hashlookup-forensic-analyser version 1.3 - including Bloom filter improvements and bugs fixed
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
GitHub
Release hashlookup-forensic-analyser version 1.3 - including Bloom filter improvements and bugs fixed · hashlookup/hashlookup-forensic…
hashlookup-forensic-analyser version 1.3 - including Bloom filter improvements and bugs fixed. You can now specify the hash algorithm used for the Bloom filter sets.
Thanks to Jens Hubler for the c...
Thanks to Jens Hubler for the c...
Misuse of Windows Projected File System (ProjFS) proof-of-concept - A file provided by ProjFS changing its content depends on who's asking. File "contains" a full path to the asking process image... EDR file telemetry hoovers broken in 3..2..
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
GitHub
PSBits/ProjFS at master · gtworek/PSBits
Simple (relatively) things allowing you to dig a bit deeper than usual. - gtworek/PSBits
New SEC Cybersecurity Rules: What You Need to Know
The US Securities and Exchange Commission (SEC) recently adopted rules regarding mandatory cybersecurity disclosure. Explore what this announcement means for you and your organization.
https://www.trendmicro.com/en_us/research/23/h/sec-cybersecurity-rules-2023.html
🎖@malwr
The US Securities and Exchange Commission (SEC) recently adopted rules regarding mandatory cybersecurity disclosure. Explore what this announcement means for you and your organization.
https://www.trendmicro.com/en_us/research/23/h/sec-cybersecurity-rules-2023.html
🎖@malwr
Trend Micro
New SEC Cybersecurity Rules: What You Need to Know
[P2O Vancouver 2023 SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955)](https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-chain/)
🗣scopedsecurity
🎖@malwr
🗣scopedsecurity
🎖@malwr
STAR Labs
[P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955)
Brief I may have achieved successful exploitation of a SharePoint target during Pwn2Own Vancouver 2023. While the live demonstration lasted only approximately 30 seconds, it is noteworthy that the process of discovering and crafting the exploit chain consumed…
Malware News pinned «Guys with premium telegram account, boost please: https://t.me/malwr?boost»
Samples come as clean by AV but have hundreds of malicious & suspicious indicators
Hi, I just reinstalled but still I have suspicious files that come undetected by AV but have 100s of malicious / suspicious indicators
Anyone care to look at the hybrid-analysis.com results for example in the correct path and location
a few others saved here:
https://gist.github.com/SkyN9ne/f8d21a2438e33733f1bb3e61e7222096
Look at for example the "Incredibuild"
🗣Skyline9Time
I'll add that isn't it weird that for example the Nvidia nvdispco64.exe says hash not seen before? so are many other files I'd expect the hashes to be in the DB
👤Skyline9Time
🎖@malwr
Hi, I just reinstalled but still I have suspicious files that come undetected by AV but have 100s of malicious / suspicious indicators
Anyone care to look at the hybrid-analysis.com results for example in the correct path and location
nvdispco64.exeanalysis: https://hybrid-analysis.com/sample/a02854e9615b6c7fee43508693dc4e795ae4938d42048aa1c19e98fa6e7b5d67/650e4c54983ef2e7cc04c7e3#mitre-matrix-modal
a few others saved here:
https://gist.github.com/SkyN9ne/f8d21a2438e33733f1bb3e61e7222096
Look at for example the "Incredibuild"
install.exementioned last on my Gist.... It was in my VS Code Insiders folder. The CPUInfo.exe and MailSpawn.exe were in the same directory. I just recently reinstalled, haven't downloaded anything but actual Visual Studio related development tools etc... no cracks, never ran a game on my PC in my life and again these come AV clean but are they not suspicious in your opinion?
🗣Skyline9Time
I'll add that isn't it weird that for example the Nvidia nvdispco64.exe says hash not seen before? so are many other files I'd expect the hashes to be in the DB
👤Skyline9Time
🎖@malwr
❤1
25th September – Threat Intelligence Report
https://research.checkpoint.com/2023/25th-september-threat-intelligence-report/
🎖@malwr
https://research.checkpoint.com/2023/25th-september-threat-intelligence-report/
🎖@malwr
Check Point Research
25th September – Threat Intelligence Report - Check Point Research
For the latest discoveries in cyber research for the week of 25th September, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES Monti ransomware gang has claimed responsibility for a cyber-attack on New Zealand’s third-largest university…
Malware News pinned «Guys with premium telegram account, boost please: https://t.me/malwr?boost»