π€ I finally found the time to push a small update on the #Unprotect project with malware evasion techniques contributed by @futex90, @HoIIovv, and @sadocadonon.
Check it out π cc: @DarkCoderSc
https://t.co/LwKoE08Xbs
My kind of CVEs ππ Big shoutout to the team at Unprotect, @fr0gger_ and @DarkCoderSc, for their relentless efforts! Proud to contribute and keep pushing the boundaries together! π #Cybersecurity#ReverseEngineering
4οΈβ£ VboxEnumShares: This method identifies VirtualBox shared folders by iterating through network resources using WNetOpenEnum and WNetEnumResource, looking for names like "VirtualBox" or "VBoxSrv." It's an alternative to the WNetGetProviderName technique. Added by @HoIIovv. https://t.co/XXLxxt8f8J
Excited to share a new evasive technique recently added to the https://t.co/xmj6oVgusE project discovered by me! You can find the PoC and YARA rules on their fantastic website, along with more detailed insights on my personal website. Huge thanks to @fr0gger_ and @DarkCoderScππ½
The source code of our framework for finding completeness bugs in optimizing compiler toolchains has been released!
Tomorrow I will be presenting our paper at @ASPLOSConf, in Vancouver (CA).
It is available at: https://t.co/0EzsJHUl7i
I'm thrilled to announce that our paper on the (in)completeness of debug information will appear in ASPLOS '23. We spot clang & gcc bugs behind debug information loss when compiling with optimizations.
Preprint: https://t.co/XF9AJgHSbC
The code will be open-sourced.
#agenttesla with a triple exfiltration strategy (SMTP, FTP and @telegram API) handled by a configuration variable in the final payload.
The @telegram API exfiltration routine uses default credentials (empty username and password) and stores the API url in a plain text variable.
On July 14, I had the honor of defending my master's thesis in #Cybersecurity with a grade of 110 under the supervision of @dcdelia.
My research project is a framework to track and build a detailed profile for the evasion strategy of a malware sample.
https://t.co/Yx00qh1DQ1