9374
Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: ฟกฟ
User ID: 8859812612
Reason: spam
I would consider that for the kind of questions expressed not building but simply understanding a zeroclick chain would have taken years by the guy. I would have encouraged his research.
Читать полностью…
That's what I am trying to figure out like when I submit malwarebazaar sample I got the result perfect but when I submit different which is not listed on malwarebazaar or virustotal database some time my sandbox say safe so I am trying to check where my sandbox is lacking
Читать полностью…
I think whenever someone needs to interrogate, the ending is never happy
Читать полностью…
Sometimes it's fun, I should say. But most of the times it's sad
Читать полностью…
New FedBan
Fed: Libra's Empire
FedAdmin: alex 27
User: Adam
User ID: 8041920084
Reason: maldev
Bro,
Actually, I wanna build my own so I want help and instructions from all of you.
So your curiosity is because you can't get it to work?
Читать полностью…
Or as a shortcut, start Googling about Pegasus malware and read the technical reports
Читать полностью…
You can pivot from those news and further research on them
Читать полностью…
Right now there's another exit like Pegasus?
Читать полностью…
That difference can mean the sandbox is seeing different behaviour rather than simply missing a known signature. Compare the execution conditions and telemetry from each run, then use a small controlled set with documented expected behaviour. That makes the gap easier to explain than a simple safe or unsafe result.
Читать полностью…
I think those are people who are up to no good, especially when those malware are used for specific reasons
I'm not even talking law enforcement cases, which I don't 100% believe
No real curiosity beyond "how to hack iphone/Instagram "
Читать полностью…
I think at some point we will learn interrogation techniques to extract out the truth 😂
Читать полностью…
Please see @aleph_two message on malware development
It's not allowed
And I've pointed out some hints to start with
Читать полностью…
But the technology has been updated. So that process is not working right now.
Читать полностью…
Yea, I read..
But I think there's still an exit. Or in this group does anyone know about that?
I see the pattern emerging for the "new" malware recently..
Читать полностью…
I don't think any reports have mentioned the source codes, but it's been analyzed
Читать полностью…
And in this group is not about malware development
Читать полностью…