9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
Define "new"?
Commodity malware like Agent Tesla, Vidar have thousands of hashes daily and you can pull it from Malware Bazaar via API
Malware that gets caught by generic rules but belonging to another family or new family is another thing
For a sandbox test, I would use curated samples with known behaviour and keep the lab disposable and isolated. What signal do you need to validate first?
Читать полностью…
hey i am threat hunter and i am testing my sandbox so i want some new malware sample to test my sandbox so any one can help me with that
Читать полностью…
Could someone please help me download this sample?f1246fd6af3a426fed75a23618b2e78f47864d7687d750b6f40c752cc06107f6
almost every malware has similar observable behaviour. How do you based on those determine the family?
almost every malware will persist, has network activity, makes system changes for all kinds of reasons
if I observe this in this malware A, then do I assign it to family A, B, or C?
Hello Malithu, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello, Could anyone get this sample? Thanks in advance.
MD5:33ec4b6ea71bb7065ddb2d3faa909f3b
https://www.virustotal.com/gui/file/19258ac29e55d6709391ddf920ec9e8e3906c6c2501c3f5c9a31477c868d6f5d/detection
Hello Benjamim, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
For a service you control, keep any security logging visible and limited to what is needed. A disguised link that exposes a visitor’s IP or location is not a responsible way to collect it.
Читать полностью…
Hello DIPTI 😘❣️, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello Team,
Could anyone kindly drop this sample?
Hash: 7cbbf077acf987f8df6785a57f6b7d904f5fa312ecf1640e9592a8f700a82047
https://www.virustotal.com/gui/file/7cbbf077acf987f8df6785a57f6b7d904f5fa312ecf1640e9592a8f700a82047
Thank You in advance
Tool that create links .. than when users click on it i got those locations or ip or can say … i forget the tool name any one here know this kind of tool
Читать полностью…
I would avoid live malware for the first exercise. Start with YARA's public test corpus and the official example rules, then compare several static files in an isolated lab. The useful first milestone is being able to explain why every condition is specific.
Читать полностью…
Can you suggest a simple family to start with?
Читать полностью…
It can be considered if there's enough time to do so
Читать полностью…
A sample request is easier to assess when it includes the research question and the handling plan, not only a hash. That helps people decide whether sharing is appropriate and makes the result easier to reproduce.
Читать полностью…
Generic persistence and network activity are triage signals, not a family label. I would keep it unknown until more specific evidence lines up, such as code lineage or a distinctive configuration format. The important thing is to separate what was observed from what was inferred.
Читать полностью…
Before assigning a malware family, I prefer to record the observable behaviour first: persistence, network activity and file changes. What early evidence has proved most reliable for others here?
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Matias Molina
User ID: 7826254721
Reason: scam
sample request please 8738d53860c8b439cf7f1b672685757b6ff1021b912b3997cbc679b20e210e26
Читать полностью…
Hello @Pierre_844, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
Hello H3r3t1c, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
as long as you own the logs, you can get that info
that's how Google, Microsoft, Facebook and other big tech companies warn you that your account is compromised
Hello @elviswebdev, welcome to the Malware Research group! Please read the pinned message before you post!
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: LÜZËÑ
User ID: 7622394351
Reason: shit
I would download some sample from malware bazaar. Simple stuff. Not obfuscated.
Читать полностью…
Start with a family of samples rather than a single file. Look for strings or code sequences that survive across related samples, then test the rule against unrelated benign files. A pattern that only matches one sample is usually a fingerprint, not a useful rule.
Читать полностью…