Andromeda/Gamarue bot loves JSON too (new versions details) | eternal-todo.com
After my last post about Andromeda different updates related to version 2.07 and 2.08 appeared. Mostly, Fortinet was talking about the version 2.7 features and the new anti-analysis tricks of version 2.08. After that, Kimberly was also mentioning version 2.09 in his blog
but I have not seen too many details about the latest versions of
Andromeda. This is a summary of the interesting details about the newer
versions.
Wednesday, May 6, 2015
Tuesday, May 5, 2015
CyberGuerrilla soApboX » #ro0ted #OpNewblood What the blackhats dont want you to know: Analyzing the ZeuS bot Part 2
CyberGuerrilla soApboX » #ro0ted #OpNewblood What the blackhats dont want you to know: Analyzing the ZeuS bot Part 2
Okay start up REMnux and sign in as root.
Okay start up REMnux and sign in as root.
We start with the command like in the previous tutorial:
type: volatility -f ‘zeus.vmem’ imageinfo
Thursday, April 30, 2015
Anti-Botnet Advisory Centre: Inform
Anti-Botnet Advisory Centre: Inform
To prevent the re-infection of your computer please note these important rules:
1Check your computer for infection. Please use our EU-Cleaner to remove all
malware.
2Install current Service Packs and Security Updates for your system. Activate automatic updates. Microsoft Instructions: Protect.
3Check your Internet browser and the
embedded plugins (e.g. Java, Flash, Shockwave, Quicktime) regularly to
make sure they are up to date. Browser- and Plugincheck
4Install a virus scanner, e.g. one that is mentioned here and update it
regularly.
5Use a firewall e.g. built-in Windows firewall or a router. More Information
about Firewalls..
hfiref0x/UACME · GitHub
hfiref0x/UACME · GitHub
UACMe
- Defeating Windows User Account Control by abusing built-in Windows AutoElevate backdoor.
- More info http://www.kernelmode.info/forum/viewtopic.php?f=11&t=3643
Wednesday, April 29, 2015
Blaze's Security Blog: Thoughts on Absolute Computrace
Blaze's Security Blog: Thoughts on Absolute Computrace: Introduction Not too long ago my friend and colleague from Sweden, Jimmy, contacted me in regards to a strange issue. In the firewall, he...
Subscribe to:
Posts (Atom)