Dealing with obfuscated RTF files
https://isc.sans.edu/forums/diary/Dealing+with+obfuscated+RTF+files/23169/
https://isc.sans.edu/forums/diary/Dealing+with+obfuscated+RTF+files/23169/
Transacted Hollowing - a PE injection technique. A hybrid between Process Hollowing and Process Doppelgänging.
https://github.com/hasherezade/transacted_hollowing
https://github.com/hasherezade/transacted_hollowing
GitHub
GitHub - hasherezade/transacted_hollowing: Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and…
Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging - hasherezade/transacted_hollowing
Order of Six Angles
Transacted Hollowing - a PE injection technique. A hybrid between Process Hollowing and Process Doppelgänging. https://github.com/hasherezade/transacted_hollowing
GitHub
GitHub - hasherezade/process_ghosting: Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using…
Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file - hasherezade/process_ghosting
Order of Six Angles
malware/monero
этот кусок я нашел в redline stealer кстати (не тот что из этой статьи, а просто рандомный)
https://therecord.media/nft-creators-tricked-into-installing-malware-in-highly-targeted-attack/
https://therecord.media/nft-creators-tricked-into-installing-malware-in-highly-targeted-attack/
The Record
NFT creators tricked into installing malware in highly targeted attack
Multiple digital artists and creators of non-fungible tokens (NFT) were at the center of a highly targeted malware campaign last week during which a threat actor tried to swipe their hard-earned profits.
Order of Six Angles
malware/monero
Но образец по всей видимости тестовый. Закриптованные строки должны содержать C2, но не декриптятся в валидный адрес хз пачиму
The purpose of BinLex is to extract basic blocks and functions as traits from binaries then compare these traits amonst other trait sets using genetic programming.
https://github.com/c3rb3ru5d3d53c/binlex
https://github.com/c3rb3ru5d3d53c/binlex
GitHub
GitHub - c3rb3ru5d3d53c/binlex: A Binary Genetic Traits Lexer Framework
A Binary Genetic Traits Lexer Framework. Contribute to c3rb3ru5d3d53c/binlex development by creating an account on GitHub.
Exfiltrating Data By Transfering It To The Cloud With Azcopy
https://m365internals.com/2021/06/11/exfiltrating-data-by-transfering-it-to-the-cloud-with-azcopy/
https://m365internals.com/2021/06/11/exfiltrating-data-by-transfering-it-to-the-cloud-with-azcopy/
Microsoft 365 Security
Exfiltrating data by transfering it to the cloud with Azcopy
During the past year, we have seen ransomware gangs using public tools to exfiltrate data by copying it to an array of a Cloud storage provider. In November 2020, SentinelOne discovered, that adver…
Forwarded from Devious Methods
YouTube
Mobb Deep - Shook Ones, Pt. II (Official HD Video)
Watch the official music video for "Shook Ones, Pt. II" by Mobb Deep
Listen to Mobb Deep: https://MobbDeep.lnk.to/listenYD
Subscribe to the official Mobb Deep YouTube channel: https://MobbDeep.lnk.to/subscribeYD
Watch more Mobb Deep videos: https://Mob…
Listen to Mobb Deep: https://MobbDeep.lnk.to/listenYD
Subscribe to the official Mobb Deep YouTube channel: https://MobbDeep.lnk.to/subscribeYD
Watch more Mobb Deep videos: https://Mob…
Chinese netfilter driver (новый, signed by Microsoft)
https://twitter.com/struppigel/status/1405483373280235520
https://twitter.com/jaydinbas/status/1406252350302527493
https://twitter.com/malwarelab_eu/status/1406347503092502535
https://twitter.com/struppigel/status/1405483373280235520
https://twitter.com/jaydinbas/status/1406252350302527493
https://twitter.com/malwarelab_eu/status/1406347503092502535
Order of Six Angles
Chinese netfilter driver (новый, signed by Microsoft) https://twitter.com/struppigel/status/1405483373280235520 https://twitter.com/jaydinbas/status/1406252350302527493 https://twitter.com/malwarelab_eu/status/1406347503092502535
Google Docs
Netfilter Rootkit Samples
check-results_Venom23-162402271
Lookup Hash,Rating,Positives,Virus,File Names,First Submitted,Last Submitted,File Type,MD5,SHA1,SHA256,Imphash,Harmless,Revoked,Expired,Trusted,Signed,Signer,Hybrid Analysis Sample,MalShare Sample
04e88b7717aadc6b56dfa006…
Lookup Hash,Rating,Positives,Virus,File Names,First Submitted,Last Submitted,File Type,MD5,SHA1,SHA256,Imphash,Harmless,Revoked,Expired,Trusted,Signed,Signer,Hybrid Analysis Sample,MalShare Sample
04e88b7717aadc6b56dfa006…
BAZARCALL (BAZACALL) CAMPAIGN PUSHES BAZARLOADER (BAZALOADER)
https://www.malware-traffic-analysis.net/2021/06/21/index.html
https://www.malware-traffic-analysis.net/2021/06/21/index.html