#maldocs search results
Maldocs are the main vector of malware infection these days (about 70%). Understanding them are not usually difficulty (certainly, dozens times easier than any malicious binary), but it's so important to learn how to do it. #malware #maldocs #cyberthreats #cybersecurity
Three Simple Methods For Analysing Malicious Documents A quick overview of olevba, Microsoft Word, and Procmon for analysing malware documents and extracting embedded macro content. [1/10] 🧵 #malware #maldocs
Although most professionals prefer using sandboxes to analyze malicious documents, try to examine them using a static approach. It could be interesting :) #malware #maldocs #security #cyberthreat
While I'm away due to research tasks and heavily busy writing articles and a book... Remember: don't waste time with trivial maldocs... #maldocs
Being inspired by @hasherezade, @demonslay335 and @MalwareTechBlog vlogs, I decided to start my own. Today's lecture #Maldocs Analysis explains the techniques for malicious DOCX and XLSX files analysis. #malwareanalysis #nioguard #engensec #spearphihsing youtu.be/7MnHoBGeoWA
I've taught classes about reversing/malware analysis for many years, but one of them is an entry-level course named "Malicious Document Analysis". Maldocs continue being the main vector of attack against nations, companies e people. securelist.com/it-threat-evol… #maldocs #malware
Interesting #maldocs: They are hosted in DropBox and they are using template injection. Turkey.docx 55748b22a52823a3ccb5d8b106826cec https://dl.dropboxusercontent[.]com/s/psmt483ybusajvy/Turkey.docx?dl=0 "Turkey's Nuclear Dreams are a Nightmare for International Community"
🚨 I've put together my first #cheat #sheet around #maldocs, you can download a PDF version from 👇 ✅ thecyberyeti.com/quick-referenc… Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.
🚨 icymi - I've put together my first #cheat #sheet around #maldocs, you can download a PDF version from 👇 ✅ thecyberyeti.com/quick-referenc… Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.
#maldocs also perform anti-analysis, such as looking for a virtual environment. Here is an example of a #maldoc checking the manufacturer and model of the system against hard-coded list of values
Excel #maldocs weaponized with XLM macros are pushing #CobaltStrike (Targeting UA) Docs: bb4f4aac378727f78ff212b811851caa 2312634773bb6b6567964dce999fb907 97a2f4cc0c407e157556f400fb53e171 Download URL: https://datacdn[.]digital/8e83336b5d1da7ca8b576f7511440c2b/svchost.exe
Updating grammar is scary... but sometimes inevitable New technique used in #xlm #maldocs that breaks #xlmdeobfuscator: multiple macros in one cell =f1=f2=f3 #xlmdeobfuscator grammar assumes only one formula Fixed in handle_multi_statement branch, still needs more testing
These #maldocs load Shell.Application by overriding the XMLSaveThroughXSLT property. 1⃣virustotal.com/gui/file/be0e2… 2⃣virustotal.com/gui/file/51af5… They share a common malicious settings.xml.rels: 🔗virustotal.com/gui/file/d342e…
Backdooring Office Structures. Part 1: The Oldschool mgeeky.tech/backdooring-of… #Pentesting #Maldocs #Malware #CyberSecurity #Infosec
#opendir #maldocs observed #betabot #formbook #lokibot hxxp://oneprivatecloudshareandfileprotectagenci.duckdns.[org]/receipt/ formbook -> app.any.run/tasks/7ed213ef… lokibot -> app.any.run/tasks/10246573… betabot -> app.any.run/tasks/2897aa80… @James_inthe_box
These #maldocs look interesting! Was anyone able to get the remote templates?! 1ff24d73646d1958590e2bdba64f35de Nord Stream2. Two sides of the one coin.docx 216f2c0db84ab3bdabcb11b9af2cc024 Global Forum on Cyber Expertise.docx msdocumentviever[.]com
Backdooring Office Structures. Part 1: The Oldschool mgeeky.tech/backdooring-of… #Pentesting #Maldocs #Malware #CyberSecurity #Infosec
@RealAlexJones what’s the chances Trump just discovered Wrays FBI doctored content in the Epstein files to incriminate @realDonaldTrump ? Not like they haven’t tried before #SteelDossier #MALdocs #MALraid
(PT_BR) O treinamento de MALICIOUS DOCUMENT ANALYSIS está com a próxima turma CONFIRMADA para início em 04/JANEIRO/2025. Informações adicionais podem ser obtidas no website da Blackstorm Security. #maldocs
(PT_BR) O treinamento de MALICIOUS DOCUMENT ANALYSIS está CONFIRMADA para início em 22/JUNHO/2024. Informações adicionais podem ser obtidas no website da Blackstorm Security e também enviando uma mensagem para o endereço de email marcado no banner. #maldocs
5/ Obtaining Macros With Microsoft Word Microsoft word (on a safe VM) will also allow you to inspect #maldocs. You can do this by opening up a suspicious document, and browsing to View -> Macros -> View Macros -> Edit.
