M4lcode (@m4lcode) 's Twitter Profile
M4lcode

@m4lcode

Threat Researcher @DeXpose | Blog Author @ ANY.RUN & @cyber5w | Malware Researcher & CTI

ID: 1627422920652759041

linkhttps://m4lcode.github.io calendar_today19-02-2023 21:41:24

162 Tweet

469 Followers

231 Following

M4lcode (@m4lcode) 's Twitter Profile Photo

Fake job interviews are a growing attack vector One example here is InvisibleFerret, a malware from North Korea, that targets tech professionals See detailed analysis of its code and collect IOCs to avoid infection by Mauro Eldritch 🏴‍☠️ any.run/cybersecurity-… ANY.RUN

M4lcode (@m4lcode) 's Twitter Profile Photo

FExcited to share that ANY.RUN now supports Android OS inside its interactive sandbox! You can analyze APK behavior in real time, right in the cloud. 🔥 Available for ALL plans (yes, even free!). 📷 Let’s check it out together! app.any.run/?utm_source=x_…

FExcited to share that ANY.RUN now supports Android OS inside its interactive sandbox! You can analyze APK behavior in real time, right in the cloud.  🔥 Available for ALL plans (yes, even free!).  📷 Let’s check it out together! app.any.run/?utm_source=x_…
Gameel Ali 🤘 (@malgamy12) 's Twitter Profile Photo

We’re excited to announce the launch of malops.io , a platform built by analysts, for analysts and it’s completely free. You can join and enjoin with our frist challenge about RokRat Loader.

We’re excited to announce the launch of malops.io , a platform built by analysts, for analysts  and it’s completely free.
You can join and enjoin with our frist challenge about RokRat Loader.
M4lcode (@m4lcode) 's Twitter Profile Photo

#clickfix #booking #fakecaptcha bokparthub[.]click → (Under Construction) apartmenr-di16[.]click → PowerShell (files.catbox.moe/09fd7c[.]txt) → LightYellow4.zip → LightYellow4.pfx Hex-based ZIP reconstructed → payload cleaned → executed via regsvr32.exe abuse (LOLBins)

#clickfix #booking #fakecaptcha
bokparthub[.]click → (Under Construction)

apartmenr-di16[.]click → PowerShell (files.catbox.moe/09fd7c[.]txt) → LightYellow4.zip → LightYellow4.pfx Hex-based ZIP reconstructed → payload cleaned → executed via regsvr32.exe abuse (LOLBins)
M4lcode (@m4lcode) 's Twitter Profile Photo

Open directory spotted: 20.243.255[.]185 Hosting multiple suspicious files, including: shell_le: Metasploit ELF payload - recently submitted to VirusTotal. true.png: PNG file with embedded VBScript (1/61 on VT) - recently submitted to VirusTotal main_mips: ELF binary flagged

Open directory spotted: 20.243.255[.]185
Hosting multiple suspicious files, including:

shell_le: Metasploit ELF payload - recently submitted to VirusTotal.

true.png: PNG file with embedded VBScript (1/61 on VT) - recently submitted to VirusTotal

main_mips: ELF binary flagged
Mohamed Sultan (@msult4n) 's Twitter Profile Photo

Just published a new blog post on how Microsoft’s “Mouse Without Borders” can be abused for data exfiltration & lateral movement. Features KAPE Target, C# scripts, and a BOF as a poc: 0xsultan.github.io/dfir/Exfiltrat…

Muhammad Hasan Ali (@muha2xmad) 's Twitter Profile Photo

As-salamu Alaykum I wrote 3 #yara rules about #RedLine stealer , #ArrowRAT, and #MilleniumRat. RedLine:github.com/muha2xmad/yara… ArrowRAT:github.com/muha2xmad/yara… MilleniumRat:github.com/muha2xmad/yara…

Thomas Roccia 🤘 (@fr0gger_) 's Twitter Profile Photo

👀 OpenSource Malware an open database for tracking malicious open-source packages from npm, PyPI, GitHub repos! Great source of intel feed for supply-chain attacks! 👇 opensourcemalware.com

👀 OpenSource Malware an open database for tracking malicious open-source packages  from npm, PyPI, GitHub repos!

Great source of intel feed for supply-chain attacks! 👇

opensourcemalware.com
RussianPanda 🐼 🇺🇦 (@russianpanda9xx) 's Twitter Profile Photo

Good morning! ☀️ #GootLoader woke up and chose violence (again) Grab your coffee, this one's JUICY 💣 huntress.com/blog/gootloade…

M4lcode (@m4lcode) 's Twitter Profile Photo

🔴 Live stream alert! Join Mauro Eldritch to dissect FunkLocker; AI-powered #FunkSec ransomware behind 120+ attacks across North America and Asia. 🕒 Time: Nov 12, 3:00 PM UTC 🔔 Set a reminder: youtube.com/live/PiWOtiYs2… ANY.RUN

🔴 Live stream alert!

Join Mauro Eldritch to dissect FunkLocker; AI-powered #FunkSec ransomware behind 120+ attacks across North America and Asia.

🕒 Time: Nov 12, 3:00 PM UTC

🔔 Set a reminder: youtube.com/live/PiWOtiYs2…

<a href="/anyrun_app/">ANY.RUN</a>
ANY.RUN (@anyrun_app) 's Twitter Profile Photo

🔴 LIVE from inside #Lazarus APT's IT workers scheme. For weeks, BCA LTD & NorthScan kept #hackers believing they controlled a US dev's laptop. In reality, it was our sandbox recording everything. See full story and videos ⬇️ any.run/cybersecurity-…

🔴 LIVE from inside #Lazarus APT's IT workers scheme.
 
For weeks, <a href="/BirminghamCyber/">BCA LTD</a> &amp; <a href="/north_scan/">NorthScan</a> kept #hackers believing they controlled a US dev's laptop. In reality, it was our sandbox recording everything.
 
See full story and videos ⬇️
any.run/cybersecurity-…