9630
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
nothing is better then using and messing with it and reading some books and arch, gentoo wiki and Linux documentation can help you
Читать полностью…
wdym by roadmap, just learn linux if you want to administrate it i guess
Читать полностью…
Is their any Linux or network admins in this group?
Читать полностью…
A Chinese-founded company, Zoom, illegally provided user privacy to the U.S. government
Twitter:Stephen_H1487/status/1796384382330269981
If anyone is proficient in Android, I recently had possible malloc vulns being exploited against one of my phones through the X app.
Читать полностью…
Who knows how to remove this malware that switches crypto wallet addresses from a windows machine when they are copied
Читать полностью…
And also am checking on my main machine so I can run the script with no concern
Читать полностью…
because a JS file for the browser doesn't execute the same (or at all) in a random sandbox
Читать полностью…
Somehow when I submit the hash on vt nothing comes back
Читать полностью…
if you start from the domain search itself, it has a JS, then the JS leads to your file, it redirects again or downloads more JS
Читать полностью…
User Linda has 1/3 warnings; be careful!
Reason:
stay on topic
Hello everyone.
Can anyone advise how to remove vmprotected 3.6.0 obfuscation from the .sys (rootkit) file and debug it ?
In case someone wants to have a look I can send you the logs.
Читать полностью…
HiJackThis+ with boot from Safe Mode, UVs, or FRST, if you knowledgeable enough to analyze the logs. Otherwise, it's better to ask help in special places like BleepingComputers or HJT help section: https://github.com/dragokas/hijackthis/issues . Those clipper is often uses thread injection technique in system processes. If that's Trojan.Win64.Miner.pef those who have access in restricted area at BC may find my research there. I found fork of it it also distributed in X as a propose of beta-tester Web3 job.
Читать полностью…
It simply replaces any wallet address I copy with a different one .
Читать полностью…
A clipper, is what they are called. But without further details, we cant help
Читать полностью…
I found a researcher who has been tracking the same malware. They named it balada injector.
Читать полностью…
Js deobfuscation is a headache. I think pure assembly is better lol
Читать полностью…
Also the traffic is through https. I got no clue how to decrypt that lol. Wayback machine saved the day.
Читать полностью…