0xdf · @0xdf
448 followers · 19 posts · Server infosec.exchange

A lnk file that downloads JavaScript from . This one uses lolbins like certutil for base64 decode, bitsadmin for download, and colorcpl for file copy. Also lots of JavaScript charcode obfuscation.

youtube.com/watch?v=i-jeW6Ah8q

#malwarebazaar

Last updated 2 years ago

abuse.ch · @abuse_ch
324 followers · 11 posts · Server ioc.exchange

We have just published our report for December 2022, providing you some insights into malware trends across our platforms, including and 🪲🔎👀

👉 hubs.ly/Q01x40Ct0

#URLhaus #malwarebazaar

Last updated 3 years ago

Nils Kuhnert · @0x3c7
89 followers · 4 posts · Server infosec.exchange

Just pushed an update for malwarebazaar, my little Python/CLI API client for @abuse_ch . Originally just used for querying bazaar itself, now it's possible to query , too. Additionally the CLI was updated to provide a richer (haha - rich.readthedocs.io/) output. You can find the new version on Github (github.com/3c7/bazaar/releases) and on PyPI via `malwarebazaar`.

#malwarebazaar #yaraify #threatintel #malware

Last updated 3 years ago

avallach · @xorhex
118 followers · 62 posts · Server infosec.exchange

Some additions, improvements, and fixes coming to soon.

github.com/xorhex/mlget

Mlget is a downloader, allowing you to download from the following services:







/ @malshare






<-- NEW ADDITION COMING
/#virustotal
/ @VXShare

It can also download and automatically upload to an MWDB instance of your choice.

#mlget #malware #capesandbox #filescanio #HybridAnalysis #Inquests #joesandbox #malpedia #malshare #malwarebazaar #mwdb #objectivesee #polyswarm #triage #unpacme #urlscanio #vt #vxshare

Last updated 3 years ago

avallach · @xorhex
160 followers · 162 posts · Server infosec.exchange

Some additions, improvements, and fixes coming to soon.

github.com/xorhex/mlget

Mlget is a downloader, allowing you to download from the following services:







/ @malshare






<-- NEW ADDITION COMING
/#virustotal
/ @VXShare

It can also download and automatically upload to an MWDB instance of your choice.

#mlget #malware #capesandbox #filescanio #HybridAnalysis #Inquests #joesandbox #malpedia #malshare #malwarebazaar #mwdb #objectivesee #polyswarm #triage #unpacme #urlscanio #vt #vxshare

Last updated 3 years ago

Frehi · @frehi
66 followers · 534 posts · Server fosstodon.org

Hm, @abuse_ch requires a Twitter account to log in to . I don't have that any more.

#malwarebazaar

Last updated 3 years ago