Three Simple Methods For Analysing Malicious Documents A quick overview of olevba, Microsoft Word, and Procmon for analysing malware documents and extracting embedded macro content. [1/10] 🧵 #malware #maldocs
Oletools – Herramientas para el análisis de Maldocs derechodelared.com/oletools-herra… #Oletools #Maldocs #VBA #macros
🚨 icymi - I've put together my first #cheat #sheet around #maldocs, you can download a PDF version from 👇 ✅ thecyberyeti.com/quick-referenc… Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.
🚨 I've put together my first #cheat #sheet around #maldocs, you can download a PDF version from 👇 ✅ thecyberyeti.com/quick-referenc… Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.
🚨Ummm... isn't this a form of bribery and/or obstruction? #MALDocs #JudgeCannon #JackSmith
Judge Cannon works for tRump and is working to earn that promised seat on the Supreme Court.
Τα κακόβουλα έγγραφα, γνωστά και ως #maldocs, αποτελούν σημαντική απειλή, εκμεταλλευόμενα τις ανθρώπινες αδυναμίες για να διεισδύσουν σε συστήματα και να κλέψουν ευαίσθητες πληροφορίες. cyberup.gr/el/protecting-…
2/2 And while #maldocs aren't as popular, these are good primers on the subject and also help to see/create an analysis workflow 👇 Getting Started w/ Malicous Office docs: youtube.com/live/tmrfZKRwN… Getting Started w/ Malicious Excel docs: youtube.com/live/WAf7Nm6bS…
youtube.com
YouTube
🎥 Getting Started Analyzing Malicious Excel Documents
So, they were trying to abbreviate on @MSNBC chyron when discussing the Mar-A-Lago classified documents case & just shortened it to “Mal Docs” - which is perfect, imho, for a hashtag for 37 of the 91 felony counts against the former guy. #MalDocs Whadya say? PS #TrumpIsGuilty
🔒Cyber Threat Advisory Alert! MalDoc in PDF Attack 📥 Download the advisory to see the technical details, indicators of compromise (IOCs) and corrective & preventive actions: sequretek.com/cyberthreatadv… #JPCERT #cyberthreat #maldocs #PDFattacks #hackers #malware #cybersecurity
Backdooring Office Structures. Part 1: The Oldschool mgeeky.tech/backdooring-of… #Pentesting #Maldocs #Malware #CyberSecurity #Infosec
Backdooring Office Structures. Part 1: The Oldschool mgeeky.tech/backdooring-of… #Pentesting #Maldocs #Malware #CyberSecurity #Infosec
FYI some of the "bloat" in the #emotet loader of 536MB is text from Moby Dick. #malware #maldocs #ThreatIntelligence #threathunting #misp
Our coverage of this #malware campaign includes a breakdown of the attack chain, IOCs, and some other curious details. People unfamiliar with OneNote as a weaponized document format should get used to this; #QakNote #maldocs are probably here to stay. 6/6 news.sophos.com/en-us/qakbot-o…
New Blog Article: Not Just #OneNote, Also Microsoft Publisher #Maldocs can Deliver #Malware | Execution flow is document[.]pub (MSPUB.EXE) -> cmd.exe -> mshta.exe ➨ bit.ly/3X3wKJc #Cybersecurity #Cyberdefense #InfoSec #OSINT
Being inspired by @hasherezade, @demonslay335 and @MalwareTechBlog vlogs, I decided to start my own. Today's lecture #Maldocs Analysis explains the techniques for malicious DOCX and XLSX files analysis. #malwareanalysis #nioguard #engensec #spearphihsing youtu.be/7MnHoBGeoWA
Three Simple Methods For Analysing Malicious Documents A quick overview of olevba, Microsoft Word, and Procmon for analysing malware documents and extracting embedded macro content. [1/10] 🧵 #malware #maldocs
Maldocs are the main vector of malware infection these days (about 70%). Understanding them are not usually difficulty (certainly, dozens times easier than any malicious binary), but it's so important to learn how to do it. #malware #maldocs #cyberthreats #cybersecurity
