Malvidin

7 posts

Malvidin banner
Malvidin

Malvidin

@malvidin

Beigetreten Aralık 2015
19 Folgt5 Follower
Malvidin
Malvidin@malvidin·
@RedDrip7 @intel @Cisco Updated to decode encoded data across multiple DNS queries. Thanks to @netresec for the CreateSecureString info. Also decodes CCB19334A6D32DAA and CDCC93B50477F52F (@netresec decoder does not yet)
English
1
0
1
0
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
Short thread on analyst life: I kept seeing this same partial string in a bunch of Tonto Team malware "wkko%00" I'm looking at tons of bins a day, rather than diving into it, I kinda *guessed* it was a common start to a key or password of some sort. Wrote a Yara rule, moved on.
Steve YARA Synapse Miller tweet media
English
3
40
119
0