securityjoes/MasterParser: MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
https://github.com/securityjoes/MasterParser
π@malwr
https://github.com/securityjoes/MasterParser
π@malwr
GitHub
GitHub - securityjoes/MasterParser: MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs - securityjoes/MasterParser
luijait/DarkGPT: DarkGPT is an OSINT assistant based on GPT-4-200K (recommended use) designed to perform queries on leaked databases, thus providing an artificial intelligence assistant that can be useful in your traditional OSINT processes.
https://github.com/luijait/DarkGPT
π@malwr
https://github.com/luijait/DarkGPT
π@malwr
Embed A Malicious Executable in a Normal PDF or EXE | by Sam Rothlisberger | Medium
Today weβre going to show how to create a malicious executable that looks like a PDF, word doc, or web browser executable with the functionality of the normal file/program, but also our embeddedβ¦
https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e
π@malwr
Today weβre going to show how to create a malicious executable that looks like a PDF, word doc, or web browser executable with the functionality of the normal file/program, but also our embeddedβ¦
https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e
π@malwr
Medium
Embed A Malicious Executable in a Normal PDF or EXE
DISCLAIMER: Using these tools and methods against hosts that you do not have explicit permission to test is illegal. You are responsibleβ¦
login-securite/lsassy: Extract credentials from lsass remotely
https://github.com/login-securite/lsassy
π@malwr
https://github.com/login-securite/lsassy
π@malwr
GitHub
GitHub - login-securite/lsassy: Extract credentials from lsass remotely
Extract credentials from lsass remotely. Contribute to login-securite/lsassy development by creating an account on GitHub.
googleprojectzero/fuzzilli: A JavaScript Engine Fuzzer
https://github.com/googleprojectzero/fuzzilli
π@malwr
https://github.com/googleprojectzero/fuzzilli
π@malwr
GitHub
GitHub - googleprojectzero/fuzzilli: A JavaScript Engine Fuzzer
A JavaScript Engine Fuzzer. Contribute to googleprojectzero/fuzzilli development by creating an account on GitHub.
Nightmare: One Byte to ROP // Deep Dive Edition - HackMD
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho
https://hackmd.io/@pepsipu/ry-SK44pt
π@malwr
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho
https://hackmd.io/@pepsipu/ry-SK44pt
π@malwr
HackMD
Nightmare: One Byte to ROP // Deep Dive Edition - HackMD
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho
obhq/jailbreak-11: Experimental PS4 jailbreak for 11.00 and lower
https://github.com/obhq/jailbreak-11
π@malwr
https://github.com/obhq/jailbreak-11
π@malwr
GitHub
GitHub - obhq/jailbreak-11: Experimental PS4 jailbreak for 11.00 and lower
Experimental PS4 jailbreak for 11.00 and lower. Contribute to obhq/jailbreak-11 development by creating an account on GitHub.
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.
https://www.huntandhackett.com/blog/hunting-for-a-sliver
π@malwr
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.
https://www.huntandhackett.com/blog/hunting-for-a-sliver
π@malwr
Huntandhackett
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.
Debugging Stop 0x76 β PROCESS_HAS_LOCKED_PAGES | Machines Can Think
PROCESS_HAS_LOCKED_PAGES (76) Caused by a driver not cleaning up correctly after an I/O. Arguments: Arg1: 0000000000000000, Locked memory pages found in process being terminated. Arg2: fffffa800b1a4060, Process address. Arg3: 0000000000000004, Number of locked pages. Arg4: 0000000000000000, Pointer to driver stacks (if enabled) or 0 if not. Issue a !search over all of physical memory forβ¦
https://bsodtutorials.wordpress.com/2024/04/10/debugging-stop-0x76-process_has_locked_pages/
π@malwr
Machines Can Think
Debugging Stop 0x76 β PROCESS_HAS_LOCKED_PAGES
PROCESS_HAS_LOCKED_PAGES (76) Caused by a driver not cleaning up correctly after an I/O. Arguments: Arg1: 0000000000000000, Locked memory pages found in process being terminated. Arg2: fffffa800b1aβ¦
β€1π1
From IcedID to Dagon Locker Ransomware in 29 Days
https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/
π@malwr
https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/
π@malwr
π1
The Darkgate Menace: Leveraging Autohotkey & Attempt to Evade Smartscreen
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/the-darkgate-menace-leveraging-autohotkey-attempt-to-evade-smartscreen/
π@malwr
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/the-darkgate-menace-leveraging-autohotkey-attempt-to-evade-smartscreen/
π@malwr
McAfee Blog
The Darkgate Menace: Leveraging Autohotkey & Attempt to Evade Smartscreen | McAfee Blog
Authored by Yashvi Shah, Lakshya Mathur and Preksha Saxena McAfee Labs has recently uncovered a novel infection chain associated with DarkGate malware.