Although most professionals prefer using sandboxes to analyze malicious documents, try to examine them using a static approach. It could be interesting :) #malware #maldocs #security #cyberthreat
While I'm away due to research tasks and heavily busy writing articles and a book... Remember: don't waste time with trivial maldocs... #maldocs
@JohnLaTwC I've just seen your sample and stopped few minutes to solve it and offer a supplemental view of your comments to the same maldoc. #malware #maldocs
Backdooring Office Structures. Part 1: The Oldschool mgeeky.tech/backdooring-of… #Pentesting #Maldocs #Malware #CyberSecurity #Infosec
I've taught classes about reversing/malware analysis for many years, but one of them is an entry-level course named "Malicious Document Analysis". Maldocs continue being the main vector of attack against nations, companies e people. securelist.com/it-threat-evol… #maldocs #malware
#opendir #maldocs observed #betabot #formbook #lokibot hxxp://oneprivatecloudshareandfileprotectagenci.duckdns.[org]/receipt/ formbook -> app.any.run/tasks/7ed213ef… lokibot -> app.any.run/tasks/10246573… betabot -> app.any.run/tasks/2897aa80… @James_inthe_box
Updating grammar is scary... but sometimes inevitable New technique used in #xlm #maldocs that breaks #xlmdeobfuscator: multiple macros in one cell =f1=f2=f3 #xlmdeobfuscator grammar assumes only one formula Fixed in handle_multi_statement branch, still needs more testing
Interesting #maldocs: They are hosted in DropBox and they are using template injection. Turkey.docx 55748b22a52823a3ccb5d8b106826cec https://dl.dropboxusercontent[.]com/s/psmt483ybusajvy/Turkey.docx?dl=0 "Turkey's Nuclear Dreams are a Nightmare for International Community"
#maldocs also perform anti-analysis, such as looking for a virtual environment. Here is an example of a #maldoc checking the manufacturer and model of the system against hard-coded list of values
🚨 I've put together my first #cheat #sheet around #maldocs, you can download a PDF version from 👇 ✅ thecyberyeti.com/quick-referenc… Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.
🚨 icymi - I've put together my first #cheat #sheet around #maldocs, you can download a PDF version from 👇 ✅ thecyberyeti.com/quick-referenc… Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.
Hi Everyone, I would like to thank @PenTestMag for this opportunity. This paper presents a security analysis in PDF files focus on some techniques used by attacker. #malwareanalysis #maliciousPDF #maldocs #infosec
Excel #maldocs weaponized with XLM macros are pushing #CobaltStrike (Targeting UA) Docs: bb4f4aac378727f78ff212b811851caa 2312634773bb6b6567964dce999fb907 97a2f4cc0c407e157556f400fb53e171 Download URL: https://datacdn[.]digital/8e83336b5d1da7ca8b576f7511440c2b/svchost.exe
Backdooring Office Structures. Part 1: The Oldschool mgeeky.tech/backdooring-of… #Pentesting #Maldocs #Malware #CyberSecurity #Infosec
Few @anyrun_app runs of #maldocs using the same PS loader. Debating to blog or not 🧐 #AgentTesla - app.any.run/tasks/20251bc5… #pony - app.any.run/tasks/3dad0940… #QuasarRAT - app.any.run/tasks/5e6e4b6f…
Something went wrong.
Something went wrong.
United States Trends
- 1. #IDontWantToOverreactBUT N/A
- 2. $ENLV 9,911 posts
- 3. Jimmy Cliff 17.9K posts
- 4. #GEAT_NEWS N/A
- 5. Thanksgiving 137K posts
- 6. #MondayMotivation 11.7K posts
- 7. Victory Monday 3,188 posts
- 8. Good Monday 47.2K posts
- 9. TOP CALL 4,654 posts
- 10. #WooSoxWishList N/A
- 11. DOGE 218K posts
- 12. $GEAT N/A
- 13. Monad 159K posts
- 14. The Harder They Come 2,381 posts
- 15. #MondayVibes 3,145 posts
- 16. AI Alert 2,623 posts
- 17. Market Focus 3,132 posts
- 18. Shane Bowen 8,253 posts
- 19. Check Analyze N/A
- 20. Token Signal 3,137 posts