Semper legerent "Salve Regina" ante venatione malware
837 followers 0 articles/week
MMD-067-2021 - Recent talks on Linux process injection and shellcode analysis series at R2CON-2020, ROOTCON-14 2020 from HACK.LU-2019

The background of these research and talks After HACK.LU-2019's talk in 2019 [link], I was asked a lot of questions about Linux process injection that can trigger code execution and yes, one of favorite topic is when it comes to the shellcode used as the payload on injection. As a blue-teamer, following up questions received, put me in a unique state...

Wed Mar 3, 2021 06:48
MMD-0066-2020 - Linux/Mirai-Fbot - A re-emerged IoT threat

Prologue A month ago I wrote about IoT malware for Linux operating system, a Mirai botnet's client variant dubbed as FBOT. The writing [link] was about reverse engineering Linux ELF ARM 32bit to dissect the new encryption that has been used by their January's bot binaries, The threat had been on vacuum state for almost one month after my post,...

Sun Feb 23, 2020 22:41
MMD-0065-2020 - Linux/Mirai-Fbot

Prologue I setup a local brand new ARM base router I bought online around this new year 2020 to replace my old pots, and yesterday, it was soon pwned by malware and I had to reset it to the factory mode to make it work again (never happened before). When the "incident" occurred, the affected router wasn't dead but it was close to a freeze state,...

Wed Jan 15, 2020 14:48
More About My 2019.HACK.LU Keynote Talk

As promised, this is my additional notes and review about my Keynote talk in 2019.HACK.LU (link) About 2019.HACK.LU HACK.LU is a great conference, thank you for having me this year, I could interact with a lot of infosec community who I already know but haven't met them until now, and I could also get along with old friends in the community...

Mon Oct 28, 2019 16:02
MMD-0064-2019 - Linux/AirDropBot

Prologue There are a lot of botnet aiming multiple architecture of Linux basis internet of thing, and this story is just one of them, but I haven't seen the one coded like this before. Like the most of other posts on our analysis reports in MalwareMustDie blog, this post was started from a request from a friend to take a look at a certain binary that...

Sat Sep 28, 2019 05:00
MMD-0063-2019 - Summarize report of three years MalwareMustDie research (Sept 2016-Sept 2019)

Hello, it's unixfreaxjp here. It has been a while since I wrote our own blog, and it is good to be back. Thank you for your patience for all of this time. The background It was after September 2016 when we decided to move our blog and since then I had a lot of fun in learning and experimenting much with "Jekyll" (based on "Poole") and "BlackDoc",...

Sat Sep 21, 2019 15:53

Build your own newsfeed

Ready to give it a go?
Start a 14-day trial, no credit card required.

Create account