seanpm2001 🇺🇦️ · @seanpm2001
5 followers · 91 posts · Server techhub.social

Project of the day (day 19) 2023, Sunday, September 10th

: github.com/seanpm2001/Linux_De

is an anti-virus for Linux, with a like (which can be turned off when needed) it clears most common Linux desktop malware, but extends to also include and, depending on how strict you set it to be, it can block the installation of programs like Google Chrome, and other tracking software pieces (they are spyware) along with any software.

It is written mostly in with rule sets additionally being written in it is aimed at being ported to as many Linux distributions as possible. It is early in development, and is not functional yet.

#linuxdefender #linux #defender #windowsdefender #interface #spyware #proprietary #python #yara

Last updated 1 year ago

ARoivainen · @ARoivainen
198 followers · 198 posts · Server mastodontti.fi

Suomessa ei haluta laatia uutisia, matkailujuttuja, luontojuttuja kontekstiin. Tässäkin hehkutetaan Savon/ Siilinjärven mahtavaa luontoa. Samaan aikaan Timosen ja kaikkien muidenkin Laukansalossa olevien välittömään naapuriin laajenee apatiittikaivos. Merkitty punaisella. Mökit piku pisteitä rannassa. Siitä luonnosta ei jää yhtään mitään jäljelle, kun avolouhos jätekivineen alueen valtaa.

#siilinjarvi #yara

Last updated 1 year ago

vPierre · @vPierre
25 followers · 844 posts · Server mas.to

@nboynorge search for and you will find thousands of rules from us

#yararules #yara #ndaal

Last updated 1 year ago

Simon Descarpentries · @Siltaer
1032 followers · 10729 posts · Server mamot.fr

. Amende record pour le fabricant d’engrais France, près de Saint-Nazaire
ouest-france.fr/environnement/

L’usine d’engrais de Montoir-de-Bretagne, faute de s’être mise aux normes, doit cette fois payer l’astreinte de 519 000 €. Un record.

#pollution #yara

Last updated 1 year ago

Geekmaster 👽:system76: · @Geekmaster
166 followers · 1262 posts · Server ioc.exchange
Forbes Brasil · @ForbesBR
17 followers · 1499 posts · Server mastodon.world
Forbes Brasil · @ForbesBR
5 followers · 782 posts · Server mastodon.world
esoriano · @esoriano
126 followers · 288 posts · Server social.linux.pizza

Hoy toca ver y, por supuesto, expresiones regulares!

Puedes ver las transpas (creative commons) en:
gitlab.etsit.urjc.es/esoriano/

#yara

Last updated 2 years ago

📧🙄 News: Another one of our predictions for the ongoing campaign turns out to be correct: E4 and E5 are now spamming lures. We published a rule on @abuse_ch to detect the .one -> .wsf delivery method.
Yarahub: yaraify.abuse.ch/yarahub/rule/

#emotet #onenote #yara #yarahub #cybersecurity #infosec #blueteam

Last updated 2 years ago

lazarusholic · @lazarusholic
2 followers · 29 posts · Server infosec.exchange

"Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW" published by Mandiant. , , , , , , , mandiant.com/resources/blog/li

#unc2970 #lightshift #lightshow #byovd #yara #cti #osint #lazarus

Last updated 2 years ago

lazarusholic · @lazarusholic
2 followers · 28 posts · Server infosec.exchange

"Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970" published by Mandiant. , , , , , , mandiant.com/resources/blog/li

#unc2970 #lightshow #byovd #yara #cti #osint #lazarus

Last updated 2 years ago

🚨 -2023-21716 is a new criticial in Microsoft Word exploited through RTF documents. Similar, older exploits are still very popular with threat actors.
We tested the PoC created by @jduck and created a first prototype hunting rule 🔍

Github: github.com/SIFalcon/Detection/

Please keep in mind that this is meant as a hunting rule only and there is certainly potential for tuning.

More on CVE-2023-21716 as reported by @BleepinComputer: bleepingcomputer.com/news/secu

NVD: nvd.nist.gov/vuln/detail/CVE-2

PoC: twitter.com/jduck/status/16324

Happy hunting! 🕵️

#cve #rce #yara

Last updated 2 years ago

Josh Lemon · @joshlemon
133 followers · 38 posts · Server infosec.exchange

Didier Stevens also wrote up a signature to detect suspicious OneNote files with embedded objects.

isc.sans.edu/diary/rss/29598

#yara

Last updated 2 years ago

Greg Lesnewich · @glesnewich
128 followers · 214 posts · Server infosec.exchange

Anyone in the space familiar with methods for finding similarity across 🍎 Macho 🍏malware samples?

We hash things like the (ordered) import table, and the decoded rich header, and look for distinctive toolmarks in the DLL name, and PDB path in Portable Executables. I’m wondering if there are similar avenues already explored by anyone else?

I’m familiar with SymHash from Anomali, but haven’t heard of much other focus on clustering in those manners. Most reporting about Macho malware is focused on analysis of functionality

#malwareanalysis #reverseengineering #malware #yara

Last updated 2 years ago

leakix · @leakix
180 followers · 38 posts · Server mastodon.social

Finally releasing our new file indexing and search project.

We integrated and scanning and are archiving suspicious files we come across.

We also look into compressed files.

files.leakix.net/?q=infected%3

#clamav #yara

Last updated 2 years ago

leakix · @leakix
180 followers · 38 posts · Server mastodon.social

Finally releasing our new file indexing and search project.

We integrated and scanning and are archiving suspicious files we come across.

We also look into compressed files.

files.leakix.net/?q=infected%3

#clamav #yara

Last updated 2 years ago

williballenthin · @williballenthin
732 followers · 142 posts · Server mastodon.social

here’s an exploration on the prevalence of shellcode hashes via : williballenthin.com/post/shell

#yara #100DaysofYARA

Last updated 2 years ago

FeministFatale · @FeministFatale
0 followers · 60 posts · Server mastodon.scot

What a beautiful place for a revolution.

#gaming #yara #FarCry6

Last updated 2 years ago

Ransomware Targets with Command-Line Options and Optimized Encryption Routines blogs.blackberry.com/en/2023/0

#darkbit #israel #ioc #yara #geopolitics

Last updated 2 years ago

Eric Capuano · @eric_capuano
2442 followers · 668 posts · Server infosec.exchange

Rarely do I stumble on a truly impressive rule, but the weighted value nature of this one is impressive.

It assigns a "weight" to various strings in PowerShell commands to determine the likelihood of maliciousness in context when the string itself is highly prone to false positives.

#yara #detection

Last updated 2 years ago