RSSAmplifier

Blog

Megabeets

Recent content on Megabeets

megabeets.netRSS feed ↗86 posts

Latest posts

LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices

When Avatars Come Alive: Understanding Hybrid Threat Actors

AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks

Modern Approach to Attributing Hacktivist Groups

Virus Bulletin 2024 Conference Paper

About

‹ › $ WHOAMI Hey there!👋 I’m Itay Cohen. I’ve been fascinated by computers for as long as I can remember. Over time, I developed a fascination with cybersecurity and started teaching myself about hacking, reverse engineering and malware analysis. Most of my free time is dedicated for political and social activism and in general pursuing of what I see as just. I am an…

Darkbit Decoded: Analysis of an Iranian-Sponsored Attack

Virus Bulletin 2023 Conference Paper

The Dragon Who Sold His Camaro: Analyzing Custom Router Implant

Twisted Panda: Chinese APT espionage operation against Russian state-owned defense institutes

EvilPlayout: Attack Against Iran’s State Broadcaster

Indra — Hackers Behind Recent Attacks on Iran

IndigoZebra APT continues to attack Central Asia with evolving tools

The Story of Jian - How APT31 Stole and Used an Unknown Equation Group 0-Day

SUNBURST, TEARDROP and the NetSec New Normal

Bandook: Signed & Delivered

Pay2Key Ransomware Alert

Exploit Developer Spotlight: The Story of PlayBit

Part of multi-publication entry

Graphology of an Exploit - Hunting for exploits by looking for the author's fingerprints

Virus Bulletin 2020 Conference Paper

Mapping the connections inside Russia’s APT Ecosystem

If the names Turla, Sofacy, and APT29 strike fear into your heart, you are not alone. These are known to be some of the most advanced, sophisticated and notorious APT groups out there – and not in vain. These Russian-attributed actors are part of a bigger picture in which Russia is one of the strongest powers in the cyber warfare today. Their advanced tools, unique approaches, and solid…

Deobfuscating APT32 Flow Graphs with Cutter and Radare2

The Ocean Lotus group, also known as APT32, is a threat actor which has been known to target East Asian countries such as Vietnam, Laos and the Philippines. The group strongly focuses on Vietnam, especially private sector companies that are investing in a wide variety of industrial sectors in the country. While private sector companies are the group’s main targets, APT32 has also been known to…

The Evolution of BackSwap

The BackSwap banker has been in the spotlight recently due to its unique and innovative techniques to steal money from victims while staying under the radar and remaining undetected. This malware was previously spotted targeting banks in Poland but has since moved entirely to focus on banks in Spain. The techniques used by it were thoroughly described by our fellow researchers at the Polish CERT…

Nazar: Spirits of the Past

CONFidence Teaser CTF – Hidden Flag

During CONFidence Teaser CTF, one specific task caught my interest. Not because it was hard or complicated – it wasn’t, but because the concept behind it was interesting and relevant to my day-to-day work as a malware researcher. In this short article, I will show a highly esoteric , not to say trivial , concept in which you can leak the content of “sensitive” files on systems where scanning the…

Vicious Panda: The COVID Campaign

5 Ways to patch binaries with Cutter

I recently watched a video by LiveOverflow in which he showed how different tools are used to patch binaries. By demonstrating some of the features that Radare2, Ghidra, and Binary Ninja offer for the task, the viewer can get some sense of the things they can get from using these tools. While all these tools are great, and although Radare2 was showed there (and oh boy, things went wrong), there…

Mapping the connections inside Russia's APT Ecosystem

Cutter: The radare2 GUI

Deobfuscating APT32 Flow Graphs with Cutter and Radare2

The Evolution of BackSwap

A Targeted Campaign Break-Down - Ryuk Ransomware

Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 2

Prologue Previously, in the first part of this article, we used Cutter, a GUI for radare2, to statically analyze APT33’s Dropshot malware. We also used radare2’s Python scripting capabilities in order to decrypt encrypted strings in Dropshot. If you didn’t read the first part yet, I suggest you do it now . Today’s article will be shorter, now that we are familiar with cutter and r2pipe, we can…

