SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group https://www.secureworks.com/blog/supernova-web-shell-deployment-linked-to-spiral-threat-group
Secureworks
SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group
Similarities between the SUPERNOVA activity and a previous compromise of the network suggest that SPIRAL was responsible for both intrusions and reveal information about the threat group.
Clast82 – A new Dropper on Google Play Dropping the AlienBot Banker and MRAT https://research.checkpoint.com/2021/clast82-a-new-dropper-on-google-play-dropping-the-alienbot-banker-and-mrat/
Check Point Research
Clast82 – A new Dropper on Google Play Dropping the AlienBot Banker and MRAT - Check Point Research
Research by: Aviran Hazum, Bohdan Melnykov, Israel Wernik Check Point Research (CPR) recently discovered a new Dropper spreading via the official Google Play store, which downloads and installs the AlienBot Banker and MRAT. This Dropper, dubbed Clast82, utilizes…
nice post » One day short of a full chain: Part 1 - Android Kernel arbitrary code execution https://securitylab.github.com/research/one_day_short_of_a_fullchain_android
Email forensics Analysis https://linuxhint.com/email_forensics_analysis/
Linuxhint
Email forensics Analysis
Email forensic Analysis is used to find the actual sender and receiver of an email, date and time it is received and the info about intermediate devices involved in the delivery of the message. The email has become a primary source of communication for organizations…
How to Perform Symbolic Execution of Mobile Apps with R2Frida & ESILSolve https://www.nowsecure.com/blog/2021/03/10/how-to-perform-symbolic-execution-of-mobile-apps-with-r2frida-esilsolve/
Nowsecure
Perform Symbolic Execution of Mobile Apps with R2Frida & ESILSolve
Learn about the many benefits of ESILSolve and how to harness symbolic execution in the the NowSecure tutorial.
Analysis of an active Telegram malvertising campaign https://suid.ch/research/Telegram_Malware_Analysis.html
Nice write-up of Not Beginners Stack (Zer0pts CTF 2021) » https://litios.github.io/2021/03/11/not-beginners-stack.html
Litios Blog
Not Beginners Stack
WNKKKNW WXxc'...':d0NW W0d:..'cxxdl,..'cx0N NOo;..,lOXW WKkl,..,cxKW WXkl'..;o0N NKxc,..,lkXW WKxc'..:xKW N0xc'..;okXW N0d;..'lkXW N0dc'..:oOXW NOo,..,oON WNOd:'.':xX Kl'..;d0N WXx' .dW Wo 'xX WKxc'..c0 Ko;..,cxKN W0d:..'ckXW WKkl,..,lxKW NOo,..,lON W0l.…
Implementing Direct Syscalls Using Hell’s Gate https://teamhydra.blog/2020/09/18/implementing-direct-syscalls-using-hells-gate/
Team Hydra
Implementing Direct Syscalls Using Hell’s Gate
I first encountered the concept of using direct system calls to bypass user-land API hooking a little more than a year ago when I read a blog post by Cornelis De Pla (@Cn33liz). It is an exce…
Shadrak: a script to generate decompression bomb in various formats https://gitlab.com/brn1337/shadrak
GitLab
prisma / Shadrak · GitLab
Shadrak is a script to generate decompression bomb in various formats.
Old, but gold » Writing a basic Windows debugger https://www.codeproject.com/Articles/43682/Writing-a-basic-Windows-debugger
Codeproject
For those who code
CVE-2020-24581 D-Link DSL-2888A Remote Command Execution https://reconshell.com/cve-2020-24581-d-link-dsl-2888a-remote-command-execution/
VM Detection Tricks, Part 2: Driver Thread Fingerprinting https://labs.nettitude.com/blog/vm-detection-tricks-part-2-driver-thread-fingerprinting/
LRQA Nettitude Labs
VM Detection Tricks, Part 2: Driver Thread Fingerprinting
This year we're documenting a series of new and as-yet undocumented VM detection tricks. These detection tricks will be focused on 64-bit Windows 10 or Windows Server 2019 guests, targeting a variety of VM platforms.
In the first article we investigated…
In the first article we investigated…
1day exploit for chrome CVE-2020-16040 (includes a typer hardening bypass, works for chrome version <= 87.0.4280.88) https://github.com/r4j0x00/exploits/tree/master/CVE-2020-16040
GitHub
exploits/CVE-2020-16040 at master · r4j0x00/exploits
Contribute to r4j0x00/exploits development by creating an account on GitHub.
TryHackMe: DNS Manipulation Walkthrough https://infosecwriteups.com/tryhackme-dns-manipulation-walkthrough-5944bf60f10f
Playing in the (Windows) Sandbox https://research.checkpoint.com/2021/playing-in-the-windows-sandbox/
Check Point Research
Playing in the (Windows) Sandbox - Check Point Research
Research By: Alex Ilgayev Introduction Two years ago, Microsoft released a new feature as a part of the Insiders build 18305 – Windows Sandbox. This sandbox has some useful specifications: Integrated part of Windows 10 (Pro/Enterprise). Runs on top of Hyper…
Exploiting remote DoS vulnerability in my not-so-smart TV https://vavkamil.cz/2021/03/11/exploiting-remote-dos-vulnerability-in-my-not-so-smart-tv/
Kamil Vavra @vavkamil
Exploiting remote DoS vulnerability in my not-so-smart TV
tl;dr: I found a remotely exploitable DoS vulnerability in my “smart” TV in less than two hours after unboxing. I have released full details, including a 0-day PoC exploit.