9630
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
I remember uploading my programs to virustotal virtual boxes, and there I collected information on how these machines were detecting our malware at the time, the amazing thing I found was that at that time the vulnerability was in mouse inactivity on their machines, and we bypassed these machines in a similar way:
POINT pos1, pos2;
g_winapi.GetCursorPos(&pos1);
g_winapi.Sleeping(2000);
g_winapi.GetCursorPos(&pos2);
if ((pos1.x == pos2.x) && (pos1.y == pos2.y))
g_winapi.ExitProcess(1);
and on 2024 we have systems like "anti-analysis", "anti-debugging"
Читать полностью…
obfusication of malware code, droppers of dlls, hiddne imports, you just cannot detect this
Читать полностью…
If u want to use tor you have to know to thing: a Good malware cannot be detected
Читать полностью…
Well, you definitely need an antivirus program. I would also recommend you to use Tor
Читать полностью…
Jo hablo portugues es un poco parecido al español.
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Simo
User ID: 5324413521
Reason: illegal activity
that's related to browsers right? or a PDF file can trigger it?
Читать полностью…
I haven't seen them since 2015 or 2016, so I doubt so
but PDF with phishing links still exist 🙈
and yes, they get past the filters. I don't know this tech (email gateways) well enough to know why
I know what u mean but I don’t know in deep that concept
Читать полностью…
With a Good obfuscation the api call will not be detected
Читать полностью…
Thanks, i know i can’t became a malware analyst, but when i start study i see that: Good virus are undetectable. My pc is full of malware, yes, but i know is my fault ahahah
Читать полностью…
Sorry, maybe if u need an antivirus for the crap u download u can’t use tor
Читать полностью…
anyway, off topic. please move to /channel/LibraLair to continue
Читать полностью…
My question is what additional security can I use on my PC other than VPN?
Читать полностью…
I have a number of questions, what cybersecurity can I use other than a VPN to do serious things?
Читать полностью…
User Adrian has 1/3 warnings; be careful!
Reason:
stay on-topic please
is #4 still a thing? I mean do modern anti phishing email kits let PDFs w/ JS pass by?
Читать полностью…
those are many years ago, and till date, I've never quite seen them already, probably since around 2015/2016
1. To create phishing pages
2. To create phishing + drive-by downloads
3. For drive-by downloads
4. PDF JS malware
But I've seen some cases of:
1. Injection into ads that the website uses. If user doesn't have adblocker or similar protection, it could lead to drive-by downloads or on payment pages, stealing of their credit card details
2. Injection into websites to compromise them. Similar impact as #1