1.
ExecuteMalware
@executemalware
30 Dec 21
copy & paste +upvote -downvote A bunch of updates to REMnux today (see 🧵 for details). Run "remnux upgrade" to get them.
2.
ExecuteMalware
@executemalware
Check out my malware analysis article about the new villain #Squirrelwaffle
“A Virtual Baffle to Battle 🧇”
Exe… twitter.com/i/web/status/1…
“A Virtual Baffle to Battle 🧇”
Exe… twitter.com/i/web/status/1…
26 Sep 21
copy & paste +upvote -downvote Check out my malware analysis article about the new villain #Squirrelwaffle
“A Virtual Baffle to Battle 🐿🧇⚔️”
Exe… https://t.co/4QtWYwibbN
3.
4.
5.
6.
7.
ExecuteMalware
@executemalware
#Emotet - Reminder. Make sure you use the resources below. twitter.com/Cryptolaemus1/…
Retweet of status by @Cryptolaemus1
31 Jan 21
copy & paste +upvote -downvote #Emotet - Reminder. Make sure you use the resources below. 👇 https://t.co/b1UDnLlEGl
ExecuteMalware
@executemalware
It's nice to report that I received 0 #emotet emails today.
Here's what I saw:
Here's what I saw:
27 Jan 21
copy & paste +upvote -downvote It's nice to report that I received 0 #emotet emails today.
Here's what I saw:
😉
ExecuteMalware
@executemalware
Just wrote a new reversing tips about IDAPython! Also linked this useful cheat sheet by Pavel Rusanov.
blog:… twitter.com/i/web/status/1…
blog:… twitter.com/i/web/status/1…
08 Jan 21
copy & paste +upvote -downvote Just wrote a new reversing tips about IDAPython! Also linked this useful cheat sheet by Pavel Rusanov.👌
👉 blog:… https://t.co/8MIdBj94JY
ExecuteMalware
@executemalware
Last #Dridex #Malware has a fuckin' evil wonder!!!
it randomly chooses one of the 44 dropUrls obfuscated in its… twitter.com/i/web/status/1…
it randomly chooses one of the 44 dropUrls obfuscated in its… twitter.com/i/web/status/1…
07 Sep 20
copy & paste +upvote -downvote Last #Dridex #Malware has a fuckin' evil wonder!!!🤟
🆒it randomly chooses one of the 44 dropUrls obfuscated in its… https://t.co/wUmN1c0dQB
ExecuteMalware
@executemalware
When you want to get into an encrypted Excel (OLESS) malware sample, here are some tools:
virustotal.com/gui/file/455b5…… twitter.com/i/web/status/1…
virustotal.com/gui/file/455b5…… twitter.com/i/web/status/1…
Retweet of status by @JohnLaTwC
28 May 20
copy & paste +upvote -downvote When you want to get into an encrypted Excel (OLESS) malware sample, here are some tools:
🔗https://t.co/GxDCdQTcKS… https://t.co/5G48Szj8t9
8.
9.
10.
11.
ExecuteMalware
@executemalware
2020-05-16: #Stager Possible 'Windows Defender' Bypass Attempt
"usage: stager.exe hostname port"
Establishes a… twitter.com/i/web/status/1…
"usage: stager.exe hostname port"
Establishes a… twitter.com/i/web/status/1…
16 May 20
copy & paste +upvote -downvote 2020-05-16: 🔥🆕#Stager Possible 'Windows Defender' Bypass Attempt
"usage: stager.exe hostname port"
🔦Establishes a… https://t.co/ZgmXxKcZ7t
ExecuteMalware
@executemalware
2020-04-25: Let's Learn: #TrickBot "#BazarBackdoor" Process Hollowing Injection Primer | Reverse Engineering: Deep… twitter.com/i/web/status/1…
25 Apr 20
copy & paste +upvote -downvote 2020-04-25:📚 Let's Learn: #TrickBot "#BazarBackdoor" Process Hollowing Injection Primer | Reverse Engineering: Deep… https://t.co/2Ar9cB5YnD
ExecuteMalware
@executemalware
Binary Deobfuscation
How to Deobfuscate latest Emotet Binary.
(Volume Up) . pic.twitter.com/ripGTP7s01
How to Deobfuscate latest Emotet Binary.
(Volume Up) . pic.twitter.com/ripGTP7s01
Retweet of status by @raashidbhatt
11 Mar 20
copy & paste +upvote -downvote Binary Deobfuscation 🦠
How to Deobfuscate latest Emotet Binary.
(Volume Up) . https://t.co/ripGTP7s01
ExecuteMalware
@executemalware
21 Jan 20
copy & paste +upvote -downvote 2020-01-21:🔥👿#Emotet #Loader
💡Insight:
1⃣Wordlist Builder➡️Process Exec
2⃣Crypter Layer from #TrickBot*
"STUPID_WI… https://t.co/Y4zTowFXXL
...but wait! There's more!
1.
fakhright
@fakhright
astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat*
14 Jan 13
copy & paste +upvote -downvote astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat* 🙈🙈🙊