Malware News
12.6K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
New polymorphic techniques pushed to Revenant.

Rev now uses the python build script to generate C code at build time, compile randomly different binaries, and combine runtime polymorphic patches to give better obfuscation

Check it out!
https://github.com/0xTriboulet/Revenant

@deadvolvo
πŸ—£0xTriboulet


πŸŽ–@malwr
πŸ”₯1
Nice research by Maciej Domanski (@trailofbits) on cURL command line interface fuzzing and vulnerabilties

https://blog.trailofbits.com/2023/02/14/curl-audit-fuzzing-libcurl-command-line-interface/

#fuzzing
πŸ—£0xor0ne


πŸŽ–@malwr
MinHash-based Code Relationship & Investigation Toolkit (MCRIT), a framework created by the Cyber Analysis & Defense team from Fraunhofer FKIE institute to simplify the application of the MinHash algorithm in the context of code similarity.
https://github.com/fkie-cad/mcritweb
#Botconf2023
πŸ—£Requiem_fr


πŸŽ–@malwr
πŸ”₯2
Reverse Engineering Tofsee Spambot to find vaccine - Malware Lead @RaashidBhatt discloses two vaccines and a network-based kill switch. First up, it's part one, how to inject a malware vaccine into the binary file.πŸ‘‡
https://hubs.ly/Q01LkdrX0

#MalwareVaccine #Spambot #Tofsee
πŸ—£SpamhausTech


πŸŽ–@malwr
Check it out! WinDbg has just released out of preview, out of the Windows store and (what I worked on) with Time Travel Debugging support for ARM64. http://aka.ms/windbg
πŸ—£TheJCAB


πŸŽ–@malwr
πŸ‘1
Revizor automatically detects microarchitectural leakage in CPUs, speeding up discovery of vulnerabilities that previously required persistent hacking and painstaking manual labor. This new tool helps the industry protect customers from risk: https://msft.it/6013gHEGd
πŸ—£MSFTResearch


πŸŽ–@malwr
Celebrating the 10th anniversary of releasing Noriben!

https://github.com/Rurik/Noriben

What started as a way to make filemon/regmon/procmon analysis easier for work mentoring has turned into an awesome automated tool I've used for large-scale ransomware analysis, and more.
πŸ—£bbaskin


πŸŽ–@malwr
IOCs available...

Threat actors strive to cause Tax Day headaches https://rodtrent.com/j7j

#MicrosoftSentinel #MicrosoftDefender #M365D #Cybersecurity #MicrosoftSecurity #Security #MicrosoftThreatIntelligence
πŸ—£rodtrent


πŸŽ–@malwr
😁1
βœ…βœ…βœ… Forward posts to the other groups βœ…βœ…βœ…
Malware News pinned Β«βœ…βœ…βœ… Forward posts to the other groups βœ…βœ…βœ…Β»
LIEF v0.13.0 is out:

https://lief-project.github.io/blog/2023-04-09-lief-0-13-0/
πŸ—£LIEF_project


πŸŽ–@malwr