Source Byte
Ir al canal en Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Mostrar más8 154
Suscriptores
+2124 horas
+707 días
+31530 días
Archivo de publicaciones
8 152
Repost from Unk9vvN
#puNK Lilith #RAT #Autolt
گروه تهدید آسیای شرقی با نام puNK اخیرا حملاتی رو انجام داده است که نکات فنی مفیدی را میتواند داشته باشد.
زنجیره حمله به این صورت بوده که یک فایل فرمت LNK به محض اجرا شدن، یک کد Powershell رو بر روی خط فرمان cmd بصورت مبهم سازی شده اجرا میکند.
این اجرا موجب میشود یک فایل با نام Decoy دانلود و اجرا شود، اما در ادامه اجرای کد Powershell، یک فایل
curl.exe دانلود و اجرا میشود که البته با نام تصادفی ساخته شده است، همچنین ساخت پوشه C:\GSILzFnTov و ریختن فایل اجرایی Autolt3.exe و فایل اسکریپت آن که با نام QwbpjvdmTA.au3 است.
کد Powershell مرحله اول، بعد از دانلود و اجرای 2 فایل مرتبط با autolt3 بواسطه فایل curl.exe، یک Persistence نیز با schtasks.exe میسازد تا در یک بازه زمانی مشخص فایل بدافزار اجرا شود.
بعد از اجرای بدافزار، مهاجم اقدام به سرقت نشست های Cookie مرورگر قربانی خواهد کرد.
@Unk9vvN8 152
Mastering PE Parsing with WinDbg
Speaker: Jonathan Reiter , 13 Jan
Register :
https://www.sans.org/webcasts/mastering-pe-parsing-windbg/
8 152
Repost from /mdre/
✨ Windows Authentication - Credential Providers - Part 1.
A primer on writing a credential provider in Windows.
✨ Windows Authentication - Credential Providers - Part 2.
Sequence of calls to a credential provider in Windows.
8 152
Repost from Infosec Fortress
Happy New Year 2025! Wishing you a year filled with joy, health, and success. 🎉🎄
8 152
WTSRM - Writing Tiny Small Reliable Malware demo repository for my corresponding talk.
Unhooks all Windows Dlls with \KnownDlls\ No CRT dependencies Small size Low entropy Random string encryption key (thus no plaintext strings) API hashing Hook detection Walks around hooks for initial unhooking on ntdllhttps://github.com/rad9800/WTSRM
8 152
NanoDump: How I Reinvented SafetyKatz to Dump LSASS with NanoDump
https://xakep.ru/2024/11/13/lsass-nanodump/
8 152
Repost from Infosec Fortress
Exploit Development: No Code Execution? No Problem! Living The Age of VBS, HVCI, and Kernel CFG
🔗 Link
#binary
#exploitation
#windows
#hvci
———
🆔 @Infosec_Fortress