‘Decrypting APT33’s Dropshot Malware with Radare2 and Cutter – Part 1’

Prologue As a reverse engineer and malware researcher, the tools I use are super important for me. I have invested hours and hours in creating the best malware analysis environment for myself and chose the best tools for me and my needs. For the last two years, radare2 is my go-to tool for a lot of reverse-engineering tasks such as automating RE related work, scripting, CTFing, exploitation and…

Solving PwCTF Prequel

Epilogue PwCTF is an on-site CTF event in Israel. It will take part on January 29-31 in Cybertech Tel-Aviv 2018. Honestly I’ve never heard of it before but I thought I’ll give it a try and ended up to be the first to finish the prequels . In the following writeup I’ll go step by step on how I solved each challenge. Here we go. The first challenge It was a morning time, I was eating my breakfast…

Reversing a Self-Modifying Binary with radare2

Prologue It took me three months to finish writing this article. I had so many tasks on my to-do list that sadly this one was pushed down to the bottom of the list. Last weekend I made a promise to myself that until Sunday I’m going to finish writing it, I successfully kept my word and here it is, another radare2 tutorial. Today we’ll solve a very nice challenge, “packedup”, written by ad3l for…

Reverse engineering a Gameboy ROM with radare2

Prologue A month ago in Barcelona I was attending to r2con for the first time. This is the official congress of the radare2 community where everyone can learn more about radare2 framework and dive deep into different aspects of reverse engineering, malware analysis, fuzzing, exploiting and more. It also the place where all of us, the contributors and developers of radare2, can meet, discuss and…

A journey into Radare 2 – Part 2: Exploitation

Prologue helllo asf world fas Welcome back to the second part of our journey into the guts of radare2! In this part we’ll cover more of the features of radare2, this time with the focus on binary exploitation. A lot of you waited for the second part, so here it is! Hope to publish the next part faster, much faster. If you didn’t read the first part of the series I highly recommend you to do so. It…

A journey into Radare 2 – Part 1: Simple crackme

Update (2020): Since writing this article, it has become, in a way, the go-to tutorial for learning radare2. Your feedback was amazing and I am very happy for the opportunity to teach new people about radare2. A lot has changed since I wrote this tutorial, both with radare2 and with me. I am now, for several years, a core member in the radare2 team and a maintainer of <a…

[Pragyan CTF] New Avenger

Description: New Avenger | Stego 300 pts The Avengers are scouting for a new member. They have travelled all around the world, looking for suitable candidates for the new position. Finally, they have found the perfect candidate. But, they are in a bad situation. They do not know who the guy is behind the mask. Can you help the Avengers to uncover the identity of the person behind the mask ?…

[Pragyan CTF] Roller Coaster Ride

Description: Bobby has been into Reverse Engineering and Binary Exploitation lately. One day, he went to an amusement park in his city. It was very famouse for its Roller Coaster Rides. But, Bobby, being 12 years old, was not allowed on those rides, as it was open for people who were 14 years or older. This made Bobby very angry. On reaching home, he hacked into the servers of the amusement park,…

[Pragyan CTF] Lost Friends

Description: Lost Friends **| **Stego 300 Moana and her friends were out on a sea voyage, spending their summer joyously. Unfortnately, they came across Charybdis, the sea monster. Charybdis, furious over having unknown visitors, wreaked havoc on their ship. The ship was lost. Luckily, Moana survived, and she was swept to a nearby island. But, since then, she has not seen her friends. Moana has…

[Pragyan CTF] The Vault

Description: [!@# a-z $%^ A-Z &* 0-9] [1,3] file All we got is a file and regular expression. Lets run file command on the file to determine its type: ```diff $ file ./file.kdb file: Keepass password database 1.x KDB, 3 groups, 4 entries, 50000 key transformation rounds ``` The file is KDB file which is Keepass password database. Keepass is a famous opensource password manager. I tried open it…

