Setting up an analysis VM for reverse engineering?
Here are a few good tools (with short demos) that I recommend after running the Mandiant/FLARE script, (which installs 99% of tooling for you) 🔥
TLDR:
Garbageman, SpeakEasy, BlobRunner, Dumpulator
#Malware#RE#Analysis
Recent Chinese Threat Actor #PlugX APT #Malware Spread from ISP: UCLOUD Hong Kong (AS 135377)
C2 IP/Domain : 45.249.245.35:8008 (TCP)/ ntpserver(.)xyz/
Currently 𝗔𝗰𝘁𝗶𝘃e
Malware Hash:
eeadacdfb1d0c571362ff86b34cd736a80531e635ad46f20b2e90ec862af36af
Check out our latest blog post to learn about the activity & similarities between multiple #ransomware families related to AVADDON ransomware.
👉 https://t.co/DLbeQ3cveW
Mandiant researchers explore activity, similarities and overlaps between multiple ransomware families related to the AVADDON ransomware. https://t.co/o9V6OZl9Oo
It appears that a file used in the LockFile attack has similarities to a previous sample attributed to APT10.
It's an interesting find, so I took a quick look at it. #APT#lockfile#Ransomware Thread👇
Today we are releasing a new blog and technical information regarding TTPs & new malware families observed during previously disclosed #NOBELIUM phishing campaigns we have observed/tracked since as early as Jan 2021.
https://t.co/Cd7DEdGIwl
Thread on the new families & TTPs ⬇️
#CobaltStrike hunting tip of the week:
EDR and AV got you down? Another way to detect/hunt for CS in your environment is through the deployment of Yara rules.
This list has some good stuff, including Yara rules from @tenacioustek and @cyb3rops.
https://t.co/pqNcTDC3qY
#RedDelta version of #PlugX; this time encrypted with a 13 byte XOR key.
43.254.217.165:110
43.254.217.165:80
Embedded Marker: ja-user-pc
ThreatConnect: https://t.co/f9OxYHadtn
VT (encrypted): https://t.co/XxDHPczUbm
5d2856d38f182cba36a045935ed11a17
#MustangPanda
Bye-bye botnets👋 Huge global operation brings down the world's most dangerous malware.
Investigators have taken control of the Emotet botnet, the most resilient malware in the wild.
Get the full story: https://t.co/NMrBqmhMIf
#APT#mustangpanda/#honeymyte Cobaltstrike activity in 2019. The below graph is based on PE compilation time of their cobalt strike payloads in 2019. Using Yara, I was able to find 28 unique CS samples. @James_inthe_box @P3pperP0tts
Another #RedDelta version of #PlugX; this time encrypted with a 15 byte XOR key.
43.254.217.165:110
43.254.217.165:80
Marker (campaign id?): ja-acer
ThreatConnect: https://t.co/rc9Z2osWEP
VT (encrypted): https://t.co/lCbcQj1Owy
798810d4ab0637916e699eeeffb393db
#MustangPanda
So you want to talk about the massive software supply chain intrusion & the most carefully-planned, complex espionage I’ve ever helped uncover?
Start here: https://t.co/m1nJG5UlVk 🤩
But then what?? Let’s talk about some post-compromise techniques...
Okay folks, let’s talk about SolarWinds.
For those not familiar with it, SolarWinds is a network management system (NMS). It’s probably the most ubiquitous NMS out there, so we shouldn’t jump to conclusions that FireEye and Treasury were both breached by an SolarWinds vuln. 1/