9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
you did not read, and simply reply you can do it?
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: V ACS
User ID: 1874467154
Reason: haxor
here's somewhere to start - https://github.com/hslatman/awesome-threat-intelligence
many of them will have API calls to perform automation
How do I check if this file has maleware I scanned it with virus total didn’t get anything
Читать полностью…
You create or gather a rule for each family, build an app that scans the drivers or what you want to scan to detect the malwares on it
Читать полностью…
Need to develop a script which will fetch the malware related information from any channels which update malwares which come up daily around the globe.
Currently working as intern in cybersecurity company and this script work is assigned so needed help regarding how go find these kind of channels...tried surfing internet couldn't get any so thought this community may help
Hi @all
I needed a help.
Is there any telegram channel which updates the malwares which come up on daily basis? Needed this for one of my project
I usually start with DIE, strings/floss and capa for initial analysis
The rest depends on the above analysis. Most common tools I use are ILSpy, Cyberchef and PowerShell
What programs do you actually recommend for static analysis?
Читать полностью…
looking at its strings, it looks suspicious (clipboard activities), debugging, window hiding
while it's an ELF file, it has strings related to Android, so it may not be meant for Linux systems, but for Android
quick look at the strings + potential to be used in Android would suggest infostealer malware
User Abhi has 1/3 warnings; be careful!
Reason:
stay on topic and add description to links
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: X
User ID: 1620772772
Reason: haxor
run it in a sandbox, run it in a VM, reverse engineer the file
Читать полностью…
0e1eae76d9b4c6fc2ba625577653f551cf5eaaeb79d0f2f126349dad2d437bc4
I think this Yara rule
Read about it or watch the series for it on oalabs channel in YouTube
Hi team, Please help on this sample:https://www.virustotal.com/gui/file/9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 thank you!
Читать полностью…
https://chatgpt.com/share/6a3b79df-f758-83ec-9e20-ed54c9b5d0dd
asked ChatGPT out of fun, keeping mind open about this
not gonna do more work on this. you should do it yourself
Writeup: Analysis and reverse engineering of variant of a PolinRider npm package - Dead drops on the blockchain
https://meltedinhex.com/posts/polinrider-blockchain-dead-drop-npm/
I thought I wasn't breaking any rules, but I'm deleting it just in case.
Читать полностью…
Hello @Mukopadhyay_23, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…