Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Malware AV/VM evasion - part 14: encrypt/decrypt payload via A5/1. Bypass Kaspersky AV. Simple C++ example.

This post is the result of research on try to evasion AV engines via encrypting payload with another function: GSM A5/1 algorithm:

https://cocomelonc.github.io/malware/2023/03/24/malware-av-evasion-14.html
usenix2023-wifi.pdf
190.2 KB
Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
teamcity_whitepaper_cloud_cost.pdf
468.4 KB
15 Ways to Optimize Your Cloud CI/CD Costs
Malwoverview

… threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, InQuest:

https://github.com/alexandreborges/malwoverview
PoC CVE-2023-27532 (Veeam Backup & Replication)

Proof of Concept code to exploit CVE-2023-27532 and either leak plaintext credentials or perform remote command execution:

https://github.com/sfewer-r7/CVE-2023-27532