12

Linux Memory Diff Analysis using Volatility

This blog post contains details of Linux Mem Diff Tool, this tool uses Volatility advanced memory forensics framework to run various plugins against the clean and infected Linux memory image and reports the changes. Similar tool to perform diff analysis on the Windows memory images can be found here Why this tool? Many times while […]

14

Hunting and Decrypting Communications of Gh0st RAT in Memory

This blog post contains the details of detecting the encrypted Gh0st RAT communication, decrypting it and finding malicious Gh0st Rat artifacts (like process, network connections and DLL) in memory. I also present a Volatility (Advanced Memory Forensics Framework) plugin (ghostrat) which detects the encrypted Gh0st RAT communication, decrypts it and also automatically identifies the malicious […]

12

Hunting APT RAT 9002 In Memory Using Volatility Plugin

On Nov 10, 2013 FireEye published a blog about how the latest IE zero day exploit was used in the wild by the APT actors to serve 9002 RAT (aka Hydraq/McRat/Mdmbot). The FireEye blog also mentioned that the threat actors directly injected the payload of 9002 RAT into memory without writing to disk. This technique […]

2

Cysinfo Cyber Security Meetup – 28th May 2016, Bangalore

This is an announcement for the upcoming Cysinfo cyber security community meetup on 28th May 2016 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST. Here is Schedule of Security Talks: 09:30 – 10:10 Understanding Cryptolocker(ransomware) with a case […]

2

Cysinfo Cyber Security Meetup – 30th January 2016

This is an announcement for the upcoming Cysinfo cyber security community meetup on 30th January 2016 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. Here is Schedule of Security Talks: 10:15 – 11:00 – Breaking into hospital […]

2

Cysinfo Cyber Security Meetup – 10th October 2015

Friendly reminder for the upcoming Cysinfo cyber security community meet on 10th October 2015 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. Here is Schedule of Security Talks: 10:00-10:45 – Partial Homomorphic Encryption – Sreelakshmy and Mythily […]