Ilkka · @ilkka
30 followers · 235 posts · Server mstdn.social

Microsoft AppX (UWP) concept is OK, but good grief the technical implementation is awful!

I just spent 2 hours fixing a nonsense issue, where the InstallLocation of an app was changed to NULL due to a disk volume change and of course the App failed to start or run or even uninstall. You couldn't re-install it from the store either.

Had to scrub the registry clean with SYSTEM access to get even some control over it, but now it remains to be seen if it helped or not...

#Windows #uwp #appx

Last updated 1 year ago

As promised, here are our rules for unsigned /#msix Installer packages:

Installer: yaraify.abuse.ch/yarahub/rule/
Manifest: yaraify.abuse.ch/yarahub/rule/

Also make sure to check out this thread by @nas_bench on Event Log/Sigma detections: twitter.com/nas_bench/status/1

#yara #appx

Last updated 2 years ago

Proof of Concept: Delivery via /#msix packages.
In our test case we needed administrative permissions to install the package with putty.exe as our test payload.

We did test it first with a binary, but Windows Defender caught the payload and that didn't look so nice on a screenshot 😅

Our .appx demo package is based off of a in-the-wild sample of that was signed with a stolen signature (Jan 2022). With this change in Windows 11 it is now possible to install unsigned appx packages (given required perms).
twitter.com/f0wlsec/status/148

Detection opportunities:
- Execution out of C:\Program Files\WindowsApps\
- Looking for the special OID documented by Microsoft here: learn.microsoft.com/en-us/wind

We are going to publish our rules for this tomorrow, stay tuned.

#malware #appx #wannacry #ransomware #Magniber #yara

Last updated 2 years ago

informapirata :privacypride: · @informapirata
3842 followers · 8765 posts · Server mastodon.uno

MobSF
Mobile Security Framework () è un'applicazione completa e automatizzata (/#iOS/#Windows) per svolgere attività di penetration test, analysis e valutazione di sicurezza delle mobile. Il sistema, , può eseguire analisi statiche e dinamiche e supporta i binari come (, , e ) assieme al codice sorgente e fornisce API REST per una integrazione e automatizzazione all'interno della tua pipeline CI/CD o .
redhotcyber.com/post/programmi

#MobSF #XAPK #devsecops #android #malware #app #opensource #apk #ipa #appx

Last updated 3 years ago