Sushil Singh
5.3K posts

Sushil Singh
@SushilSin
The quieter you become, the more you are able to hear.
India Katılım Ağustos 2012
748 Takip Edilen441 Takipçiler
Sushil Singh retweetledi

This is very good malware.
This is solid-solid-SOLID B+ malware, very close to A- malware.
APT37 is using a old-school playbook. They're doing EPO (Entry Point Obfuscation) on a self-delivered binary for evasion. They also unironically are using something akin to cavity infection ... but on themselves. This is something you saw more in the Windows 95 - Windows XP era, not something you see in 2026.
Very cool. I respect it.
The multi-staged fragmentation of shellcode phases is also really, really, really cool. This is (once again) a more old-school technique usually reserved for infected binaries, not self-delivered binaries.
Despite all of these super cool features, APT37 shoots themselves in the foot immediately.
- EAT walking for Kernel32 functionality (???)
- XOR decryption is a huge red flag
- Allocating with PAGE_EXECUTE_READWRITE (???)
- Hardcoded OAuth token (???)
- Used external dependency for AES (???)
Why not use NT functionality to hook evasion? XOR is easily identified in static analysis, why XOR? Allocating memory with VirtualAlloc with RWX is a MASSIVE RED FLAG. They also hardcode a OAuth token ... they can multi-staged shellcode payload with old-school malware techniques but hardcore AN OAUTH TOKEN?
It unironically makes me wonder if they had one old-head malware guy working on it, then they had some newer dude do the non-hardcore stuff. There is a huge gap in skill sets here.
Or the old-head hasn't kept up to date on malware stuff since 2005... or they got lazy... I don't know, really weird.
Virus Bulletin@virusbtn
Genians Security Center uncovers an APT37 campaign that used social networking as an initial access vector. Two Facebook accounts set to North Korea-linked locations were used to screen targets, build trust, and move conversations to Messenger. genians.co.kr/en/blog/threat…
English
Sushil Singh retweetledi

Sushil Singh retweetledi

Sushil Singh retweetledi

Sushil Singh retweetledi

Sushil Singh retweetledi
Sushil Singh retweetledi

Telegram Maltego: A free set of Transforms for Maltego that enables OSINT investigations in the Telegram messenger
GitHub: github.com/vognik/maltego…

English
Sushil Singh retweetledi

🎉🎉 Celebrating Success! Airtel's Live Bug Bounty Triumph at nullcon Goa 🛡️
Huge shoutout to the talented ethical hackers and security experts who made this event a tremendous success. Your dedication to cybersecurity is truly commendable. 🙌👏 #nullconGoa #BugBounty #Airtel




English
Sushil Singh retweetledi
Sushil Singh retweetledi

😎For the past 3 editions, Airtel has been a strong supporter!
👊Super thrilled to welcome @airtelindia as our 🥈Silver Sponsor with a new identity
Keep an eye out on Live bug bounty 💰bit.ly/3VWR8g6
#NullconGoa2023 #Infosec #Conference

English
Sushil Singh retweetledi

Hey #bughunters! 🟢Application for Private Live Bug Hunting is now open
Rewards upto ₹10,00,000 | 🎯Target to hunt #vulnerabilities provided by @airtelindia & @fractalai
Apply before 7th Sep➡️rebrand.ly/Livebughunting
#NullconGoa2023 #bughunting #Infosec #Conference

English
Sushil Singh retweetledi

👨💻Unleash your #hacking skills! Rewards up to 💰₹10,00,000 at stake with Targets to hunt provided by @airtelindia & @fractalai
👊Application for Private Live Bug Hunting ends on 7th Sep➡️rebrand.ly/Livebughunting
#NullconGoa2023 #bughunting #Infosec #Conference

English
Sushil Singh retweetledi

🕰️You have just few hours left to submit your application for 👩💻Live Bug hunting!
⚠️Select 50 participants will get a chance | Apply soon ➡️ rebrand.ly/Livebughunting
#NullconGoa2023 #Infosec #Conference #bugbounty | @airtelindia | @fractalai
GIF
English

Calling all security enthusiasts, bug bounty seekers, and researchers.
A live bug bounty competition is being held by Bharti Airtel at @nullcon Goa-2023 @antriksh_s @rahul_gehlaut @airtelindia
register here: share.hsforms.com/1aCwUg2GhSYWXB…

English
Sushil Singh retweetledi

Sushil Singh retweetledi

Defcon Conference Slides Presentations 22-30
Credit: @C0d3Cr4zy
↓↓
Defcon 22 All Slides
media.defcon.org/DEF%20CON%2022…
Defcon 23 All Slides
media.defcon.org/DEF%20CON%2023…
Defcon 24 All Slides
media.defcon.org/DEF%20CON%2024…
Defcon 25 All Slides
media.defcon.org/DEF%20CON%2025…
Defcon 26 All Slides
media.defcon.org/DEF%20CON%2026…
Defcon 27 All Slides
media.defcon.org/DEF%20CON%2027…
Defcon 28 All Slides
media.defcon.org/DEF%20CON%2028…
Defcon 29 All Slides
media.defcon.org/DEF%20CON%2029…
Defcon 30 All Slides
media.defcon.org/DEF%20CON%2030…
#cybersecurity #Pentesting #Hacking #bugbountytips #infosec #cybersecuritytips #redteam #coding #vulnerabilities #BugBounty #CyberSecurityAwareness
English
Sushil Singh retweetledi

😎For the past 3 editions, Airtel has been a strong supporter! 👊Super thrilled to welcome back Airtel @airtelindia as our 🥈Silver Sponsor
Keep an eye out on Live bug bounty 💰bit.ly/3VWR8g6
#NullconGoa2023 #Infosec #Conference

English










