malwareresearch | Unsorted

Telegram-канал malwareresearch - Malware Research

9687

Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033

Subscribe to a channel

Malware Research

does anyone have any sample of this rootkit? (snapekit)
https://x.com/GenThreatLabs/status/1841482299558215698

Читать полностью…

Malware Research

Has anyone seen or heard about threat actor targetting a security researcher because they published a piece about their activities?

Читать полностью…

Malware Research

Anyone know Is it possible to download this sample?
https://www.virustotal.com/gui/file/c8c5d2e0d2a29417c4a89c55c4a0e452b948b1429418eda84be725774504a35c/detection

Читать полностью…

Malware Research

Hello Rakesh, welcome to the Malware Research group! Please read the pinned message before you post!

Читать полностью…

Malware Research

Blog post alert!

This one is about portable executable process injection (T1055.002) as implemented in BugSleep backdoor loader (attributed to MuddyWater). This is an old technique, but I go over why the implementation in the loader is buggy and easily blocked by EDRs.

I think people getting into malware analysis can use this information to learn not only the process injection technique, but also how not to take malware code at face value and to keep an eye out for bugs.

Blog link: https://nikhilh-20.github.io/blog/inject_bugsleep/

Читать полностью…

Malware Research

You can check this fork. It features additional commits that you also might want to examine if you don't trust changes by others than the original author.
https://github.com/digitalsleuth/UnAutoIt

However, if you want to rebuild the binaries yourself, you'll realize the libautoit package is needed. Also, you might have to edit go.mod and some other files. I found a surviving fork with version 1.2.8, dated May 25, 2021.
https://github.com/CrackerCat/libautoit

I used this tool sometime ago and I faced a few bugs. For example, the dump directory is created with wrong permissions on Linux, and the option to set the chunk length to split long literal strings is called "strlit-max" in the help and "max-strsz" in the parser.

Читать полностью…

Malware Research

hint: search Github (log in to Github and search the codes), Google, Bing

Читать полностью…

Malware Research

User Dhiraj has 1/3 warnings; be careful!
Reason:
add context to links

Читать полностью…

Malware Research

ah thank you, this is the actual sample i was referring to, if this helps

Читать полностью…

Malware Research

sorry was that response for me?

Читать полностью…

Malware Research

https://x.com/RandomDhiraj/status/1839717748970021027

Читать полностью…

Malware Research

https://malcat.fr/blog/lnk-forensic-and-config-extraction-of-a-cobalt-strike-beacon/

might still be there, but you likely will need to tinker around till you get it (example in the above link)

Читать полностью…

Malware Research

Checked the .data section, couldnt really find something

Читать полностью…

Malware Research

Guys is it necessary that the config in a cobalt strike beacon is present on the .data section?

Читать полностью…

Malware Research

Hello @httpredsec, welcome to the Malware Research group! Please read the pinned message before you post!

Читать полностью…

Malware Research

Follow-up do you think that it would be better to publish research under a pseudonym or just initials to avoid such situations?

Читать полностью…

Malware Research

Hello JARVIS, welcome to the Malware Research group! Please read the pinned message before you post!

Читать полностью…

Malware Research

Eu estou transmitindo ao vivo! Venha ver! https://k.kwai.com/l/ZKCi0OZd

Читать полностью…

Malware Research

https://github.com/capstone-engine/capstone/releases/tag/6.0.0-Alpha1

Читать полностью…

Malware Research

I'm trying to install the CAPEv2 sandbox, but I'm encountering some confusion or lack of understanding regarding some configuration descriptions used in conf/processing.conf, specifically about the on_demand setting. Does anyone know about this setting and the impact of setting it to on or off?

Читать полностью…

Malware Research

the hash is different though, you really sure it's the same sample?

Читать полностью…

Malware Research

Does anyone have the tool from this GitHub repository: ?I've tried searching for it on the Wayback Machine but couldn't download it. Maybe someone has it. If you do, could I please ask for it? Thank you.

https://github.com/x0r19x91/UnAutoIt/

Читать полностью…

Malware Research

Sorry, I only have a free account, so I can't download samples there

Читать полностью…

Malware Research

https://koodous.com/apks/6c13658a81921f658f660a0f670eb61e9459d8105c1a72910a6bc8abd7795c65/general-information

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: V O I D
User ID: 6809771801
Reason: selling exploits

Читать полностью…

Malware Research

hi everyone, "7ff02fb46009fc96c139c48c28fb61904cc3de60482663631272396c6c6c32ec" sample request, thank you in advance

Читать полностью…

Malware Research

Any help would be appreciated

Читать полностью…

Malware Research

So I found a beacon, and ran some bunch of extractors on the sample turns out they fail on extracting but the detections and memory dump has traces of cobalt strike beacon based artefacts

Читать полностью…

Malware Research

Hello @savi_hash, welcome to the Malware Research group! Please read the pinned message before you post!

Читать полностью…

Malware Research

Hello @Kanaguthara, welcome to the Malware Research group! Please read the pinned message before you post!

Читать полностью…
Subscribe to a channel