9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
Hello @krylnn, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Guys has anyone come across malware being triggered on UTMP file … trend micro detected it as HTML_DORF.AF … im not able to find much on this alert and nothing suspicious in utmp,wtmp and btmp logs
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Tava Kurchenko
User ID: 6730394273
Reason: scam
please ask specific questions and elaborate them
e.g. where are you stuck at, what you have tried, what you don't understand, etc details that may help
Hello Richard, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello Art, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Gloria Ortega
User ID: 7253036486
Reason: scam
greetings team, I have an account but it does not allow me to download this, https://hybrid-analysis.com/sample/4ba96615dd4f38d5bf75c192c6bee81ecac595fda911d6974739557118eda032?environmentId=100
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Reliable Lead
User ID: 6730950760
Reason: illegal activity
🚨 BREACH:// CTF — ZERORELAY SEC
🔗 https://fioricet-necklace-craps-promoted.trycloudflare.com
═══════════════════════════════════
📜 RULES
═══════════════════════════════════
1. Register with your Telegram @username (no fake accounts)
2. Solve phases in order — each flag unlocks the next
3. No sharing flags/solutions publicly — DM them, discuss technique
4. Brute-force = instant disqualification (we log attempts)
5. Play fair. The goal is learning, not just winning.
6. Bugs found? Report them — bonus points if valid.
═══════════════════════════════════
🏆 SCORING
═══════════════════════════════════
• 200 pts — Registration bonus (everyone starts here)
• 100 pts — Each phase (clean solve, no hints)
• -20 pts — Hint Level 1 used
• -40 pts — Hint Level 2 used
• -60 pts — Hint Level 3 used
MAX POSSIBLE: 1100 points (200 bonus + 9×100 clean)
Each hint reduces your phase score. Clean solvers rank higher.
═══════════════════════════════════
🎯 THE CHALLENGE
═══════════════════════════════════
Phase 1 — RECON (JS Deobfuscation)
Phase 2 — INJECTION (SQL Injection)
Phase 3 — PIXELS (Image Steganography)
Phase 4 — CROSSFIRE (XSS + Cookie Theft)
Phase 5 — SHELL SHOCKED (Command Injection)
Phase 6 — FREQUENCY (Audio Spectrogram)
Phase 7 — IDENTITY (JWT + IDOR)
Phase 8 — UPLOAD (File Upload RCE)
Phase 9 — TEMPLATE (SSTI → RCE)
Phase 10 — THE VAULT (Chain All 9 Codes) 🏆
═══════════════════════════════════
New to CTFs? Start with Phase 1. Use hints if stuck.
Pro? No hints. Full score. Flex on the leaderboard.
Hi! Anyone can point in the direction of which ransomware type this is?
A 9 character long file extensions is appended to encrypted files.
Operator username is: revenantdec@gmail.com
Read this text carefully.Читать полностью…
We have breached your network due to security vulnerabilities and encrypted all your files using a military algorithm.
We have also TAKEN your CRITICAL DATA to our servers. If you do not cooperate by the deadline, We will leak or sell your data.
- The only way for restoring your files is through purchase of decryption software from us.
- You can also send us an unimportant file less than 1MB, We decrypt it as a guarantee for free.
What do we offer in exchange for your payment:
- Decryption and restoration of all your machines and data within 24 hours with a guarantee;
- Assurance that we will never inform anyone about the data breach from your company;
- After data decryption and system restoration, we will delete all of your data from our servers forever;
- Provision of valuable advice on your company's IT protection so no one can attack you again.
In order to start negotiations, Send message to our mailboxes:
- revenantdec@gmail.com
- revenantdec@yandex.com
- Make sure the subject of your email is your client ID: xxx
>>> WARNING!
- Avoid recovery companies; they are costly middlemen who may deceive you.
- They negotiate with us for decryption software, then overcharge you or scam you.
- Do NOT modify encrypted files, as this leads to permanent data loss.
- Do NOT use third-party repair software; it can damage your files irreparably.
- Act quickly, The faster you pay, the lower the price.
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Lenix
User ID: 8936838440
Reason: spam
Please try to keep the topic to malware-related contents
Читать полностью…
Hey there! I found a LPE in CATO networks VPN & here is the write-up for it.
https://somelab.ai/cato-securestore-xpc-lpe
but if first and second are the same -- clearly person doesn't care
Читать полностью…
@xiaomayi what do you think about banning if warning reason is the same?
Читать полностью…
Guys can anyone help in analysing this file on x64dbg …
Sha256 - 30c7682bb170be976646a9aeabdc9eb0cbebb3ef8ef6b92b83c6f26175913a06
Please dm me if you want the sample … im stuck at unpacking it
Hello @hltsrtl7, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello, I would like to know if you can tell me where I can report malware (ransomware) obtained as new variants for proper investigation and possible analysis using recovery tools.
Читать полностью…
Yes sir , i just created a 10 phase ctf challenge . Its gonna be a cold start, try to break though 10 fun challenges
Читать полностью…
Please post it if you are open to people joining it
Читать полностью…
https://www.google.com/search?q=makop+ransomware
First few articles should give a hint