Dissecting Windows Malware Series – Understanding Cryptography and Data Encoding – Part 3
https://8ksec.io/dissecting-windows-malware-series-understanding-cryptography-and-data-encoding-part-3/
🎖@malwr
https://8ksec.io/dissecting-windows-malware-series-understanding-cryptography-and-data-encoding-part-3/
🎖@malwr
8kSec
Windows Malware Part 3: Cryptography & Encoding | 8kSec
Learn how malware uses encryption like AES and encoding like Base64 to hide its functionality. Part 3 of the Windows malware series.
👍2
GitLab XSS Via Autocomplete Results
Overview The SonicWall Capture Labs threat research team became aware of a cross-site scripting vulnerability in GitLab, assessed its impact and developed mitigation measures. GitLab, an open-source code-sharing platform, published an advisory on this vulnerability
https://blog.sonicwall.com/en-us/2024/04/gitlab-xss-via-autocomplete-results/
🎖@malwr
Overview The SonicWall Capture Labs threat research team became aware of a cross-site scripting vulnerability in GitLab, assessed its impact and developed mitigation measures. GitLab, an open-source code-sharing platform, published an advisory on this vulnerability
https://blog.sonicwall.com/en-us/2024/04/gitlab-xss-via-autocomplete-results/
🎖@malwr
Getting Started with dnSpyEx - Unraveling a .NET Formbook Dropper - YouTube
In this video, I'll show you the basics of the dnSpyEx interface and discuss techniques for performing effective static and dynamic analysis. We'll use a rec...
https://youtu.be/LCxdCn9exbQ?si=P_UlgzbEv571cGJ-
🎖@malwr
In this video, I'll show you the basics of the dnSpyEx interface and discuss techniques for performing effective static and dynamic analysis. We'll use a rec...
https://youtu.be/LCxdCn9exbQ?si=P_UlgzbEv571cGJ-
🎖@malwr
YouTube
Getting Started with dnSpyEx - Unraveling a .NET Formbook Dropper
In this video, I'll show you the basics of the dnSpyEx interface and discuss techniques for performing effective static and dynamic analysis. We'll use a recent Formbook malware sample for this demo and unravel several stages of obfuscation to find the primary…
microsoft/MS-DOS: The original sources of MS-DOS 1.25, 2.0, and 4.0 for reference purposes
https://github.com/microsoft/MS-DOS
🎖@malwr
https://github.com/microsoft/MS-DOS
🎖@malwr
GitHub
GitHub - microsoft/MS-DOS: The original sources of MS-DOS 1.25, 2.0, and 4.0 for reference purposes
The original sources of MS-DOS 1.25, 2.0, and 4.0 for reference purposes - microsoft/MS-DOS
👍1
Investigating Industrial Control Systems using Microsoft’s ICSpector open-source framework - Microsoft Community Hub
Industrial Control Systems (ICS) security has been a subject of research for many years, spurred, in part, by recent state-sponsored ICS-targeting malware
https://techcommunity.microsoft.com/t5/security-compliance-and-identity/investigating-industrial-control-systems-using-microsoft-s/ba-p/4120580
🎖@malwr
TECHCOMMUNITY.MICROSOFT.COM
Investigating Industrial Control Systems using Microsoft’s ICSpector open-source framework | Microsoft Community Hub
Microsoft released ICSpector as an open-source framework to help organizations secure their industrial control systems. Read our blog post for details on...
Brokewell – Unknown Malware family Discovered to target Banking Applications
Brokewell is a new mobile malware targeting the banking industry. It includes a dropper with Android 13+ bypass capability. Victims are lured through phishing pages posing as browser updates. The malware can steal data, control devices remotely, and has specific commands for actions. The threat actor, identified as "Baron Samedit," also developed a bypass tool. Threat Fabric has published a comprehensive report on this malware.
https://hackhunting.com/2024/04/26/brokewell-unknown-malware-family-discovered-to-target-banking-applications/
🎖@malwr
Brokewell is a new mobile malware targeting the banking industry. It includes a dropper with Android 13+ bypass capability. Victims are lured through phishing pages posing as browser updates. The malware can steal data, control devices remotely, and has specific commands for actions. The threat actor, identified as "Baron Samedit," also developed a bypass tool. Threat Fabric has published a comprehensive report on this malware.
https://hackhunting.com/2024/04/26/brokewell-unknown-malware-family-discovered-to-target-banking-applications/
🎖@malwr
Zombieware: Malware That Never Dies...
Self-replicating malware, long abandoned by its operators, continues to contribute significant volume and noise to malware feeds. We investigate this trend, which we refer to as Zombieware.
https://blog.unpac.me/2024/04/25/zombieware/
🎖@malwr
Self-replicating malware, long abandoned by its operators, continues to contribute significant volume and noise to malware feeds. We investigate this trend, which we refer to as Zombieware.
https://blog.unpac.me/2024/04/25/zombieware/
🎖@malwr
UNPACME
Zombieware: Malware That Never Dies...
Self-replicating malware, long abandoned by its operators, continues to contribute significant volume and noise to malware feeds. We investigate this trend, which we refer to as Zombieware.
