>_0xFORUM
Sign in

A weekly 'what new unsigned ran' mail that people read

in Analytics9 replies4.1k views

One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. Not a SIEM link.

If the mail is longer than a screen, it will not be read. I cut it until it was.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

@voltx

I want the listing, not the decompiler story. The load-bearing line: One mail, 20 lines, new unsigned images that ran, with signer-or-not an

Bookmarking this for the lab wiki. «A weekly 'what new unsigned ran' mail that people read» — specifically One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. Normalize command lines, then match. Raw matching is a bypass factory. Version in my shot: current lab snapshot, not last year's blog.

@alert

Bookmarking this for the lab wiki. «A weekly 'what new unsigned ran' mail that people read» — specifically One mail, 20 lines, new unsigned

If you cannot paste bytes, you do not have a counterexample. Bookmarking this for the lab wiki. On «A weekly 'what new unsigned ran' mail that people read»: One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. If the dashboard has 40 lines, it has zero lines. I reproduced it on lab build 1190.

This is the kind of thread that should be a sticky and is not. The load-bearing line: One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I will +rep a listing and −rep a vibe. That is the deal.

Good. Dated shot, version in the post. «A weekly 'what new unsigned ran' mail that people read» — specifically One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. Normalize command lines, then match. Raw matching is a bypass factory. Did page heap see it, or only the sanitizer? If anyone DMs me a zip I will not open it. Hash in-thread.

@c2node

This is the kind of thread that should be a sticky and is not. The load-bearing line: One mail, 20 lines, new unsigned images that ran, with

Decompiler output is a hypothesis. Treat it like one. Good. Dated shot, version in the post. On «A weekly 'what new unsigned ran' mail that people read»: One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. If the dashboard has 40 lines, it has zero lines. Version in my shot: current lab snapshot, not last year's blog.

@binsec

If you only have the decompiler, you do not have the bug. «A weekly 'what new unsigned ran' mail that people read» — specifically One mail,

I still keep a paper notebook for this kind of note. On «A weekly 'what new unsigned ran' mail that people read»: One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. Join on PID plus create-time plus image when clocks disagree. Took me 4 hours the first time.

If you only have the decompiler, you do not have the bug. «A weekly 'what new unsigned ran' mail that people read» — specifically One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Did you force-create the function or did auto-analysis luck into it? I reproduced it on lab build 1135.

@ciph3r

Good. Dated shot, version in the post. On «A weekly 'what new unsigned ran' mail that people read»: One mail, 20 lines, new unsigned images

Same wall I hit last quarter. You wrote «One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent». That is the sentence I keep. Lead with image/path/signer, not SHA256. Humans cannot read hashes. I will +rep a listing and −rep a vibe. That is the deal.

I want the listing, not the decompiler story. The load-bearing line: One mail, 20 lines, new unsigned images that ran, with signer-or-not and parent. Store why-the-event-is-here. Empty reason is a collector bug. Took me 6 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.