Johannes Bader

196 posts

Johannes Bader banner
Johannes Bader

Johannes Bader

@viql

Reverse engineer / malware analyst. On the hunt for domain generation algorithms. Current side project: https://t.co/Cv3COq0ZmR

Schweiz Katılım Ağustos 2013
166 Takip Edilen1.8K Takipçiler
abuse.ch
abuse.ch@abuse_ch·
@andretavare5 This error message happens if the API is overloaded.
English
1
0
0
85
Johannes Bader
Johannes Bader@viql·
Today, I'm releasing the first version of a small web 🚀: rosti.bin.re It provides IOCs and YARA rules collected semi-automatically from public blog posts and reports of almost 200 cybersecurity sites. I hope it proves useful to some of you ... 🙏✨ #ThreatIntel
Johannes Bader tweet media
English
17
124
372
32.3K
Johannes Bader retweetledi
abuse.ch
abuse.ch@abuse_ch·
According to @GovCERT_CH , an unknown threat actor has sent out postal letters (yes, *postal* letters ✉️) to recipients in Switzerland that pretend to originate from @meteoschweiz, luring the recipient into downloading and installing a rogue App 🔥🕵️‍♂️ The QR code in the letter leads to a malicious App that impersonating the "AlertSwiss" App of the federal administration. However, the App in fact is a version of Coper (aka Octo2) #malware, infecting mobile phones running Android 📱🤖 Payload delivery URL: 🌐 urlhaus.abuse.ch/url/3290212/ Malware sample: 📄 bazaar.abuse.ch/sample/4928c56… Coper botnet C2: 🔥 threatfox.abuse.ch/ioc/1344824/ncsc.admin.ch/ncsc/en/home/a…
English
0
29
79
27.5K
Johannes Bader retweetledi
ThreatCat.ch
ThreatCat.ch@threatcat_ch·
We're proud to be a @Quad9DNS partner, helping make the Internet a safer place!
ThreatCat.ch tweet media
English
0
4
14
5.6K
Johannes Bader
Johannes Bader@viql·
@_mostwanted002_ This is the #khalesi info stealer. The DGA picks 10 random alphanumeric characters with a common Mersenne Twister implementation. Unfortunately, the seed is just the current tick count, so unpredictable for both the attackers and analysts.
Johannes Bader tweet mediaJohannes Bader tweet media
English
1
0
1
32
Mayank Malik
Mayank Malik@_mostwanted002_·
First time detonating a sample that uses DGA. O.O Sample: 004a56d1896512f7a6c5793fe7aa5919 #malware #threatintel
Mayank Malik tweet media
English
1
0
2
664
Johannes Bader retweetledi
ThreatCat.ch
ThreatCat.ch@threatcat_ch·
New video on the Domain Generation Algorithm of the file infector m0yv. We've sinkholed multiple domains & show how infections dramatically increased in the last 400+ days 📈. #m0yv #DGA youtu.be/3RYbkORtFnk
YouTube video
YouTube
ThreatCat.ch tweet media
English
1
5
6
1.4K