9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
Hello Benjamim, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
For a service you control, keep any security logging visible and limited to what is needed. A disguised link that exposes a visitor’s IP or location is not a responsible way to collect it.
Читать полностью…
Hello DIPTI 😘❣️, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello Team,
Could anyone kindly drop this sample?
Hash: 7cbbf077acf987f8df6785a57f6b7d904f5fa312ecf1640e9592a8f700a82047
https://www.virustotal.com/gui/file/7cbbf077acf987f8df6785a57f6b7d904f5fa312ecf1640e9592a8f700a82047
Thank You in advance
Tool that create links .. than when users click on it i got those locations or ip or can say … i forget the tool name any one here know this kind of tool
Читать полностью…
I would avoid live malware for the first exercise. Start with YARA's public test corpus and the official example rules, then compare several static files in an isolated lab. The useful first milestone is being able to explain why every condition is specific.
Читать полностью…
Can you suggest a simple family to start with?
Читать полностью…
User Alex has 1/3 warnings; be careful!
Reason:
stay on topic
Did you write any interesting blog article or paper?
Читать полностью…
@aleph_two are you the author of "smashing the stack for fun and profit?"
Читать полностью…
consume more materials. watch videos on topic, read documentation, and experiment
Читать полностью…
well, this is not YARA problem per se. You need to work this out by yourself. Check sample with strings, count them, search for patterns
Читать полностью…
Hello @khaleddzdzdz, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello @Pierre_844, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello H3r3t1c, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
as long as you own the logs, you can get that info
that's how Google, Microsoft, Facebook and other big tech companies warn you that your account is compromised
Hello @elviswebdev, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: LÜZËÑ
User ID: 7622394351
Reason: shit
I would download some sample from malware bazaar. Simple stuff. Not obfuscated.
Читать полностью…
Start with a family of samples rather than a single file. Look for strings or code sequences that survive across related samples, then test the rule against unrelated benign files. A pattern that only matches one sample is usually a fingerprint, not a useful rule.
Читать полностью…
no, I didn't. Maybe someday later, but I doubt it
Читать полностью…
https://yara.readthedocs.io/en/latest/writingrules.html#
Читать полностью…
Can you suggest something that will help me with this problem?
Читать полностью…
I know how to write one and the commands to use.
I want help with finding unique strings and byte code from the assembly
what problem do you have with documentation like that: https://yara.readthedocs.io/en/stable/writingrules.html
Читать полностью…
A little question, Can I send my new website here?
Читать полностью…