Felix Bilstein

105 posts

Felix Bilstein banner
Felix Bilstein

Felix Bilstein

@fxb_b

Security Researcher | YARA-Rules for @malpedia using YARA-Signator

Bonn, Germany เข้าร่วม Eylül 2015
551 กำลังติดตาม288 ผู้ติดตาม
Felix Bilstein รีทวีตแล้ว
Malpedia
Malpedia@malpedia·
A new set of auto-generated rules (courtesy of@fxb_b) has been published to Malpedia and GitHub. It includes 1460 updated rules and 136 new additions.
English
0
5
7
1.3K
Felix Bilstein รีทวีตแล้ว
Karsten Hahn
Karsten Hahn@struppigel·
I have spent way too much time on writing this #GootLoader JS unpacker and C2 extractor with abstract syntax tree manipulation. 🌳 But I could not stop at having it half done and this malware has 6 layers. I am sorry for the terrible code. github.com/struppigel/hed…
Karsten Hahn tweet mediaKarsten Hahn tweet media
English
8
48
159
15.8K
Felix Bilstein รีทวีตแล้ว
Karsten Hahn
Karsten Hahn@struppigel·
Awesome project by malpedia creator @push_pnx presented at VB2023 Applied one-to-many code similarity analysis using MCRIT Talk: youtube.com/watch?v=CMu1r5…
YouTube video
YouTube
English
1
17
63
9.6K
Felix Bilstein รีทวีตแล้ว
Fabian Marquardt
Fabian Marquardt@marqufabi·
Extractor updated 🎉 Should now support recent #DarkGate samples and can dump complete config and strings. Still some more Ghidra sessions needed to find out what all the new flags do 😂 github.com/telekom-securi…
Fabian Marquardt tweet media
English
0
2
12
701
Felix Bilstein รีทวีตแล้ว
Daniel Plohmann
Daniel Plohmann@push_pnx·
@mec314 As a follow-up to my previous response, I have now started populating another Github repo with ready-to-use reference data: github.com/danielplohmann… I'm currently running automated extraction for all available MinGW versions and back-process my MSVC symbols for a first milestone.
English
0
1
3
124
Felix Bilstein รีทวีตแล้ว
Malpedia
Malpedia@malpedia·
Another iteration of the YARA-Signator rule set has been generated by @fxb_b and has been published to Malpedia and GitHub. It includes 1273 updated rules and 44 new additions.
English
1
4
16
2.6K
Felix Bilstein รีทวีตแล้ว
Marc R
Marc R@Seifreed·
We live in the automation era, recently I played with one of my favorite tools @radareorg main developers Mr. @trufae to automate the #malware analysis using it with @OpenAI
Marc R tweet media
English
2
9
24
4.3K
Felix Bilstein รีทวีตแล้ว
x64dbg
x64dbg@x64dbg·
The first commit of x64dbg was 10 years ago today (2013-05-19). Writing a retrospective is harder than I thought, but here is a screenshot of the first version as a sneak peak. Thanks to everybody in the community for the support over the years! Duncan
x64dbg tweet media
English
16
174
1K
109.7K
Felix Bilstein รีทวีตแล้ว
Malpedia
Malpedia@malpedia·
We just published a new iteration of the YARA-Signator rule set has been generated by @fxb_b and published it to Malpedia and GitHub. It includes 1272 updated rules with 33 new additions.
English
0
5
9
1.7K
Felix Bilstein รีทวีตแล้ว
Andre Pawlowski
Andre Pawlowski@sqall01·
I was always searching for a cool open source replacement for the 010 Editor. Since I rarely need it, buying it seemed a waste. But it seems my search is at an end. A colleage just send me github.com/WerWolv/ImHex and the first impression is great!
English
3
58
234
20.5K
Felix Bilstein รีทวีตแล้ว
DFRWS
DFRWS@DFRWS·
After a great boat ride in the Rhine last night the Forensic Rodeo took place courtesy of the NFI Forensic Rodeo team! Congratulations to the winning team JimmyThreePockets 🥇🥇 #DFRWSEU2023 #DFIR
DFRWS tweet media
English
0
5
11
2.5K
Felix Bilstein รีทวีตแล้ว
0xor0ne
0xor0ne@0xor0ne·
Cool blog post by Karsten König (@CrowdStrike) showing how to modify an existing Linux kernel exploit (CVE-2021-3490) to achieve container escape crowdstrike.com/blog/exploitin…
0xor0ne tweet media0xor0ne tweet media0xor0ne tweet media
English
2
90
247
23.1K
Felix Bilstein รีทวีตแล้ว
Lorenzo Romani
Lorenzo Romani@lorenzoromani·
[THREAD] Finding the real IP of a Cloudflare-hidden website has always been challenging. There are interesting tools out there such as fav-up, written by @noneprivacy, which leverages Shodan to find the real IP address via a favicon lookup. However, you can often find the IP...
English
7
132
454
52.2K