Malwoverview version 6.1.0 has just been released:
https://t.co/EwDKd2Vsez
To install it:
$ python -m pip install -U malwoverview
This release includes several new features:
[+] Introduces the -vx option for Virus Exchange (@vxunderground).
[+] Introduces the -ip option for IPInfo and BGPView.
[+] Introduces the -O option for saving samples to a central directory.
[+] Fixes several other issues.
My friend Artur Marzano (@MacmodSec) did an excellent job coding all the new features, so he deserves credit. I just managed the process by proposing these features, suggesting new ideas and reviewing the final result.
Have a great day.
#malware #threathunting #dfir #cybersecurity #informationsecurity #hacking #github
👁️ Missionné par la #DGSI pour pirater des sites djihadistes, @Sh0ckFR a découvert des années après avoir arrêté que son propre officier traitant l’avait spolié d’une partie de la rémunération que le service de #renseignement lui versait. (v/@MatthieuSuc)
https://t.co/VQ5uoJDIvo
DevCon #20 - Une conférence Programmez! gratuite 100 % sécurité & qualité du code: L’édition 2023 de notre conférence DevCon 100% Sécurité se tiendra le 19 octobre prochain. Cette DevCon est complémentaire au hors série été 100 % sécurité & Qualité du… https://t.co/tfYTnhc5hx
We received quite a few e-mails today from the Red Cross of Italy - compromised e-mails. The compromised e-mails come from an unknown individual asserting that the Red Cross of Italy is stealing (and laundering?) money
They also say they're not going to ransom them
¯\_(ツ)_/¯
If you have just started learning reverse engineering and malware analysis, you should pay attention to simple and well-known tricks that still have been used by adversaries when analyzing the resulting assembly code.
#idapro#reversing
We have received our first Twitter payout. We received $285.63. We donated the full amount to WiCyS (Women in CyberSecurity).
We will continue to donate our monthly Twitter revenue to non-profits.
Have a nice day.
Today Lockbit ransomware group issued a poll to all of their affiliates.
Lockbit is considering implementing new rules for Lockbit affiliates due to their frustration with ransomware negotiators. Currently, Lockbit ransomware group has no rules in place for how much (or how little) affiliates can ransom a company for. They are considering "regulating" ransom demands.
They state newer affiliates are giving large discounts to victim companies out of desperation for money, whereas more experienced affiliates do not cave to negotiator's proposed payment from the victims.
Lockbit administrative staff are proposing the following options.
1. No changes in payment policy, payment options will remain "unregulated" and remain up to the affiliates.
2. New rules in place which set the minimum payment allowed to be 3% of the victim companies annual revenue with the option of a 50% discount, bringing it down to 1.5% of annual revenue.
3. Establish a new rule where affiliates can only grant a 50% discount of the original ransom price.
4. Establish a new rule where they will not accept a payment below the victims maximum ransomware insurance policy.
5. Establish a new rule where they will accept a minimum payment of 50% of the victims ransomware insurance policy.
In regards to this poll, National Hazard Agency, a subdivision of Lockbit ransomware group, has stated they will no longer accept payments below 3% of the companies annual revenue. They will immediately retaliate against any negotiator who approaches them with an offer of less than 3% of the companies revenue. The retaliation will be complete destruction of company data.
Image 1. Original Lockbit poll (Russian)
Image 2. Lockbit poll (English)
Image 3. Message from National Hazard Agency
All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk.
A company valued at $33,900,000,000 was defeated by a 10-minute conversation.