ‰1
You can plant an undetectable backdoor in any deep learning model
https://arxiv.org/abs/2204.06974
πŸ—£neuroecology


πŸŽ–@malwr