Tweetovi

Blokirali ste korisnika/cu @MalwareUtkonos

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @MalwareUtkonos

  1. Prikvačeni tweet
    19. velj 2019.

    I've just kicked off a new blog series on reverse engineering. Please check it out and upvote!

    Prikaži ovu nit
    Poništi
  2. proslijedio/la je Tweet
    prije 16 sati
    Odgovor korisnicima i sljedećem broju korisnika:
    Poništi
  3. proslijedio/la je Tweet
    prije 16 sati
    Odgovor korisnicima i sljedećem broju korisnika:

    Still #1 on Pastebin with Indonesian, Moroccan, and Syrian teenagers.

    Poništi
  4. proslijedio/la je Tweet
    prije 22 sata

    wow ... is still used? /bwawusa.org/system/nj6pp.exe VT:1c846c9281998ea2b6c4493e3ccafad6 c2:mailsdc61,ga

    Poništi
  5. proslijedio/la je Tweet
    4. velj

    2020-02-03: 📌🔥[Researcher Pin] 🐍/ Ransomware Analysis & ICS Targeting Perspective 🔦As the ransomware strain was first identified and discovered with myself & hunting for Golang ransomware. 💭Sober outlook & analysis from the intel perspective.

    Poništi
  6. proslijedio/la je Tweet
    prije 21 sat

    Though, to be fair... The original request for some of these features came from Sir Tom of the House of Lancaster (). Credit where credit is due, of course. ;)

    Prikaži ovu nit
    Poništi
  7. proslijedio/la je Tweet
    prije 21 sat

    Since I convert the RVA to a file offset you can even check to see if enough functions are all "xor eax, eax; retn;" - which is pretty dope to be able to do so easily. There are other things this branch lets you do too, but I'll leave that up to you all to come up with. ;) 3/?

    Prikaži ovu nit
    Poništi
  8. proslijedio/la je Tweet
    prije 21 sat

    After trying it out he came up with these rules: - which are MUCH nicer to read/write, and the extra features of the branch provide increased functionality. He can compare the compiled dll name (from the export table) to the legitimate one... 2/?

    Prikaži ovu nit
    Poništi
  9. proslijedio/la je Tweet
    prije 21 sat

    Woke up this morning to a message from about a crazy YARA rule he wrote () to look for DLLs where exported functions are at the same RVA. I suggested he look into testing my pending PR (). 1/?

    Prikaži ovu nit
    Poništi
  10. proslijedio/la je Tweet
    prije 23 sata

    Now over 400K burgers served!

    Poništi
  11. proslijedio/la je Tweet
    4. velj

    1.3 is out! () lots of features from dev landing on stable.

    Poništi
  12. proslijedio/la je Tweet
    4. velj

    Just got a call pretending to be and to call 800.439.9042 "to avoid service disruption". Freakin' scammers!

    Poništi
  13. proslijedio/la je Tweet
    3. velj
    Odgovor korisnicima

    A good commit message should be 1/3 what you did and 2/3 why you did it. Learned that a long time ago and try to live by it and share it with others. I can’t count the number of times I’ve dug out an ancient commit and the message helped me instantly remember what I did and why.

    Poništi
  14. proslijedio/la je Tweet
    3. velj
    Odgovor korisnicima

    Your commit logs and documentation are always superb, thanks! Makes great reading.

    Poništi
  15. 3. velj
    Prikaži ovu nit
    Poništi
  16. 3. velj
    Prikaži ovu nit
    Poništi
  17. proslijedio/la je Tweet
    3. velj

    If you're one of the places which use the dotnet module (we use it at ) it's worth noting that it will break rules if you're looking for specific user strings. I don't like breaking backwards compatibility but getting parsing correct is important in this case. 2/2

    Prikaži ovu nit
    Poništi
  18. proslijedio/la je Tweet
    3. velj

    So pointed out some weird user strings in some .NET binaries parsed by YARA. There were occasionally a trailing \x01. Turns out I missed a paragraph in the documentation which caused this bug, but I put up a fix at . 1/2

    Prikaži ovu nit
    Poništi
  19. 3. velj

    Fake coronavirus charity site.

    Prikaži ovu nit
    Poništi
  20. 3. velj

    hxxps[://]www[.]coronavirusfund[.]org/sales-page36138196 Fake Coronavirus charity site

    Prikaži ovu nit
    Poništi
  21. proslijedio/la je Tweet
    2. velj

    Name a more iconic duo: and bbq. Pork belly burnt ends .. so good.

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·