Check Point Research has identified an unusual pattern of behavior involving PDF exploitation targeting users of Foxit Reader. Our latest publication details multiple campaigns taking advantage of this exploit, from E-crime to Espionage groups.
https://t.co/otDyzBKXkp
🔥Lumma Stealer - Manually Unpacking and Extracting C2's 🔥
Let's analyse a Lumma malware sample and manually unpack it with Dnspy and x32dbg.
We'll then leverage Ghidra and x32dbg to locate and decrypt four C2 addresses.
[1/24] 🖊️
#Malwareanalysis#Ghidra
🚨 I've put together my first #cheat#sheet around #maldocs, you can download a PDF version from 👇
✅ https://t.co/iruVT35nFh
Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.
#Qakbot came back with new tricks. In this new blog post, we will:
● unpack it
● decrypt it (strings + cnc)
● and write a config extractor in python
using only static analysis (and #malcat of course :)
https://t.co/moDXSFNjW2
Malicious documents with 5-year-old CVEs could be considered useless anymore. In reality, in 2023, they were used by big malware names and targeted lucrative sectors.
Link to the report by @_CPResearch_ : https://t.co/JYpkACty5Y
A Beginners Guide to Tracking Malware Infrastructure
New post with 11 Examples (Including Cobalt Strike and Qakbot) that you can use to query and track C2’s, Open Directories and More🔥
(Special thanks to @censysio 🥳)
https://t.co/9h1Q07mbuj
#threatintel#malware
It was a great time at @virusbtn in London with presenting a research that we made together with @_mbv06_: the one about unique evasion techniques in the voice-phishing Android apps.
The link to the video is here:
https://t.co/LqIPvyjZqs
🚀 GuLoader has leveraged cloud services to distribute malware for 3+ years. Its new techniques make it significantly challenging to analyze. New samples receive zero detections on VirusTotal, enabling the stealthy delivery of malicious payloads.
https://t.co/zonk0y4ZHy
So proud to have a privilege to represent @_CPResearch_ at the upcoming @virusbtn 2023 in London!
Come visit the talk to listen about FakeCalls Android malware research, our joint effort with @_mbv06_ who unfortunately will not attend the event.
https://t.co/nXYeDsPWQR
New #Android malware FluHorse: it mimics several APKs from Eastern Asia with 1 million installs each. #FluHorse can remain #FUD for months because of underlying Flutter framework. We analyzed it and contributed to the open-source project flutter-re-demo.
https://t.co/cBxRnukgUe
📝Our latest blog analyzes #Xloader's new #obfuscation techniques that protect critical parts of the code and data in version 4.3: https://t.co/FlPpMgToSc
🛠️An IDA script to deobfuscate Xloader's code is available in our GitHub tools repository here: https://t.co/bj0UuDOU9L
There are at least 3 different trojanized #3CX Windows installers in the recent Supply Chain attack, two MSIs and one NUPKG. As a result, some of the other components may also vary.
Those are the malicious installers identified so far:
f3d4144860ca10ba60f7ef4d176cc736
0eeb1c0133eb4d571178b2d9d14ce3e9
11bd685041d98d392df3d95f96d96dc1
>>
Defeating #dotRunpeX — New #virtualized .NET injector abusing advanced techniques to deliver numerous malware families.
CP<r> provides an in-depth analysis of this threat introducing several PoC techniques for reversing protected/virtualized #dotnet code. https://t.co/PxzqoIJJKu