Sushil Singh

5.3K posts

Sushil Singh banner
Sushil Singh

Sushil Singh

@SushilSin

The quieter you become, the more you are able to hear.

India Katılım Ağustos 2012
748 Takip Edilen441 Takipçiler
Sushil Singh retweetledi
vx-underground
vx-underground@vxunderground·
This is very good malware. This is solid-solid-SOLID B+ malware, very close to A- malware. APT37 is using a old-school playbook. They're doing EPO (Entry Point Obfuscation) on a self-delivered binary for evasion. They also unironically are using something akin to cavity infection ... but on themselves. This is something you saw more in the Windows 95 - Windows XP era, not something you see in 2026. Very cool. I respect it. The multi-staged fragmentation of shellcode phases is also really, really, really cool. This is (once again) a more old-school technique usually reserved for infected binaries, not self-delivered binaries. Despite all of these super cool features, APT37 shoots themselves in the foot immediately. - EAT walking for Kernel32 functionality (???) - XOR decryption is a huge red flag - Allocating with PAGE_EXECUTE_READWRITE (???) - Hardcoded OAuth token (???) - Used external dependency for AES (???) Why not use NT functionality to hook evasion? XOR is easily identified in static analysis, why XOR? Allocating memory with VirtualAlloc with RWX is a MASSIVE RED FLAG. They also hardcode a OAuth token ... they can multi-staged shellcode payload with old-school malware techniques but hardcore AN OAUTH TOKEN? It unironically makes me wonder if they had one old-head malware guy working on it, then they had some newer dude do the non-hardcore stuff. There is a huge gap in skill sets here. Or the old-head hasn't kept up to date on malware stuff since 2005... or they got lazy... I don't know, really weird.
Virus Bulletin@virusbtn

Genians Security Center uncovers an APT37 campaign that used social networking as an initial access vector. Two Facebook accounts set to North Korea-linked locations were used to screen targets, build trust, and move conversations to Messenger. genians.co.kr/en/blog/threat…

English
15
152
1.1K
85.9K
Sushil Singh retweetledi
Tom Dörr
Tom Dörr@tom_doerr·
open-source face recognition REST API with docker support
Tom Dörr tweet media
English
6
191
1.5K
78.7K
Sushil Singh retweetledi
Dark Web Informer
Dark Web Informer@DarkWebInformer·
Telegram Maltego: A free set of Transforms for Maltego that enables OSINT investigations in the Telegram messenger GitHub: github.com/vognik/maltego…
Dark Web Informer tweet media
English
3
76
404
38.1K
Md Riyazuddin
Md Riyazuddin@riyazmd774·
This lady exposed the dark truth about recycling. She dropped an AirTag in her recycling bin to find out where it really went. Her experiment uncovered a sinister 250-ton secret... Here's the full story: 🧵
Md Riyazuddin tweet mediaMd Riyazuddin tweet media
English
59
200
1.5K
506.4K
Sushil Singh retweetledi
Rahul Gehlaut
Rahul Gehlaut@rahul_gehlaut·
🎉🎉 Celebrating Success! Airtel's Live Bug Bounty Triumph at nullcon Goa 🛡️ Huge shoutout to the talented ethical hackers and security experts who made this event a tremendous success. Your dedication to cybersecurity is truly commendable. 🙌👏 #nullconGoa #BugBounty #Airtel
Rahul Gehlaut tweet mediaRahul Gehlaut tweet mediaRahul Gehlaut tweet mediaRahul Gehlaut tweet media
English
0
4
15
1.2K
Sushil Singh retweetledi
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
English
23
220
496
68K