malwareresearch | Unsorted

Telegram-канал malwareresearch - Malware Research

9618

Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033

Subscribe to a channel

Malware Research

You are right. Okay, I will try doing that. Thanks : )

Читать полностью…

Malware Research

Thank you for your input and for taking the time to look into this—I truly appreciate it. ❤️

To clarify, the app requires both devices to be connected to the same network; otherwise, it won’t function. The process also involves enabling Wi-Fi Wireless Debugging on the device you want to mirror, and the app needs to be installed on the second device.

Since I initially couldn’t get the app to work, I contacted the developer via email for assistance. They were very helpful and guided me through the setup process by sharing a screen recording. I also raised concerns about the app’s authenticity and asked whether it transmits any data externally. Here’s what they had to say in response.

Читать полностью…

Malware Research

Hello @iamavu, welcome to the Malware Research group! Please read the pinned message before you post!

Читать полностью…

Malware Research

Thank you, everyone. It feels like a community of truly wonderful and decent people. I wasn't embarrassed or anything; I just didn't want to trouble anyone here with my very basic questions. However, I appreciate your guidance, and I will look into the two links shared above as I continue to learn. Your kind gesture means a lot to me 🙏

Читать полностью…

Malware Research

Domain name is from China.

And here are the scan results from these two websites.

https://mobsf.live/static_analyzer/23b0c4d25dc884213a5f527765d2515c/#providers

https://www.virustotal.com/gui/file/738f7ea63e83fd7b32be42f5b2397490b7bf7c25aaf5e47306bb56b0d6830e50/relations

Читать полностью…

Malware Research

I wouldn't say that it's fine. Depends on what domain name it is

Читать полностью…

Malware Research

I'm asking because I think you don't understand what a .cc TLD indication means (and that's perfectly fine btw)

Читать полностью…

Malware Research

https://github.com/MobSF/Mobile-Security-Framework-MobSF

Читать полностью…

Malware Research

Do you know what a TLD is?

Читать полностью…

Malware Research

So, I downloaded an APK from GitHub. It aims to copy the functionality of scrcpy for mirroring one Android screen to another Android. I used the file before checking it on VirusTotal. Although everything seems okay at first glance, the 'Behavior' tab on the website gives me these warnings:

Matches rule INDICATOR-COMPROMISE: Suspicious .cc DNS query
Matches rule ET DNS Query for .cc TLD

Now, I am afraid that whatever I mirrored while using that application may have been sent to some cloud server. I don't really know. Please don't mind me if this is not the right place for asking such questions.

Читать полностью…

Malware Research

Hello, is link sharing allowed here?

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: Libra
User: гаопе
User ID: 1331514755
Reason: no warez

Читать полностью…

Malware Research

User Gloria is already banned in Libra's Empire, with reason:
scam.

Читать полностью…

Malware Research

Hello @hMESrh, welcome to the Malware Research group! Please read the pinned message before you post!

Читать полностью…

Malware Research

who decrypt the server part of a infostealer

Читать полностью…

Malware Research

Well, they didn't answered the question. It is quite strange that it needs to connects to those domains.

If you really want to find the answer, then you will have to reverse engineer the app and read the code.

In the mobsf, there is a link to download java code. Perhaps, you can check the code and search for the domain.

Читать полностью…

Malware Research

scrcpy requires device to connected via usb or via tcp/ip provided that both devices are present in the website.

If it didn't required the devices be connected to usb or be present in same network then there is a good chance that information between the devices were relayed through cloud.

If you access the website v.netsite.cc , it shows login/register page for cloud authentication / minimal card verification. I am not sure what this actually does.

If i have to make a guess then maybe this page is used to login into the cloud

Читать полностью…

Malware Research

I also don't know many things, we all start somewhere, good luck!

Читать полностью…

Malware Research

yeah that's kinda sus

Читать полностью…

Malware Research

What I mean is fine is not knowing what a TLD is. I mean this from the perspective that he seems to be ashamed of not knowing everything, which I think is a bad attitude to have. Never be ashamed or afraid of not knowing everything, and always keep an open mind.

Читать полностью…

Malware Research

https://en.wikipedia.org/wiki/.cc This is what the indication means, something tried to resolve a .cc domain

Читать полностью…

Malware Research

You can try this tool

Читать полностью…

Malware Research

Sorry, I didn't know.
Just googled it. It stands for Top Level Domain.

Читать полностью…

Malware Research

Okay, thanks. I understand.

Читать полностью…

Malware Research

If it is not breaking any rules

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: Libra
User: Dandin Nono
User ID: 1028968560
Reason: no warez

Читать полностью…

Malware Research

The internet has a lot of free software downloads. I'm sure someone on there could help you.

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Gloria González
User ID: 7694614081
Reason: scam

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: percocets
User ID: 1045368389
Reason: None given.

Читать полностью…

Malware Research

Hello, does anyone have a link to the crack version of cobalt strikee?

Читать полностью…
Subscribe to a channel