Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @MalwareUtkonos
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @MalwareUtkonos
-
Prikvačeni tweet
I've just kicked off a new blog series on reverse engineering. Please check it out and upvote!https://steemit.com/reverse/@utkonos/alphablend-malware …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Malware Utkonos proslijedio/la je Tweet
Still #1 on Pastebin with Indonesian, Moroccan, and Syrian teenagers.pic.twitter.com/icA8RaqkjM
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
wow ...
#njrat is still used? /bwawusa.org/system/nj6pp.exe VT:1c846c9281998ea2b6c4493e3ccafad6 c2:mailsdc61,ga@James_inthe_box@jcarndt@JAMESWT_MHT@500mk500Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
2020-02-03:

[Researcher Pin] 
#EKANS/#SNAKE Ransomware Analysis & ICS Targeting Perspective
As the ransomware strain was first identified and discovered with myself & @malwrhunterteam hunting for Golang ransomware.
Sober outlook & analysis from the intel perspective.https://twitter.com/DragosInc/status/1224350671761289218 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
Though, to be fair... The original request for some of these features came from Sir Tom of the House of Lancaster (
@tlansec). Credit where credit is due, of course. ;)Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
Since I convert the RVA to a file offset you can even check to see if enough functions are all "xor eax, eax; retn;" - which is pretty dope to be able to do so easily. There are other things this branch lets you do too, but I'll leave that up to you all to come up with. ;) 3/?
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
After trying it out he came up with these rules: https://gist.github.com/edeca/42c1961ecde43c8e26645fdad14f4405 … - which are MUCH nicer to read/write, and the extra features of the branch provide increased functionality. He can compare the compiled dll name (from the export table) to the legitimate one... 2/?
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
Woke up this morning to a message from
@edeca about a crazy YARA rule he wrote (https://gist.github.com/edeca/cdc1657fa8a46b8ba45ad732377c035c …) to look for DLLs where exported functions are at the same RVA. I suggested he look into testing my pending PR (https://github.com/VirusTotal/yara/pull/1097 …). 1/?Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
Now over 400K burgers served!
#MalBeaconpic.twitter.com/kVFG81PGHv
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
1.3 is out! (https://binary.ninja/2020/02/03/1.3.html …) lots of features from dev landing on stable.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
Just got a
#scam call pretending to be@DominionEnergy and to call 800.439.9042 "to avoid service disruption". Freakin' scammers!pic.twitter.com/Al4xMauAAhHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
A good commit message should be 1/3 what you did and 2/3 why you did it. Learned that a long time ago and try to live by it and share it with others. I can’t count the number of times I’ve dug out an ancient commit and the message helped me instantly remember what I did and why.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
Your commit logs and documentation are always superb, thanks! Makes great reading.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
coronavirusfund[.]org Still up: https://urlscan.io/result/8b7d396b-618a-4acf-b9a4-2eff63021be7 … https://urlscan.io/result/ea753141-66f6-4dac-b89d-43acaedda738 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
If you're one of the places which use the dotnet module (we use it at
$job) it's worth noting that it will break rules if you're looking for specific user strings. I don't like breaking backwards compatibility but getting parsing correct is important in this case. 2/2Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
So
@MalwareUtkonos pointed out some weird user strings in some .NET binaries parsed by YARA. There were occasionally a trailing \x01. Turns out I missed a paragraph in the documentation which caused this bug, but I put up a fix at https://github.com/VirusTotal/yara/pull/1207 …. 1/2Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
hxxps[://]www[.]coronavirusfund[.]org/sales-page36138196 Fake Coronavirus charity site
@briankrebspic.twitter.com/nT1bJdJir5
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Malware Utkonos proslijedio/la je Tweet
Name a more iconic duo:
@drinkhighwest and bbq. Pork belly burnt ends .. so good.pic.twitter.com/HwsYhr9KFc
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
