@tildedennis Profile picture

tildedennis

@tildedennis

average malware reverse engineer https://t.co/YjfQWBzZd9 https://t.co/67tyxbpmw1

Joined August 2016
Similar User
sysopfb photo

@sysopfb

Tom Hegel photo

@TomHegel

Joe Roosen photo

@JRoosen

CAPE Sandbox photo

@CapeSandbox

Matthew Mesa photo

@mesa_matt

sean photo

@seanmw

Antelox photo

@Antelox

Daniel Plohmann photo

@push_pnx

Rony photo

@r0ny_123

Racco42 photo

@Racco42

JaromirHorejsi photo

@JaromirHorejsi

Kirk Sayre photo

@bigmacjpg

Alexis Dorais-Joncas (@adorais@infosec.exchange) photo

@adorais

Digital_Monet photo

@aRtAGGI

Artsiom Holub photo

@Mesiagh

tildedennis Reposted

With everything going on right now preserving, contextualizing and promoting history and digital archives is more important than ever. You have to know the past to understand the present.


tildedennis Reposted

In a couple of days, we'll be releasing IDA 9.0! We're excited to introduce our supercharged FLIRT Manager plus thousands of new signatures, available as separate downloads 🤩 Learn more 🌐 eu1.hubs.ly/H0cBQx80 #idapro

Tweet Image 1

tildedennis Reposted

Have you seen the 'sp-analysis failed' error and wondered why it appears and how to fix it? In this video, we explain the stack pointer tracing/analysis feature of IDA/its processor modules and how to fix stack pointer tracing errors. youtu.be/Cd6Q-_1dxNU Some of the topics…


tildedennis Reposted

Too excited it's back in email not to share: incoming: doc_inv_09-12\#[0-9]{1,4}\.pdf CampaignID: "Alpha" hxxps://isomicrotich.com/test/ hxxps://rilomenifis.com/test/ tldr high level: Email > PDF > URL > JS > MSI > #Latrodectus Samples in comments, IOCs on bazaar


tildedennis Reposted

"Comunicazione Importante dall'Agenzia delle Entrate" spam email spread #DanaBot Urls redirect > content.servepics.[com/login.php portfolio.serveirc.[com/login.php >JS > dll http://soundata.]top/resources.dll Samples bazaar.abuse.ch/browse/tag/age… AnyRun app.any.run/tasks/a059217b…

Tweet Image 1
Tweet Image 2
Tweet Image 3
Tweet Image 4

tildedennis Reposted

🛠️ We added a basic WebUI to our malware strings lookup service. Give it a try at strings.malpedia.io

Tweet Image 1

📣We updated "Malpedia FLOSSed". TL;DR: More data, cleaner Rust/Go/Dotnet strings, various tags! We also created a public web service to make this data more accessible: strings.malpedia.io, as well as an IDA plugin as a demo use case. Read more -> github.com/malpedia/malpe…

Tweet Image 1
Tweet Image 2
Tweet Image 3


tildedennis Reposted

#Zloader aka #SilentNight is back! Check out our technical analysis of Zloader version 2.1.7.0, where we uncover the new obfuscation techniques, updates to the DGA, and the addition of RSA to network encryption. Blog link: zscaler.com/blogs/security…

Tweet Image 1

tildedennis Reposted

One of the biggest hurdles in public malware research is the lack of *labeled* samples for study. A richly labeled and organized sample corpus enables bulk research into TTPs and tradecraft for detection and intel analysis. Thank you VXUG for democratizing access. [1/2]

You can now download APTs in bulk vx-underground.org/APTs/Yearly%20…



tildedennis Reposted

If you’re into more historical stuff check out Zeus museum by @tildedennis zeusmuseum.com


tildedennis Reposted

A threat actor spreads #DanaBot using Google #malvertising via websites impersonating the Advanced IP scanner download page. It has probably been targeting IT admins (valuable hosts) for several months. Distribution infra of 40+ domain names: advancd-ip-scanner.]com ⬇️

Tweet Image 1

tildedennis Reposted

Microsoft has identified new Qakbot phishing campaigns following the August 2023 law enforcement disruption operation. The campaign began on December 11, was low in volume, and targeted the hospitality industry. Targets received a PDF from a user masquerading as an IRS employee.

Tweet Image 1

TIL CryptDeriveKey using sha256 is just sha256... thanks @kausrini !


tildedennis Reposted

Tips For Reverse Engineering Delphi (Danabot) A few tips from our recent stream, link to full VOD on Patreon follows...


tildedennis Reposted

After exploiting the vulnerability, Lace Tempest issued commands via the SysAid software to deliver a malware loader for the Gracewire malware. This is typically followed by human-operated activity, including lateral movement, data theft, and ransomware deployment.


tildedennis Reposted

Thank you again to people who listened to my presentation and talked with me at #vb2023 and #TheSAS2023 and organizers who provided me an opportunity. I released IDA FLIRT signature for fcClientDll (FlowCloud) and IOC I mentioned in the presentation. github.com/0xebfehat/2023…


tildedennis Reposted

Distracted by all those casts, and you don’t really need to see them? You can hide them, but beware of wrong results 🌐 hex-rays.com/blog/igors-tip… #IgorsTipOfTheWeek #IDAtips #IDAPro #decompiler

Tweet Image 1

tildedennis Reposted

When you are doing reverse engineering what libraries, runtimes, toolkits, etc... have you seen used in your targets? The idea is to build a large library of (compressed) #Diaphora export databases for common libraries, runtimes, toolkits, etc... 1/2 mastodon.social/@joxean/111159…


tildedennis Reposted

2023-08-03 (Thursday): Malicious Google ad led to a fake TurboTax page pushing an installer package that led to #DanaBot. List of indicators available at bit.ly/3qfbEgL

Tweet Image 1
Tweet Image 2
Tweet Image 3
Tweet Image 4

tildedennis Reposted

For those of you who prefer the comfort of YouTube… youtu.be/8jckguVRHyI

Tweet Image 1

Loading...

Something went wrong.


Something went wrong.