9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
I'm unable to find the source code about Pegasus. It was really impressive. Pegasus was zero click rat.
There's a curiosity about that.
Does anyone know about Pegasus?
anyone could guide me about the zero click exploit or one tap rat.
And it must be working for both iOS and Android.
Basically I am new to this the sandbox is developed by my company and right now I am testing it by executing different different malware and I am checking the level of accuracy I have no idea about the backend and what criteria they are following i get instruction that I have to test it and check the accuracy level and make a report regarding it
Читать полностью…
User Kin has 1/3 warnings; be careful!
Reason:
language in chat is English. Read rules
Exactly. Fresh hashes are useful only after we define whether the test is about a family, a behaviour or an evasion technique. Otherwise "new" does too much work.
Читать полностью…
Define "new"?
Commodity malware like Agent Tesla, Vidar have thousands of hashes daily and you can pull it from Malware Bazaar via API
Malware that gets caught by generic rules but belonging to another family or new family is another thing
For a sandbox test, I would use curated samples with known behaviour and keep the lab disposable and isolated. What signal do you need to validate first?
Читать полностью…
hey i am threat hunter and i am testing my sandbox so i want some new malware sample to test my sandbox so any one can help me with that
Читать полностью…
Could someone please help me download this sample?f1246fd6af3a426fed75a23618b2e78f47864d7687d750b6f40c752cc06107f6
almost every malware has similar observable behaviour. How do you based on those determine the family?
almost every malware will persist, has network activity, makes system changes for all kinds of reasons
if I observe this in this malware A, then do I assign it to family A, B, or C?
It's an old beast, well known and researched
Читать полностью…
How to build one tap rat or zero click.
And how it works
You submitted the same malware on different sandboxes and got different results, so you want different samples to test?
What's this logic?
Please explain what you are trying to do
This is site which describes how not to do and why not to do that.
Читать полностью…
Why i want new malware is when ever I try to test the malewrebaazar files the sand box gives the verdict my matching hash value but when ever I try use different platform malware sample I get totally different verdict that's why I need new Malware sample
Читать полностью…
/warn language in chat is English. Read rules
Читать полностью…
He asked for new samples
You can pull thousands of new samples from Malware Bazaar, but they are all likely from the same few families and that may not mean "new" to him
So it's important to clarify what is "new"
It can be considered if there's enough time to do so
Читать полностью…
A sample request is easier to assess when it includes the research question and the handling plan, not only a hash. That helps people decide whether sharing is appropriate and makes the result easier to reproduce.
Читать полностью…
Generic persistence and network activity are triage signals, not a family label. I would keep it unknown until more specific evidence lines up, such as code lineage or a distinctive configuration format. The important thing is to separate what was observed from what was inferred.
Читать полностью…
Before assigning a malware family, I prefer to record the observable behaviour first: persistence, network activity and file changes. What early evidence has proved most reliable for others here?
Читать полностью…