Adam

44 posts

Adam

Adam

@malworms

IDA pro enthusiast, malware reverser, addicted to Rocket League. @PwC_uk Threat Intelligence. All views my own.

Присоединился Ağustos 2020
61 Подписки292 Подписчики
Adam ретвитнул
Virus Bulletin
Virus Bulletin@virusbtn·
Google's Nino Isakovic analyses the ScatterBrain obfuscator, used on POISONPLUG variants. ScatterBrain appears to be a substantial evolution of ScatterBee, an obfuscating compiler previously analysed by PWC. cloud.google.com/blog/topics/th…
Virus Bulletin tweet media
English
0
19
52
3.7K
Adam ретвитнул
Mandiant (part of Google Cloud)
Ever wonder how attackers use advanced tools to evade detection? Mandiant analyzes #ScatterBrain, an obfuscator in the POISONPLUG.SHADOW backdoor, which is used by China-nexus actors. Learn how we’re unmasking these sophisticated threats. Read more: bit.ly/42xfceL
Mandiant (part of Google Cloud) tweet media
English
0
36
77
7.3K
Adam
Adam@malworms·
For anyone using Binary Ninja and wanting to use Mandiant's ShellcodeHashes IDA plugin-I ported a basic version of the IDA plugin to Binary Ninja: github.com/PwCUK-CTO/Bina… Known limitations - No GUI, no support for searching memory constants - but it works well for most use cases
English
0
10
25
2.2K
Adam ретвитнул
Ivan Kwiatkowski
Ivan Kwiatkowski@JusticeRage·
Step 1: open a binary in IDA and press F5 Step 2: paste the decompiled code into OpenAI's chatbot Someone's job just got way easier.
Ivan Kwiatkowski tweet mediaIvan Kwiatkowski tweet media
English
56
803
4.3K
0
Adam
Adam@malworms·
@c3rb3ru5d3d53c Looks very much like the technique lockbit is currently using to me 🧐
English
0
0
1
0
Adam
Adam@malworms·
@fr0gger_ Alt+F7 feels like a bit of an omission. Used way more by me than most on this list...
English
0
0
0
0
Adam ретвитнул
David Cannings
David Cannings@edeca·
Recently uploaded ShadowPad #malware (6e99974b8d421f8923fc132487d7da0d22c5e0fa1940494f312f9c9389c3f4ca) uses C2 login[.]onesigh[.]com. The Root module is from November 2020. Working on ShadowPad? DMs are open for collaboration #threatintel
English
1
8
26
0
Adam ретвитнул
French
French@notareverser·
What the heck is Shikata ga nai? Nothing can be done but spit out a thread
English
2
9
19
0
Adam
Adam@malworms·
@zcracga Thanks a lot!
English
0
0
0
0
Adam
Adam@malworms·
@LloydLabs Thanks mate, was a fun one to work through.
English
0
0
1
0
Adam
Adam@malworms·
extra - IDA determines if a binary is Golang or not only by the presence of the Go build string. The build string does not need to be correctly formed, just finding space in the .text section with enough CC alignment and pasting that string in lets IDA work properly @HexRaysSA
Adam tweet media
Jiří Vinopal@vinopaljiri

If you are reversing latest #Hive #Ransomware (written in GO) be careful about intentionally missing "Go build ID" string in compiled binary - latest IDA 7.6 will not treat it as GO compiled binary and no func will be recognized (Patch it -> Load it -> Patch it back).🙏😉

English
0
0
6
0