New lab on https://t.co/BabZ0NwkTR 🔬
Dissect a real MuddyWater attack chain:
📧 The Lure — phishing & maldoc
📦 The Loader — unpacking the dropper
🎯 The Implant — reversing a custom RAT
Try it now 👇
https://t.co/D02mK4aKIM
Join us: https://t.co/ktQHg2ZGi4
We’ve published our first technical malware analysis blog . The article deeply covers Remcos RAT, which has been frequently observed in financial and banking sector attacks.
https://t.co/NUqCjNAQxc
#MalwareAnalysis#infosec
Our first Lab about #Kimsuky APT campaign.
🧪 Operation Silent Serpent (7-stage chain lab)
🔗 https://t.co/W13JmkNKJ2
Each stage unlocks the next just like real-world investigations.
💬 Discord: https://t.co/g7awig8ggY
👤 Creator: https://t.co/DJyAc4cRzQ
If you’re into malware analysis and reverse engineering 🧬
at https://t.co/BabZ0NwkTR you’ll solve labs focused on multi-stage attack chains.
Train to analyze real-world attacks from initial access to final payload, with a strong focus on real APT campaigns.
Another year of the FLARE challenge done! Third year finishing all the challenges. Challenge 9 was harder than expected, but I learned a lot. Hope to do better next year! #flareon12
YARA is great at string (or byte chain) matching.
It’s not great at juggling hashes and loops in conditions.
This rule from a public demo loops over export offsets, reads 14 bytes at each offset, hashes them, and compares to an MD5.
Yeah… no.
- String matching in YARA is highly optimized (Aho-Corasick) and scales well across many rules
- But the condition of each rule has to be evaluated separately
- That means hashes, loops, and complex logic add up quickly across large rule sets
- And importing any module (not just hash) has a significant performance impact
Use YARA’s strengths: string matching.
A better way to write this?
Include the 14-byte pattern in the strings: section, then check if it matched at the offset. Done.
Also:
- Avoid import unless you really need it
- If you must import a module once, fine – reuse it. The performance hit comes with the first import, not the second use.
In large rulesets with hundreds or thousands of rules, condition evaluation doesn’t scale well.
String matching does.
More info:
YARA Performance Guidelines
https://t.co/88tjl9CwLs
The impact of importing a module
https://t.co/aXVaI2ChqB
Performance impact of condition evaluation
https://t.co/UOv2NJralZ
So far, I have already written 15 articles (1045 pages), which have been published on my blog:
blog: https://t.co/UpYLkSS6GB
ERS: Exploiting Reversing Series (currently at 439 pages, with continued progress underway):
[+] ERS 05: https://t.co/rdaPMOm4WM
[+] ERS 04: https://t.co/Vf0Fnwf0tc
[+] ERS 03: https://t.co/4lo5Hi0gnd
[+] ERS 02: https://t.co/6SNMK1tBkd
[+] ERS 01: https://t.co/YMTSBl59VC
MAS: Malware Analysis Series (606 pages -- finished):
[+] MAS 10: https://t.co/eS2S5fVqjl
[+] MAS 09: https://t.co/2RTyR4Foqj
[+] MAS 08: https://t.co/yvXoY9uoDH
[+] MAS 07: https://t.co/DIcpSdQRqo
[+] MAS 06: https://t.co/AvjPAaSP1f
[+] MAS 05: https://t.co/4wFVoBFCAr
[+] MAS 04: https://t.co/PE7JeELxvO
[+] MAS 03: https://t.co/QXa2To5rfk
[+] MAS 02: https://t.co/BPt9L7Q7oo
[+] MAS 01: https://t.co/vGnT26NgsP
I'll soon begin writing the next articles in the Exploiting Reversing series, which will focus on vulnerability and exploitation, once I've laid all the necessary groundwork.
Enjoy reading and have a great day.
#windows #iOS #macOS #cybersecurity #infosec #chrome #kernel #malware #reverseengineering #vulnerability #research #hypervisor
#SocGholish , #UNC4108 folks have been making some updates to their #JuniperStealer 👀
I covered the stealer in this article earlier in February: https://t.co/WoEN7M8vMP
We’re excited to announce the launch of https://t.co/BabZ0NwkTR , a platform built by analysts, for analysts and it’s completely free.
You can join and enjoin with our frist challenge about RokRat Loader.