Malware News
12.7K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Nice blog post on using Qiling framework for automatically unpack ELF executables

https://kernemporium.github.io/posts/unpacking/

#qiling #infosec #reverseengineering #learning
πŸ—£0xor0ne


πŸŽ–@malwr
❀1πŸ‘1
We’ve just published a short #IDAPro tutorial about the #Disassembly window. Watch it now 🌐 https://youtu.be/cgELfAUg8C4

#IDAProTutorials #IDAPro #hexrays #LearningIDA
πŸ—£HexRaysSA


πŸŽ–@malwr
Android Attack: Reversing React Native Applications
https://securityqueens.co.uk/android-attack-reversing-react-native-applications/
πŸ—£pentest_swissky


πŸŽ–@malwr
Happy to announce the release of my JADX dynamic scripting plugin, JADXecute. Now you write and share scripts to automate your Android APK analysis! #ReverseEngineering

https://github.com/LaurieWired/JADXecute
πŸ—£lauriewired


πŸŽ–@malwr
Here's a short blog on using Frida to write and bypass detections for your TTPs. We can use good ol' userland hooking + JavaScript bindings to avoid writing complex kernel code, which lets us quickly develop test cases and improve our techniques.

https://passthehashbrowns.github.io/using-frida-for-rapid-detection-testing
πŸ—£passthehashbrwn


πŸŽ–@malwr
Icicle is a multi architecture emulation framework designed for firmware fuzzing.
Very interesting research work

Paper: https://arxiv.org/pdf/2301.13346.pdf
github repo (pre-release): https://github.com/icicle-emu/icicle

#fuzzing #firmware #infosec #cybersecurity
πŸ—£0xor0ne


πŸŽ–@malwr
❀1
How to Create a Virtual Hacking Lab: The Ultimate Hacker Setup
πŸ—£flacao9

Nice article and how I did my approach to learning. Gotta love VirtualBox.

Another approach too for specific service testing is creating a vuln testbed service using docker. It's a lot lighter than a full VM.
πŸ‘€FolsgaardSE

This is all manual work, which is fine, but you could use the Red Team Attack Lab or the game of thrones lab
πŸ‘€Proud-Tap6586


πŸŽ–@malwr
New YouTube channel with IDAPython tutorial series [wip](https://www.youtube.com/@allthingsida)
πŸ—£0xeb


πŸŽ–@malwr
πŸ‘2
ZeusCloud - an open-source cloud security platform
Sharing something we're in the early innings of developing: https://github.com/Zeus-Labs/ZeusCloud

Have heard from many devops friends that they often get charged w/ managing security. Hope to get your feedback on if this would be helpful!

ZeusCloud is an open-source cloud security platform that thinks like an attacker! ZeusCloud works by:

1. Identifying risks across your cloud environments (e.g. misconfigurations, identity weakness, vulnerabilities, etc.)
2. Prioritizing those risks based on toxic risk combinations an attacker may exploit.
3. Remediating by giving step by step instructions on how to fix the risk findings.
4. Monitoring compliance - track your PCI DSS, SOC 2, GDPR, CIS goals.

So far, we’ve added misconfiguration checks and common identity-based attack paths for AWS. Up next on our roadmap are network/access graph visualizations of your entire cloud environment, vulnerability scanning, and secret scanning!

Check out our GitHub (Licensed Apache 2.0): https://github.com/Zeus-Labs/ZeusCloud

Play around with our Sandbox environment: https://demo.zeuscloud.io

Get Started (free/self-hosted): https://docs.zeuscloud.io/introduction/get-started
πŸ—£VariousAd5147

This looks very cool! Is there a way to add exclusions to rules?
πŸ‘€thescrambler1979

This is quite interesting. I've had something a bit similar in mind but instead I will take a better look and check if I could just contribute here.
πŸ‘€puputtiap

This product is similar to Selefra, https://github.com/selefra/selefra
πŸ‘€Disastrous_Pie7425


πŸŽ–@malwr
What could these mysterious β€œalign” items in the disassembly mean? Igor is here to clarify 🌐 https://hex-rays.com/blog/igors-tip-of-the-week-133-alignment-items/?utm_source=Social-Media-Post&utm_medium=Twitter&utm_campaign=Igor-Tip-133

#IgorsTipOfTheWeek #IDAtips #IDAPro
πŸ—£HexRaysSA


πŸŽ–@malwr
VMware-player-14.1.3-9474260 how can I extract filesystem data from the stored files?
Hi,

So I installed the above version of VMware and it would not run on either my laptop or computer as a result of both not having some features it apparently requires in the hardware/BIOS (virtualisation was enabled however it complained about using an Intel CPU on the laptop. Curiously VirtualBox works fine on both devices. Anyway, is there a means of which I can merely extract all the contents of the saved .vmx machine without manually running the machine? Thanks in advance.
πŸ—£Man_in_the_uk

This is now resolved, for some reason virtual box was able to run it on
my laptop but when posting this whilst trying to do this on a computer
it did not work.
πŸ‘€Man_in_the_uk

OvfTool would do the conversion to *.ovf

https://developer.vmware.com/web/tool/4.5.0/ovf-tool

Personally prefer the VMware products and wish for return of VMware Server for Linux :-)
πŸ‘€tgbauer

OK so having taken the original vmdk files to my brothers computer he can't access via the virtual office box either. So I have to see if there's a way to save the windows seven vm in such a way I can get it to boot up in virtual box. I have read you can transfer a installation from one computer to another but I don't know if the fact a hdd has things like a bootloader will be an issue, any ideas? Thanks for your help.
πŸ‘€Man_in_the_uk


πŸŽ–@malwr