Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Honeypot agent for malware curation with Siphon
I made this post about a tool a created to fetch the latest samples from threat intelligence platforms.

The tool has had a major upgrade, and now allows you to generate agents to deploy on honeypots, that can monitor folders for file activity (writes, creations).

Agents have exposed API endpoints to query and download indexed samples from, and are interacted with via Mutual TLS - allowing you to interact with it just how you'd interact with other integrations. If you try it out on your infrastructure, feel free to feedback on GitHub!

https://github.com/pygrum/siphon


The 1st sample in the image above represents an example file written to disk in a folder monitored by a Windows agent.
๐Ÿ—ฃpygrum


๐ŸŽ–@malwr
Quishing Triage 101: How to Investigate Suspicious QR Codes in Emails
๐Ÿ—ฃdigicat

Tl;dr- donโ€™t scan it with your phone. Use the tools you normally do.

You can take a screen shot of the email and put it in cyberchef for a quick result.
๐Ÿ‘คLethargicEscapist


๐ŸŽ–@malwr