Android Remote Access Trojan Equipped to Harvest Credentials
Overview The SonicWall Capture Labs threat research team has been regularly sharing information about malware targeting Android devices. Weβve encountered similar RAT samples before, but this one includes extra commands and phishing attacks designed to
https://blog.sonicwall.com/en-us/2024/04/android-remote-access-trojan-equipped-to-harvest-credentials/
π@malwr
Overview The SonicWall Capture Labs threat research team has been regularly sharing information about malware targeting Android devices. Weβve encountered similar RAT samples before, but this one includes extra commands and phishing attacks designed to
https://blog.sonicwall.com/en-us/2024/04/android-remote-access-trojan-equipped-to-harvest-credentials/
π@malwr
Advanced Frida Usage Part 9 β Memory Scanning in Android
https://8ksec.io/advanced-frida-usage-part-9-memory-scanning-in-android/
π@malwr
https://8ksec.io/advanced-frida-usage-part-9-memory-scanning-in-android/
π@malwr
8kSec
Frida Part 9: Memory Scanning in Android | 8kSec
Learn about Frida's Memory.scan() API for scanning and patching bytes in Android process memory. Covers pattern matching and practical patching.
SideCopy: A Threat Actor targeting Indian Defense and Armed Forces Personnel for a Long Time
There have been several instances where Pakistani threat actors targeted the Indian Government and allied organizations for cyber espionage and other malicious activities. One such threat activity is the Operation SideCopy in which the threat actors had been specifically targeting Indian Defense and Army Forces personnel since 2019. These threat actors have been evolving continuously [β¦]
https://hackhunting.com/2024/04/30/sidecopy-a-threat-actor-targeting-indian-defense-and-armed-forces-personnel-for-a-long-time/
π@malwr
There have been several instances where Pakistani threat actors targeted the Indian Government and allied organizations for cyber espionage and other malicious activities. One such threat activity is the Operation SideCopy in which the threat actors had been specifically targeting Indian Defense and Army Forces personnel since 2019. These threat actors have been evolving continuously [β¦]
https://hackhunting.com/2024/04/30/sidecopy-a-threat-actor-targeting-indian-defense-and-armed-forces-personnel-for-a-long-time/
π@malwr
Zloader | ThreatLabz
Technical Analysis | Zloader revives an old ZeuS-inspired anti-analysis feature, implementing unique execution restrictions.
https://www.zscaler.com/blogs/security-research/zloader-learns-old-tricks
π@malwr
Technical Analysis | Zloader revives an old ZeuS-inspired anti-analysis feature, implementing unique execution restrictions.
https://www.zscaler.com/blogs/security-research/zloader-learns-old-tricks
π@malwr
Zscaler
Zloader | ThreatLabz
Technical Analysis | Zloader revives an old ZeuS-inspired anti-analysis feature, implementing unique execution restrictions.
(The) Postman Carries Lots of Secrets β Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, itβs become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a variety of popular SaaS and cloud providers.
https://trufflesecurity.com/blog/postman-carries-lots-of-secrets
π@malwr
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, itβs become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a variety of popular SaaS and cloud providers.
https://trufflesecurity.com/blog/postman-carries-lots-of-secrets
π@malwr
Trufflesecurity
(The) Postman Carries Lots of Secrets β Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, itβs become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for aβ¦
Identifying X-Refs with Capstone | 0ffset Training Solutions
In this post, I will explain how you can locate cross references programmatically using Python modules that are generally helpful in reverse engineering.
https://www.0ffset.net/reverse-engineering/identifying-xrefs-with-capstone/
π@malwr
In this post, I will explain how you can locate cross references programmatically using Python modules that are generally helpful in reverse engineering.
https://www.0ffset.net/reverse-engineering/identifying-xrefs-with-capstone/
π@malwr
0ffset Training Solutions | Practical and Affordable Cyber Security Training
Identifying X-Refs with Capstone | 0ffset Training Solutions
In this post, I will explain how you can locate cross references programmatically using Python modules that are generally helpful in reverse engineering.
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.
https://www.trendmicro.com/en_us/research/24/e/router-roulette.html
π@malwr
This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.
https://www.trendmicro.com/en_us/research/24/e/router-roulette.html
π@malwr
Trend Micro
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.
Docker Hub Hosted a Massive 3 Million Imageless Repositories for Phishing Campaigns
Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty repositories, with 2.81 million used for malware campaigns. Threat actors used metadata to redirect users to deceptive websites. Users are advised to use "Trusted Content" docker repositories to avoid these attacks.
https://hackhunting.com/2024/05/01/docker-hub-hosted-a-massive-3-million-imageless-repositories-for-phishing-campaigns/
π@malwr
Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty repositories, with 2.81 million used for malware campaigns. Threat actors used metadata to redirect users to deceptive websites. Users are advised to use "Trusted Content" docker repositories to avoid these attacks.
https://hackhunting.com/2024/05/01/docker-hub-hosted-a-massive-3-million-imageless-repositories-for-phishing-campaigns/
π@malwr
HACKHUNTING
Docker Hub Hosted a Massive 3 Million Imageless Repositories for Phishing Campaigns
Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty reposβ¦