Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
but they use a different priv-key for "customer" or they should
Читать полностью…How decryption happens sir after ransom Is paid?
Читать полностью…Hello Profound, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…Guys I have been mostly reversing windows malware for now, planning to get into mac malware analysis whats some good book which covers some mac internals, debugging examples, common malware techniques etc? Thanks!
Читать полностью…Hello Alla, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…https://app.any.run/tasks/60eba7a5-fb51-44f9-a32d-f7cb9c73567c
Читать полностью…User 𝓘𝓷𝓭𝓮𝔁 𝓢𝓹𝓪𝓶𝓶𝓮𝓻 has 1/3 warnings; be careful!
Reason:
stay on topic
Ohhh. Do you mean, in runtime, or by changing files on the disk?
Читать полностью…Hi need to understand how a malware can hijack EAT and points fk different sections, any learning about it
Читать полностью…New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Hessen kole
User ID: 7044494350
Reason: spam
Please add direct links to content when you post something, now you link to Twitter, which links to Github...
Читать полностью…New FedBan
Fed: Libra's Empire
FedAdmin: Libra
User: Pablo Cookies 😈
User ID: 5675694406
Reason: im tired of skids
the victim downloads an unlocker that has the privkey, that privkey can decrypt all the keys that decrypt all their files
Читать полностью…Hello Profound, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…User Jeevitha has 1/3 warnings; be careful!
Reason:
no advertisement
https://objective-see.org/index.html
I think most of the Mac reverse engineering stuffs I saw are from Objective See. they also have books on it, but I'm not into Mac, so I didn't read them
your only message is "how can help you?"
do you think we have crystal ball or something?
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Cyber Task
User ID: 884606906
Reason: spam
Reported 𝓘𝓷𝓭𝓮𝔁 𝓢𝓹𝓪𝓶𝓶𝓮𝓻 [6556691134
] to admins.
Look at the PE file structure. Should answer your questions
Читать полностью…User Edward has 1/3 warnings; be careful!
Reason:
use @dfirjobs
hey all, can someone get me this sample from virustotal : a73a6631b4951b34137a45ce2198a0cf5729a5d1bfaf7b628090dbcac2116f2f
Читать полностью…https://github.com/RootUp/PersonalStuff/blob/master/smuggle_ico.py
Читать полностью…Smuggling file through icon files (.ico), still a lot to explore but you can give a try!
https://x.com/RandomDhiraj/status/1910350913161646169