Spider0x

46 posts

Spider0x

Spider0x

@Cyberagent101

Cyber security engineer 👩‍🔧 Specialized in digital forensics & malware analysis. Interested in every computer science related things.

Katılım Aralık 2021
169 Takip Edilen190 Takipçiler
Spider0x retweetledi
Cyber 5W
Cyber 5W@cyber5w·
As a DFIR Engineer, you should notice something suspicious going on here!! But how many techniques do you know that an attacker can use to hide this easy detection from you?! #C5W #DFIR #Malware #ThreatHunting #Cybersecurity
Cyber 5W tweet media
English
2
6
20
4K
Spider0x
Spider0x@Cyberagent101·
NTFS is always the place where every disk-related artifact will leave a trace, mastering its analysis is a crucial skill to have as this will make your investigation much easier. #blueteam #digitalforensics #cyberdefense
English
0
0
1
98
Spider0x
Spider0x@Cyberagent101·
If you have any addition or an interesting tool you want to share it with the community, please reach out to me and I will add it to the post, I am really interested to know more about how other analysts customize their machines. #malware #blueteam #cybersecuritytips
English
0
0
2
137
Spider0x
Spider0x@Cyberagent101·
Check out my last blog post talking about how I customize my malware analysis machine with tools and plugins that can make my life easier and save me time. blog.cyber5w.com/malware%20anal…
English
1
17
31
2.8K
Spider0x
Spider0x@Cyberagent101·
Just a quick tip for reverse engineering new guys, and any old one who doesn't care. Never rely on Decompiled code only, that always happens to me, but this time that was insane. my decompiler missed tens of lines of functions and API calls.
Spider0x tweet media
English
1
1
2
569
Spider0x
Spider0x@Cyberagent101·
- Junk Code - API Hashing - Encrypted Stack Strings - INT 0x2D instruction - OutputDebugString - Memory Write Watch Here is a detailed analysis of the new version of its Loader part.
English
1
0
0
180
Spider0x
Spider0x@Cyberagent101·
Hey malware analysts, "Pikabot" is a relatively new malware and is considered the second wave of the famous "Qakbot". This malware contains two stages armed with many Anti-Analysis techniques to make defenders' lives harder like: blog.cyber5w.com/malware%20anal…
English
2
16
49
4K
Spider0x
Spider0x@Cyberagent101·
Firmware is really a great place for hunting vulnerabilities these days. here I am discussing how to emulate and reverse firmware binaries by doing research in "DLINK DIR 832G" router "CVE-2023-43241 & CVE-2023-43235" OOB writes. amr-git-dot.github.io/vulnerability%…
English
0
0
1
251
Spider0x
Spider0x@Cyberagent101·
For Malware Analysts & Developers, another trick for executing code before "main" using "_initterm" to hide code. In this small article I discuss how you can get code execution before main using dynamically assigned global variables. amr-git-dot.github.io/malware%20anal… #malware
Spider0x tweet media
English
0
1
2
260
Spider0x
Spider0x@Cyberagent101·
I wonder how two versions of a DLL with only about three months difference can have over 10KB of size. "Microsoft office product"
Spider0x tweet media
English
0
0
2
287
Spider0x
Spider0x@Cyberagent101·
ESXIArgs Ransomware analysis. ESXIArgs Ransomware is widely spread these days due to the wide exploitation of a vulnerability with CVE-2021-21974 which is quite old but is not patched in many ESXI Servers. The malware itself is not complex at all but the danger comes from the
English
1
0
0
362