Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
New Ransomware Groups on the Rise
๐Ÿ—ฃdigicat


๐ŸŽ–@malwr
Volatility Help - pagefile & hiberfil
Hi all. I've been poking around trying to analyze a pagefile and hiberfil I recovered, but for the life of me, I can't get volatility to play nice with me.
So for starters, I've confirmed via the registry that the processor is AMD64 architecture and that it's Windows 10 19041.1.vbrelease.191206-1406. I've tried using volatility to convert to a raw image (vol -f file.sys imagecopy -O target.raw) and no matter what profile I apply - which, ostensibly should be Win10x6419041 - no plugins will take against it. Not in Volatility 2.6, 3.1, or 3.2. In the latter two, imagecopy is not an available plugin.

I am not sure what I am doing wrong, if I am missing plugins, or what have you, but I would appreciate any guidance. I would buy Arsenal Recon's tools, but that isn't currently an option.
๐Ÿ—ฃKillithidMindslayer

Volatility won't help you out with your pagefile. You're better off trying bulk extractor, Yara, or even strings.
๐Ÿ‘คBad_Grammer_Girl


๐ŸŽ–@malwr
๐Ÿšจ CVE-2022-34502
Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary file.

๐ŸŽ–@cveNotify
IDA Pro 8.0 released!

โ„น๏ธ Golang 1.18
โ„น๏ธ iOS 16 dyld shared cache support
โ„น๏ธ ARC decompiler
โ„น๏ธ Better firmware analysis
โ„น๏ธ FLAIR pattern generator (makepat)

https://hex-rays.com/products/ida/news/8_0/

๐ŸŽ–@cveNotify
๐Ÿคฎ4๐Ÿ˜3
Image displays its own MD5 hash
๐Ÿ—ฃASIC_SP

Absolute noob question incoming... What are some practical uses for this?
๐Ÿ‘คWhatArghThose

There's a mathematical function (maybe in parametric form) whose graph is the "picture of the algebraic equation" of the function itself. I can't find it right now. [not exactly correct, see below\]

EDIT:

Tupper's self-referential formula:

https://en.wikipedia.org/wiki/Tupper%27s_self-referential_formula
๐Ÿ‘คAcrobatic-Cause-4925

See also: This PDF is an NES ROM that prints its own MD5 hash!
๐Ÿ‘คcbarrick


๐ŸŽ–@malwr
๐Ÿ‘1