[Pragyan CTF] The Karaboudjan

Description **The Karaboudjan | **Forensics 150 pts Captain Haddock is on one of his ship sailing journeys when he gets stranded off the coast of North Korea. He finds shelter off a used nuke and decides to use the seashells to engrave a message on a piece of paper. Decrypt the message and save Captain Haddock. ->-.>-.—.–>-.>.>+.–>–..++++. .+++.…

[Pragyan CTF] Evil Corp

Description: fsociety has launched another attack at Evil Corp. However, Evil Corp has decided to encrypt the .dat file with a CBC cipher. Reports reveal that it is not AES and the key is relatively simple, but the IV might be long. And remember, fsociety and evilcorp are closely linked. Hint! Snakes serve the fsociety. Hmmm. Hint! fsociety and evilcorp are too close, even 16 characters long…

[Pragyan CTF] Supreme Leader

Description: North Korea reportedly has a bioweapon in the making. Hack into their database and steal it. Link : http://139.59.62.216/supreme_leader For the second web challenge we’re given with a URL, lets open it. Cute Kim 🙂 Now let’d dump the headers of the response using curl : Megabeets$ curl -D - http://139.59.62.216/supreme_leader/ HTTP/1.1 200 OK Date: Sun, 05 Mar 2017 08:47:14 GMT…

[Pragyan CTF] Answer To Everything

Description: Shal has got a binary. It contains the name of a wise man and his flag. He is unable to solve it. Submit the flag to unlock the secrets of the universe. main.exe In this challenge we have a binary, I ran file command on it: Megabeets$ file ./main.exe main.exe: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32,…

[Pragyan CTF] Interstellar

Description: Forensics 150 pts Dr. Cooper, on another one of his endless journeys encounter a mysterious planet . However when he tried to land on it, the ship gave way and he was left stranded on the planet . Desperate for help, he relays a message to the mothership containing the details of the people with him . Their HyperPhotonic transmission is 10 times the speed of light, so there is no…

[Pragyan CTF] Game of Fame

Description: p xasc. a zdmik qtng. yiy uist. easc os iye iq trmkbumk. gwv wolnrg kaqcs vi rlr. Hint! Robert Sedgewick To be honest, this challenge was pretty simple. I decrypted the text using online Vigenere cipher decrypter, which is the first cipher I try in suchcases, just after Caesar cipher. The key was “pragyan” and the result was: “a game. a movie star. his wife. name of the cs textbook .…

[33C3 CTF] pay2win Writeup

Description: pay2win – Web Do you have enough money to buy the flag ? This challenge was pretty tricky to understand at the beginning. I solved it with a quick and simple workaround that allowed me to solve the challenge without fully understand it. Once I got the flag I understood the whole story. So as with all the stories, we need to begin from the start. We’re given with a website in where we…

[33C3 CTF] The 0x90s called Writeup

Description: The 0x90s called – PWN The 0x90s called, they want their vulns back! Pwn this and get the flag. Who would’ve thought? If you want to try it locally first, check this out . This challenge was pretty simple and obvious. We are given with a website that is requesting a ‘proof of work’ from us to reduce the load on their infrastructure. We need to press start and then we get a port to…

Fantastic Malware and Where to Find Them

We, as malware analysts, are always in need of new samples to analyze in order to learn, train or develop new techniques and defenses. One of the most common questions I get is “Where to find malware to analyze?” so I’m sharing here my private collection of repositories, databases and lists which I use on a daily basis. Some of them are updated frequently and some of them are not. The short…

[H4CK1T 2016] Crypt00perator – Ethiopia Writeup

Description: Long time ago one security module has been written. But for now its sources have been missed somehow. We have forgotten th3 access k3y, which, as we remember, has been hardcoded inside the module. Help us to recollect th3 k3y!11 crypt0_0perator_56e0a9f07f54b3634ab5cc2b30e5b29e.exe h4ck1t{…} This is a pretty basic reverse challenge. We can solve it in many different ways but I will…