Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
And if you think you can cope, watch this and follow the steps to see what else you can determine from the sample to add into your report
https://youtu.be/qA0YcYMRWyI
i firstly breaked password with a tool then tryed to analyze the file but couldnt find anything so can sombody help me or at least ive me some instructions to how to nalyze the file and generate a report
Читать полностью…it has a pasword but they didnt given us any password
Читать полностью…I already checked these sources
malshare.com
bazaar.abuse.ch
virusshare.com
virus.exchange i.e vx-underground.org
filescan.io
tria.ge
threat.zone
The Creators of the OSCP Created an Entry-Level Cybersecurity Cert (Full...
https://youtube.com/watch?v=Zq9lLfECiBQ
Is using someone's Nord VPN account safe for my personal data?
In an unknown website provides login credentials, is it face using those accounts
New FedBan
Fed: Libra's Empire
FedAdmin: Libra
User: FU_QiangFU_QiangvFU_QianFU_QiangFU_QiangFU_QiangFU_QiangFU_Qiang FU_QiangFU_QiangvFU_QianFU_QiangFU_QiangFU_QiangFU_QiangFU_Qiang
User ID: 6853190827
Reason: no I dont feel
That doesn’t really add smth to your question..
Читать полностью…It’s typically wise to ask questions directly, as ML, for example, is not a small field. So more context gives ppl an idea of whether they can help you
Читать полностью…If you do not provide internet to your sandbox, you will miss out on the next non-local stages of the malware you are executing. You do have the advantage that the actor does not know you executed the code. With internet you have the inverse: you can get next stages which aren't local, while the actor might see the activity and draw conclusions from it.
If you are running publicly known samples which aren't targeting your (organisation) specifically, its usually not a problem, as you are one of many. If it is a targeted sample, executing it in a sandbox is an indication that the malware was blocked and/or analysed, which means the attack failed. This provides the attacker with information, which you might not want.
There is no right or wrong, its mainly based on your (organisation's) preferences and threat model
https://hurricanelabs.com/blog/malware-triage-dissecting-threats-to-your-security/
Triage the sample first
Even if you don't know how to analyze samples, at least this would give you something to write
Whatever you prefer
And to make things clear, we will not provide answers
Please state clearly what you have done, what you don't understand and what you need guidance on
i was give this file"https://drive.google.com/file/d/1WoLq29kZ42LR1S2xYnpQBrsrqU48WHpg/view"and this try to analyze the file and generate a report that explains in detail what happened.
Читать полностью…set up malwoverview to check from the various free sources
if no results are returned from the free sources, then ask here again and provide the VT link
Can someone help me find these samples
0dff779030691dcacc7e1b55019a4919
7429b59d493c1f8f9c7cccc928340157
is it possible to pentest your own instagram account?
Читать полностью…hi friends, I'm interested in learning about malware. does anyone have any resources or roadmap to learn this?
Читать полностью…Hello ., welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…New FedBan
Fed: Libra's Empire
FedAdmin: Libra
User: Bunny Gone
User ID: 5604124782
Reason: no skids
its simply who have skills of machine learning, yes im i can develop machine learning with this type xxx
Читать полностью…Do you have any pegasus's spy ware tutorials regarding how to download it and use
Читать полностью…Also if you give it internet connection, separate it from your local network and route it via tor network (but that will break things, as it will only accept dns queries and just tcp connections) or some commercial vpn (like nordvpn or any other). Also good way is to use lte modem as dirty internet gateway, you will look less suspicious to the malware owner/operator.
All that effort is for your privacy and security - that malware can start sending spam, ddosing someone, etc. Don't let it use your main internet connection and don't let it connect to other devices in your local network
New FedBan
Fed: Libra's Empire
FedAdmin: Libra
User: ChrisXchange
User ID: 652696127
Reason: no skids