I recently found two very interesting Linux binaries uploaded to Virustotal.
I call this malware 'GTPDOOR'.
GTPDOOR is a 'magic/wakeup' packet backdoor that uses a novel C2 transport protocol: GTP (GPRS Tunnelling Protocol), silently listening on the GRX network (1/n) 🧵
I wrote a YARA rule designed to identify emails attempting to exploit CVE-2024-21413, a vulnerability in Microsoft Outlook that permits the unauthorized acquisition of NTLM credentials
#100daysofYARA#YARA
https://t.co/RhIcyltkKV
is anyone with high expertise of malware analysis able to investigate this one??
0 hits on VT on the ''fuckingdllENCR.dll" file
although i think its #ransomware.
#opendir hxxp://5.42.64.3/dll/
Hi @BlizzardCSEU_EN ! Is anyone still working on bugfixing Starcraft 2? We can no longer create or join arcades since 5 days. Looking forward to hearing from you.. #sc2#bugs
#Turla is a veteran threat actor that has consistently adapted its tools and strategies.
Our blog entry delves into the group's historical activities, which you can explore more here: ⬇️ https://t.co/CjzDf4Dpba
Microsoft has identified targeted attacks against the defense sector in Ukraine and Eastern Europe by the threat actor Secret Blizzard (KRYPTON, UAC-0003) leveraging DeliveryCheck, a novel .NET backdoor used to deliver a variety of second stage payloads. https://t.co/mWoyzOoydF
The only ChatGPT guide you'll ever need.
Go from beginner to pro with the ultimate ChatGPT Cheat Sheet.
Get more tools & guides like this by signing up to Superhuman AI--the world’s biggest AI newsletter.
Bonne intro sur la signalisation chez les opérateurs mobiles.
Et pour aller plus loin et devenir un wireshark #SS7 master c'est par ici :
https://t.co/XwxGGtvjIT
#sstic
[Blog] Breaking https://t.co/vAXFrVj0tC: the CTF that wasn't meant to be
From an obfuscated .Net binary to a working cryptography attack: https://t.co/9aDnu2aQNV
Source code is here: https://t.co/MOMbiTkySh
(after 1.5y of procrastination on this blog post)
Thanks to Firmware Scanner of our anti-rootkit set of techs we identified a new cyberattack #MoonBounce.
The malicious implant is placed directly on SPI flash and is capable of persisting in the system across reboot or disk replacement.
Details 👉 https://t.co/L3TKVtzkro
Microsoft identified a unique destructive malware operated by an actor tracked as DEV-0586 targeting Ukrainian organizations. Observed activity, TTPs, and IOCs shared in this new MSTIC blog. We'll update the blog as our investigation unfolds. https://t.co/wBB82gp6TX
Today we are very proud to release IRIS: https://t.co/oalBbEG2XT. It is a collaborative platform designed for and by IR analysts. Developed and used by the @AirbusCyber CSIRT (special mention to the main dev, @White_Kernel). 1/4
If you rename procdump.exe to dump64.exe and place it in the "C:\Program Files (x86)\Microsoft Visual Studio\*" folder, you can bypass Defender and dump LSASS.