9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
Fuzzing is most useful when you have a small harness around code you own or are authorised to test. Keep every crash reproducible. Reduce the input before expanding the corpus. Are you looking at a file parser or a network service?
Читать полностью…
It can be a bit though, but i would read practical binary analysis.
And then practice
Also have a look at die (detect It Easy) source code. And rules It use to flag for obfuscation and encryprion signatures
Hi guys, im new to unpack malware. How can I learn this where 😭😭
Читать полностью…
you either can help or just stay quiet thank you
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Lead Gateway
User ID: 6862749281
Reason: spam
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Md Shariful
User ID: 7973149229
Reason: spam
That difference can mean the sandbox is seeing different behaviour rather than simply missing a known signature. Compare the execution conditions and telemetry from each run, then use a small controlled set with documented expected behaviour. That makes the gap easier to explain than a simple safe or unsafe result.
Читать полностью…
I think those are people who are up to no good, especially when those malware are used for specific reasons
I'm not even talking law enforcement cases, which I don't 100% believe
No real curiosity beyond "how to hack iphone/Instagram "
Читать полностью…
I think at some point we will learn interrogation techniques to extract out the truth 😂
Читать полностью…
Please see @aleph_two message on malware development
It's not allowed
And I've pointed out some hints to start with
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Simon
User ID: 8759127639
Reason: haxor
you already got help. this is not a place for spoon feeding
Читать полностью…
how are you gonna test your yara rules if you can't find the section on the site about yara rules?
Читать полностью…
hello guys.
i want to test my yara is there any websites that i can use?
free 😶
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: ฟกฟ
User ID: 8859812612
Reason: spam
I would consider that for the kind of questions expressed not building but simply understanding a zeroclick chain would have taken years by the guy. I would have encouraged his research.
Читать полностью…
That's what I am trying to figure out like when I submit malwarebazaar sample I got the result perfect but when I submit different which is not listed on malwarebazaar or virustotal database some time my sandbox say safe so I am trying to check where my sandbox is lacking
Читать полностью…
I think whenever someone needs to interrogate, the ending is never happy
Читать полностью…
Sometimes it's fun, I should say. But most of the times it's sad
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Adam
User ID: 8041920084
Reason: maldev
Bro,
Actually, I wanna build my own so I want help and instructions from all of you.
So your curiosity is because you can't get it to work?
Читать полностью…