ElliotKillick/windows-vs-linux-loader-architecture: Side-by-side comparison of the Windows and Linux (GNU) Loaders
https://github.com/ElliotKillick/windows-vs-linux-loader-architecture#the-root-of-dllmain-problems
🎖@malwr
https://github.com/ElliotKillick/windows-vs-linux-loader-architecture#the-root-of-dllmain-problems
🎖@malwr
GitHub
GitHub - ElliotKillick/operating-system-design-review: Operating System Design Review: A systematic analysis of modern systems…
Operating System Design Review: A systematic analysis of modern systems architecture - ElliotKillick/operating-system-design-review
HexaCluster/pgdsat: PostgreSQL Database Security Assessment Tool
https://github.com/HexaCluster/pgdsat
🎖@malwr
https://github.com/HexaCluster/pgdsat
🎖@malwr
GitHub
GitHub - HexaCluster/pgdsat: PostgreSQL Database Security Assessment Tool
PostgreSQL Database Security Assessment Tool. Contribute to HexaCluster/pgdsat development by creating an account on GitHub.
securityjoes/MasterParser: MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
https://github.com/securityjoes/MasterParser
🎖@malwr
https://github.com/securityjoes/MasterParser
🎖@malwr
GitHub
GitHub - securityjoes/MasterParser: MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs - securityjoes/MasterParser
luijait/DarkGPT: DarkGPT is an OSINT assistant based on GPT-4-200K (recommended use) designed to perform queries on leaked databases, thus providing an artificial intelligence assistant that can be useful in your traditional OSINT processes.
https://github.com/luijait/DarkGPT
🎖@malwr
https://github.com/luijait/DarkGPT
🎖@malwr
Embed A Malicious Executable in a Normal PDF or EXE | by Sam Rothlisberger | Medium
Today we’re going to show how to create a malicious executable that looks like a PDF, word doc, or web browser executable with the functionality of the normal file/program, but also our embedded…
https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e
🎖@malwr
Today we’re going to show how to create a malicious executable that looks like a PDF, word doc, or web browser executable with the functionality of the normal file/program, but also our embedded…
https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e
🎖@malwr
Medium
Embed A Malicious Executable in a Normal PDF or EXE
DISCLAIMER: Using these tools and methods against hosts that you do not have explicit permission to test is illegal. You are responsible…
login-securite/lsassy: Extract credentials from lsass remotely
https://github.com/login-securite/lsassy
🎖@malwr
https://github.com/login-securite/lsassy
🎖@malwr
GitHub
GitHub - login-securite/lsassy: Extract credentials from lsass remotely
Extract credentials from lsass remotely. Contribute to login-securite/lsassy development by creating an account on GitHub.
Nightmare: One Byte to ROP // Deep Dive Edition - HackMD
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho
https://hackmd.io/@pepsipu/ry-SK44pt
🎖@malwr
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho
https://hackmd.io/@pepsipu/ry-SK44pt
🎖@malwr
HackMD
Nightmare: One Byte to ROP // Deep Dive Edition - HackMD
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho
obhq/jailbreak-11: Experimental PS4 jailbreak for 11.00 and lower
https://github.com/obhq/jailbreak-11
🎖@malwr
https://github.com/obhq/jailbreak-11
🎖@malwr
GitHub
GitHub - obhq/jailbreak-11: Experimental PS4 jailbreak for 11.00 and lower
Experimental PS4 jailbreak for 11.00 and lower. Contribute to obhq/jailbreak-11 development by creating an account on GitHub.
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.
https://www.huntandhackett.com/blog/hunting-for-a-sliver
🎖@malwr
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.
https://www.huntandhackett.com/blog/hunting-for-a-sliver
🎖@malwr
Huntandhackett
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.
Debugging Stop 0x76 – PROCESS_HAS_LOCKED_PAGES | Machines Can Think
PROCESS_HAS_LOCKED_PAGES (76) Caused by a driver not cleaning up correctly after an I/O. Arguments: Arg1: 0000000000000000, Locked memory pages found in process being terminated. Arg2: fffffa800b1a4060, Process address. Arg3: 0000000000000004, Number of locked pages. Arg4: 0000000000000000, Pointer to driver stacks (if enabled) or 0 if not. Issue a !search over all of physical memory for…
https://bsodtutorials.wordpress.com/2024/04/10/debugging-stop-0x76-process_has_locked_pages/
🎖@malwr
Machines Can Think
Debugging Stop 0x76 – PROCESS_HAS_LOCKED_PAGES
PROCESS_HAS_LOCKED_PAGES (76) Caused by a driver not cleaning up correctly after an I/O. Arguments: Arg1: 0000000000000000, Locked memory pages found in process being terminated. Arg2: fffffa800b1a…
❤1👍1
From IcedID to Dagon Locker Ransomware in 29 Days
https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/
🎖@malwr
https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/
🎖@malwr
👍1
The Darkgate Menace: Leveraging Autohotkey & Attempt to Evade Smartscreen
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/the-darkgate-menace-leveraging-autohotkey-attempt-to-evade-smartscreen/
🎖@malwr
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/the-darkgate-menace-leveraging-autohotkey-attempt-to-evade-smartscreen/
🎖@malwr
McAfee Blog
The Darkgate Menace: Leveraging Autohotkey & Attempt to Evade Smartscreen | McAfee Blog
Authored by Yashvi Shah, Lakshya Mathur and Preksha Saxena McAfee Labs has recently uncovered a novel infection chain associated with DarkGate malware.