herrcore(@herrcore) 's Twitter Profileg
herrcore

@herrcore

UnpacMe | OALABS

ID:43022669

linkhttp://www.openanalysis.net/ calendar_today28-05-2009 02:03:24

8,1K Tweets

11,9K Followers

475 Following

Zscaler ThreatLabz(@Threatlabz) 's Twitter Profile Photo

development continues with new versions that include an anti-analysis feature that prevents samples from being executed on another system after an initial infection. This is likely inspired by the leaked source code that implements a similar feature.

Read the…

#Zloader development continues with new versions that include an anti-analysis feature that prevents samples from being executed on another system after an initial infection. This is likely inspired by the leaked #ZeuS source code that implements a similar feature. Read the…
account_circle
herrcore(@herrcore) 's Twitter Profile Photo

Ever wonder what is buried in a 10 year old file infector? What files has it collected over the years?

Join us at 1300 EST today and find out!


Ever wonder what is buried in a 10 year old file infector? What files has it collected over the years? Join us at 1300 EST today and find out! #OALabsLive #SundaySandboxCentipede
account_circle
UNPACME(@unpacme) 's Twitter Profile Photo

Self-replicating malware, long abandoned by its operators, continues to contribute significant volume and noise to malware feeds.

We investigate this trend, which we refer to as 𝗭𝗼𝗺𝗯𝗶𝗲𝘄𝗮𝗿𝗲 🧟‍♂️

blog.unpac.me/2024/04/25/zom…

account_circle
herrcore(@herrcore) 's Twitter Profile Photo

Honoured to be presenting the keynote for NorthSec this year. If you are in the neighbourhood May 16-17 come say hi, tickets are still available😺

Unpack all malware with a single breakpoint? Maybe? And I promise I won't mention anything about LLMs!

nsec.io

account_circle
John Hammond(@_JohnHammond) 's Twitter Profile Photo

💥 The Github comments upload malware conversation.

Candidly I wanted to record this a month ago, but now that it's in the news, I'm late to the punch and needed to talk about.😅 We do a quick demo on the upload trick, and showcase ANOTHER technique.. 😁
youtu.be/0wduZ3nO848

💥 The Github comments upload malware conversation. Candidly I wanted to record this a month ago, but now that it's in the news, I'm late to the punch and needed to talk about.😅 We do a quick demo on the upload trick, and showcase ANOTHER technique.. 😁 youtu.be/0wduZ3nO848
account_circle
herrcore(@herrcore) 's Twitter Profile Photo

Since it is back in the news here is some info on SmartLoader that mysterious LUA malware...

The name SmartLoader comes from the UserAgent string used in early builds of the malware (cc Who said what), the true name is currently unknown.

There are at least two different versions of…

Since it is back in the news here is some info on SmartLoader that mysterious LUA malware... The name SmartLoader comes from the UserAgent string used in early builds of the malware (cc @g0njxa), the true name is currently unknown. There are at least two different versions of…
account_circle
BleepingComputer(@BleepinComputer) 's Twitter Profile Photo

A GitHub flaw (or bad design decision) is being abused to distribute malware through URLs linked to Microsoft’s repository, and others, to make the files appear trustworthy.
bleepingcomputer.com/news/security/…

account_circle
Alęxandęr Hanęl(@nullandnull) 's Twitter Profile Photo

Daniel Mayer herrcore Vector 35 Josh Reynolds (jmag) Binary Ninja’s strengths are its API (especially when accessing the decompiler) and its headless mode (sadly that’s only in the commercial version.) Here is a cheat sheet for binary ninja I created a while back.

gist.github.com/alexander-hane…

account_circle
Daniel Mayer(@dan__mayer) 's Twitter Profile Photo

I got selected by Vector 35 for a free Binja license for filling out their survey! Do all my Binja folks have suggestions on where to read up on the differences from ida/what are the strengths/weaknesses?

Josh Reynolds (jmag) herrcore ?

account_circle
Josh Reynolds (jmag)(@JershMagersh) 's Twitter Profile Photo

If you’re interested in structure recovery in Binary Ninja this stream highlights their auto-generate functionality and interfaces for constructing them. Havoc is actually a pretty nice example for this. Enjoy!

account_circle
Daax(@daaximus) 's Twitter Profile Photo

Why are Google dorks returning fewer results now? The search quality has degraded significantly in the last few weeks (more than the usual degradation). Previously working queries fail to find anything, yet the sites remain unchanged. Something feels off recently; anyone else?

account_circle
Vector 35(@vector35) 's Twitter Profile Photo

Last chance to give your feedback! Reminder, our survey is only live for two more days before the prize drawing ends.

binary.ninja/survey/

Last chance to give your feedback! Reminder, our survey is only live for two more days before the prize drawing ends. binary.ninja/survey/
account_circle
BruCON(@brucon) 's Twitter Profile Photo

🚨🍻🚨 Some very nice CFP submissions are coming in for both Talks, Training and Workshops! Don't hesitate submitting yours before the CFP closes end of this month! Check it out at brucon.org/2024/cfp/ 🚨🍻🚨

account_circle
cts🌸(@gf_256) 's Twitter Profile Photo

Source: They’re building a next-gen obfuscator suitable for modern binaries Back Engineering Labs. They can do binary-to-binary translation of Windows kernel, CSGO, Chromium, Hyper-V, while respecting CFG, ACG, CET

Source: They’re building a next-gen obfuscator suitable for modern binaries @BackEngineerLab. They can do binary-to-binary translation of Windows kernel, CSGO, Chromium, Hyper-V, while respecting CFG, ACG, CET
account_circle
Vector 35(@vector35) 's Twitter Profile Photo

We want your feedback! Reminder, our survey is live for another week and half before the prize drawing ends.

binary.ninja/survey/

We want your feedback! Reminder, our survey is live for another week and half before the prize drawing ends. binary.ninja/survey/
account_circle