Source Byte – Telegram
Source Byte
7.77K subscribers
847 photos
73 videos
678 files
1.68K links
هشیار کسی باید کز عشق بپرهیزد
وین طبع که من دارم با عقل نیامیزد
Saadi Shirazi 187
Download Telegram
Source:
Handle-Ripper(Handle hijacking)
Link


#malware_dev
@islemolecule_source
vmp-3.5.1.zip
20.2 MB
al-khaser is a PoC "malware" application with good intentions that aims to stress your anti-malware system.

Link


#malware_analysis #malware_dev

-----
@islemolecule_source
This is a collection of #botnet source codes, unorganized.

Link


#malware_analysis #malware_dev

------
@islemolecule_source
ghost is a light RAT ( malware source code)

Link

#malware_analysis #malware_dev


@islemolecule_source
Where to find C malware source code
Reddit
--------
#malware_analysis #malware_dev
--------
@islemolecule_source
Linux process injection: sshd injection for credential harvesting
credits : @_xpn_ , @jm33_m0

blog.xpnsec.com/linux-proces…

jm33.me/sshd-injection-and-p…


#process_injection ,
———
@islemolecule_source
VBA: having fun with macros, overwritten pointers & R/W/X memory
credit : @AdeptsOf0xCC

https://adepts.of0x.cc/vba-hijack-pointers-rwa/

#macro , #VBA , #shellcode
———
@islemolecule_source
Oh, cool! Looks like VT supports logical operators with VTGrep, so you can almost do yara searches in an indexed (read: fast) way.
e.g.

#tweet
Source Byte
Oh, cool! Looks like VT supports logical operators with VTGrep, so you can almost do yara searches in an indexed (read: fast) way. e.g. #tweet
When helping with mquery development I wrote a small converter that takes in a Yara rule and produces a simple byte-based query as output: https://github.com/CERT-Polska/mquery/blob/master/src/lib/yaraparse.py

You could probably modify it a bit to create queries compatible with VT content search
#tweet
Potential Sliver C2's (239 C2's)
credit : @embee_research

Simple query - based on "operators" and "multiplayer" certificate values related to Sliver Team Servers.

https://search.censys.io/search?

Gist - 43 IP's with 0 VT
LINK

Gist - All 239 IP's
LINK