9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
Does anyone have any idea what backdoors or any persistent access methods they use to get in after some time interval?
Читать полностью…
Anyone have decrytor for Revrac extension ransomeware
Читать полностью…
hello, if i want to trace the steps of an APT group how can i start?
Читать полностью…
User Faith has 2/3 warnings; be careful!
Reason:
irrelevant
https://www.facebook.com/share/v/198TmWSPLa/?mibextid=wwXIfr
Читать полностью…
Reported Seller Boika Leads (Email List) [5001311537] to admins.
https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_shellcode_steganographic
Читать полностью…
Indicator of Compromise
MD5
a2ee8d2aa9f79551eb5dd8f9610ad557
ae7e18a62abb7f93b657276dcae985b9
d5fe744b9623a0cc7f0ef6464c5530da
f6d72abf9ca654a20bbaf23ea1c10a55
fd9099005f133f95a5b699ab30a2f79b
5ed95cde6c29432a4f7dc48602f82734
16a8aaaf2e3125668e6bfb1705a065f9
64d729d0290e2c8ceaa6e38fa68e80e9
443a00feeb3beaea02b2fbcd4302a3c9
e13c3a38ca58fb0fa9da753e857dd3d5
e4813c34fe2327de1a94c51e630213d1
If you want to get any sample, provide a hash for it
Читать полностью…
the most common way to find malware samples is via hashes
to find the hash, you usually make use of reports and search for them in the various malware databases to download a sample for analysis
other ways to do it are via Yara rules and tags
Anyone can let me know where I can find the rokrat.
Читать полностью…
Unfortunately it's not that simple. You simply can't distinguish adequate usage vs malicious
Читать полностью…
User Rose has been kicked from the chat because this user is in spam list
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Vibhore Sengupta
User ID: 8024304955
Reason: scam
Reported Faith Olagunju [7069819306] to admins.
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Seller Boika Leads (Email List)
User ID: 5001311537
Reason: None given.
I'm giving you 3 methods to find the samples
1. Use hashes and search for them in free malware databases
2. Use Yara rules to find matching samples
3. Use tags to find matching samples
and of all the methods, the first one is the most common and the easiest, and if you read earlier messages, most people simply provide a hash and samples will then be provided
if you still don't understand, I suggest you read up on hashes (typically parked under a section called "indicators of compromise") and their relevance to malware
and this is the one of the starting steps to malware research
I didn't get it. Rokrat is latest banking trojan
Читать полностью…
189b15627dea7a122671417242420d0c6afc8601b599444518dc3f4efaf7a12e- https://hybrid-analysis.com/sample/189b15627dea7a122671417242420d0c6afc8601b599444518dc3f4efaf7a12e
b5f581a12ba082d9fb82d4c896ecda0cc3173194e74b1162b0a22681cc88ab2b - as attached
Hello everyone, can you help me find these samples:
189b15627dea7a122671417242420d0c6afc8601b599444518dc3f4efaf7a12e
b5f581a12ba082d9fb82d4c896ecda0cc3173194e74b1162b0a22681cc88ab2b
Yeah I get that it was more of a joke than a serious suggestion, but a lot of respect for the effort
Читать полностью…
You should make a telegram bot that auto bans certain names with keywords like "Lead". It'll save you decades of banning...
Читать полностью…