Maldev Database updated
https://t.co/FEQH43edCX
Some of the newly added snippets include:
- Anti-Analysis Via Self-Deletion (Windows 11)
- Anti-Analysis Via Self-Deletion (2) (Windows 11)
- Running VBScript code in memory
- Screen Capture to BMP (ScreenShot)
- Sleep Obfuscation (Ekko)
- Sleep Obfuscation (Foliage)
- Sleep Obfuscation (Zilean)
- Sleep Obfuscation with Call Stack Spoofing (Ekko)
- Sleep Obfuscation with Heap Encryption (Ekko)
- Proxy Execute LoadLibrary With Timer APIs
- Proxy Execute LoadLibrary With Wait APIs
- Proxy Execute LoadLibrary With Work Item APIs
Thank you @joaoviictorti for assisting and to Maldev Academy members that contributed.
Windows self-delete on 24H2 (@TKYNSEC), DNS rebinding (@yarlob), VSCode backdoor (@d1rkmtr), leak Google users' 📞# (@brutecat), Entra sync dumping (@hotnops), Delegations (@podalirius_), Chrome abuse for screenshots, mic, and more! https://t.co/gQyyKRf4Os
Windows 11 24H2 broke a popular malware evasion technique! The Lloyd Labs self-deletion method now fails because of NTFS changes, so I spent time with kernel debugging to figure out why and how to fix it.
Full technical breakdown: https://t.co/chp6RbrlA3
Zoho Quick Assist has a critical flaw! Found that unprivileged users can delete arbitrary system files through the "Send Logs" function due to improper path validation, potentially escalating privileges to SYSTEM level.
Full analysis + demo: https://t.co/qCj0FYNYG2
Anyone work at ASUS? I have a local privilege escalation vulnerability in a widely deployed desktop app to disclose quickly. PoC code and explanation available. Thanks!