malwareresearch | Unsorted

Telegram-канал malwareresearch - Malware Research

9687

Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033

Subscribe to a channel

Malware Research

greetings friends, malware sample request, 7d5b6bcc9b93aedc540e76059ee27841a96acb9ea74a51545dfef18b0fcf5b57, 6fc672288e68146930b86c7a3d490f551c8d7a7e8ba3229d64a6280118095bea, 'ad9044d9762453e2813be8ab96b9011efb2f42ab72a0cb26d7f98b9bd1d65965' thank you so much!

Читать полностью…

Malware Research

/warn add context to the link and remove tracking

Читать полностью…

Malware Research

It is a somewhat modular Trojan. If I remember correctly, the server injects a few DEX modules on first request to implement additional commands for uploading or downloading files on the device, exfiltrating SMS data, getting contact list or enabling the microphone, among other things.

Читать полностью…

Malware Research

You could check if the "protocol" depicted in these posts still applies. "Packets" are formed by two ASCII-encoded length values (i.e., you see "510" instead of hex 01 FE in a network trace), each one followed by a null byte, and then two gzipped blobs of data (starting with hex 1F 8B) which have the specified lengths. Connection transport should be ordinary TCP over an arbitrary port number.

https://insinuator.net/2022/09/spymax-the-android-rat-and-it-works-like-that/
https://www.stratosphereips.org/blog/2021/2/26/dissecting-a-rat-analysis-of-the-spymax

Читать полностью…

Malware Research

I often use the Medusa framework (which depends on Frida) to intercept and analyze how the malware app handles encrypted JSON objects sent by a fake C2. Maybe Medusa can intercept other kinds of C2 commands as well. Will look into it later.

Читать полностью…

Malware Research

Hi team! I'm looking for data breach by domain, what do you recommend?

Читать полностью…

Malware Research

I think I can only recall sandboxes have it

as for getting it out, not really sure. the APIs may allow that info to be queried, or no

Читать полностью…

Malware Research

/warn read rules and use english for communication

Читать полностью…

Malware Research

Any free websites/feed available where latest malwares are mapped with mitre attack framework along with their other attributes like impact, domains/IP's used etc...

Читать полностью…

Malware Research

User Anil has 1/3 warnings; be careful!
Reason:
add a description to links

Читать полностью…

Malware Research

Device is 14 pro max

Читать полностью…

Malware Research

And it’s by pailra1n

Читать полностью…

Malware Research

Can anyone tell me how to hack android over wan without ngrok and i can gain access again using kali linux

Читать полностью…

Malware Research

checkra1n does not support 17

Читать полностью…

Malware Research

Hello , did anyone do a jailbreak to ios 17.5.1 I need it to take a full filesystem image then analyze it to see if its infected or not

Читать полностью…

Malware Research

User Anil has 2/3 warnings; be careful!
Reason:
add context to the link and remove tracking

Читать полностью…

Malware Research

https://www.linkedin.com/pulse/how-do-you-use-threat-modeling-security-testing-your-anil-7xqyf/?trackingId=JGAQH%2FLQT3SPyZiJT7YJ%2Bw%3D%3D

Читать полностью…

Malware Research

It try to connect via TCP - sends heartbeat, but not establish full connection with C2. Main problem i cant manage installed malware in admin console to make other activities like open file manager or use camera

Читать полностью…

Malware Research

Hi Guys and Girls,
I am a 3yr exp Blue team professional, and now looking to start malware analysis.
Any guidance is appreciated.

Читать полностью…

Malware Research

https://www.malware-traffic-analysis.net

Читать полностью…

Malware Research

Hi all. Has anyone analyzed spymax android rat? I'm trying to trick a malicious apk by simulating C2 in my virtual machine and reconfigured network. the virus tries to initiate a connection with the server, but does not fully establish it, that is, it is not possible to reveal the full functionality of the virus.
The main goal is to dump malicious traffic while the virus is running and reproducing remote actions on the phone. Please advise what I can try?

Читать полностью…

Malware Research

User Hamed has 1/3 warnings; be careful!
Reason:
read rules and use english for communication

Читать полностью…

Malware Research

فی کی داره بفرسته bnb در حد چند سنت

Читать полностью…

Malware Research

don't update and wait for about 2 years and there MIGHT be a jailbreak for that version and device

Читать полностью…

Malware Research

https://www.linkedin.com/pulse/welcome-cybersentinel-gladiator-stay-ahead-patil-%E1%96%B4e%E1%92%AA%E1%92%AAo%E1%97%AF-s%E1%91%ADot%E1%92%AAig%E1%95%BCt-4lc7f/?trackingId=Pc4xoQi8RzajzEne4ffA7g%3D%3D

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: Libra
User: Unknown Mr
User ID: 6728884712
Reason: no skids

Читать полностью…

Malware Research

Only 16.x is supported

Читать полностью…

Malware Research

haven't been in jailbreaking for a while. does checkra1n not support every single version? if it's not maintained im sure there is a fork of it which does support ios 17.x

Читать полностью…

Malware Research

if a11 or under checkra1n else ur out of luck

Читать полностью…

Malware Research

You mean have I downloaded any samples?

Читать полностью…
Subscribe to a channel