9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
User Gulam has 1/3 warnings; be careful!
Reason:
no jobs
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Kesmond
User ID: 8004200167
Reason: spam
This is a search bot. It also searches for bug bounty reports. You can try it.
Читать полностью…
Anyone has comprehensive samples for all recent clickfix stuff?
Читать полностью…
Hello wqer, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: luqu
User ID: 8875076032
Reason: None given.
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: shuangjian
User ID: 8840153102
Reason: None given.
Hi everyone. Does anyone have the exact encryptor used by The Gentleman group for reverse engineering of the malware? Thanks 🙏
Читать полностью…
911578c4d665c12299d237228b7eb5dfe32cf57d1a7b1c155a0fe95d8b31dbb5
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: jijing
User ID: 8990459509
Reason: None given.
When a sample drops many files, a naming convention that keeps the process and timestamp together can save a lot of guesswork later. How do people here keep the relationship between a dropped file and the process that created it clear?
Читать полностью…
I need to download a file from VirusTotal. I’ll pay anyone who can do it
Читать полностью…
I see. Searching bug bounty reports makes it more useful for early research. Does it show why a report matched or give any confidence signal?
Читать полностью…
A CVE feed is most useful when each item explains why it is relevant to an environment, not only that a proof of concept exists. A source link, publication date and affected version would make triage much faster. Does the bot keep that context with each alert?
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Vivaan Jayaraman
User ID: 8186483889
Reason: scam
Just launched a Telegram bot that pulls CVE PoCs (GitHub, Metasploit, nuclei templates, bug bounty writeups) + auto-tracks blackhat news (new malware, breaches, hacker/APT arrests) from ~60 sources. Please test it and give feedback
@cve2poc_bot
Team please help on this sample https://www.virustotal.com/gui/file/b459109d2748723ebd9b212074cebd53ba95c589d540089e41380baad596f30d/detection
Читать полностью…
I would start with a public technical report rather than try to source the encryptor itself. Map the file markers, extension changes and recovery notes it describes, then define what you need to validate. That keeps the analysis goal clear without turning it into a malware request.
Читать полностью…
1c8860b24267cf5ed4bb21db453bc3288c4e9339eeb5d85500847fe2e4dffd73
Читать полностью…