eng_awm's profile picture.

Abdulwahab Almidani

@eng_awm

Earthquake disaster in Syria: Give what you can to help the White Helmets save lives whitehelmets.org/en/


Abdulwahab Almidani reposted

Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049) breakdev.org/zip-motw-bug-a…


Abdulwahab Almidani reposted

Nice EDR bypass using file names.. may or may not be more like this if you look hard.

Bypassing AV & EDR detection by playing with file names. The security tools think the files MUST end in .exe or .dll, but they don't. Currently, it's bypass Defender AV & EDR, Crowdstrike, and Palo. Thanks for @mrd0x for this info!

ellishlomo's tweet image. Bypassing AV & EDR detection by playing with file names. The security tools think the files MUST end in .exe or .dll, but they don't.

Currently, it's bypass Defender AV & EDR, Crowdstrike, and Palo. 

Thanks for @mrd0x for this info!


Abdulwahab Almidani reposted

RE tip of the day: Apart from CreateProcess, ShellExecute and WinExec WinAPIs, attackers can use CoCreateInstance API with F935DC21-1CF0-11d0-ADB9-00C04FD58A0B IID (Wscript.Shell COM object) to create new processes #infosec #cybersecurity #malware #reverseengineering

re_and_more's tweet image. RE tip of the day: Apart from CreateProcess, ShellExecute and WinExec WinAPIs, attackers can use CoCreateInstance API with F935DC21-1CF0-11d0-ADB9-00C04FD58A0B IID (Wscript.Shell COM object) to create new processes

#infosec #cybersecurity #malware #reverseengineering

Abdulwahab Almidani reposted

This looks like an #APT attack targeting travelers that are planing to enter to UK.. It might be related to #CloudAtlas. 1ca8b287ea91be2f3d9bb5ad6f27cf34 "FORM-0-COVID-19.doc" 139.60.161[.]74 217.182.9[.]185

h2jazi's tweet image. This looks like an #APT attack targeting travelers that are planing to enter to UK.. It might be related to #CloudAtlas. 

1ca8b287ea91be2f3d9bb5ad6f27cf34
"FORM-0-COVID-19.doc"
139.60.161[.]74
217.182.9[.]185
h2jazi's tweet image. This looks like an #APT attack targeting travelers that are planing to enter to UK.. It might be related to #CloudAtlas. 

1ca8b287ea91be2f3d9bb5ad6f27cf34
"FORM-0-COVID-19.doc"
139.60.161[.]74
217.182.9[.]185
h2jazi's tweet image. This looks like an #APT attack targeting travelers that are planing to enter to UK.. It might be related to #CloudAtlas. 

1ca8b287ea91be2f3d9bb5ad6f27cf34
"FORM-0-COVID-19.doc"
139.60.161[.]74
217.182.9[.]185

cisco.com/c/en_uk/produc…{keyword}&KWID=&dtid=psotwt000174&ecid=&oid=vidsc003147&PLACEMENT=2ndParty&gclid=&ad_id=&dclid=CMeTiIuFg9gCFYqD7Qod65YFOQ


Caleb Barlow: Where is cybercrime really coming from? go.ted.com/Cydh


United States Trends

Loading...

Something went wrong.


Something went wrong.