Tuesday, March 31, 2020

Beware of scam during COVID-19 Pandemic:

We are all in the mid of pandemic on the Corona infection widespread and facing nationwide lockdown (many countries are facing the lockdown for more than 15 days. Many people including celebrities like actors, sportspersons started contributing to generously on PM care fund, so these funds can contribute to people who are suffering from COVID-19 infection. But, scammers are using this time to lure the contributor and collecting funds to fake BHIM account which deceives like PMcare fund. Refer to the below snapshot:

The legit account has the beneficiary name (Registered name) as Pm Cares and the fake ID as pmcare@sbi. Contributors need to be more careful about the beneficiary BHIM UPI ID is correct. Ev 

Post by

Saturday, March 21, 2020

Arnold Schwarzenegger - True inspirational!!! (Part -1)

We all have someone as an inspirational being who always guide us during their critical vertexes of life. In my personal heroes, Arnold Schwarzenegger is a true inspiration not only for bodybuilders, actors, politicians but mainly for immigrants and people who want to live the American dream. Many times, when I am down with setbacks I do listen to the talks of Arnold about the struggles he faced in his life especially at the beginning of his bodybuilding career. 

Let's watch his one of the groundbreaking speech about success and motivational thoughts.

Dream about life in America
Arnold was born after the second world war and lives with his family in Austria (the country was experiencing the effect of the post-war situation). During one of his school days, there was a documentary played for school children about life in America. The little kid start to dream about life in America. He started to dream of settling in America and he didn't know that he is going to be the perfect symbol of the American dream.
"American dream: the ideal by which equality of opportunity is available to any American, allowing the highest aspirations and goals to be achieved."

Arnold Schwarzenegger embodies such visions and achieved his target. He didn't realize that one need a golden ticket to enter the land of opportunities. Like Steve Jobs quoted one couldn't see the dots connecting in the future and they realize by seeing the past which connects the dot. Yes, Arnold saw the picture of Reg Park, his future idol, in the magazine stores which made him choose bodybuilding for living. And it is the golden ticket to enter his dreamland, America. The big muscles and gigantic shoulders of a single picture created the spark on the little kid. (That is why legends told that picture is a thousand words.) 

Picking up the weights as he could

Arnold is fortunate to have a vision in life to become a bodybuilding champion and he started picking up the weights as he could lift. With laser-sharp focus, hard work, Arnold started to gain quality muscles and definitions. 
For his dedication, we have a classic example:  
In usual Gym training, people do a warm-up before weight training. Arnold served in the Austrian Army in 1965 to fulfill the one year of service required at the time of all 18-year-old Austrian males. He usually drives the military truck which warm-up the driver. To not waste the warm-up in driving, he usually carries the dumbles with him and performs the strength training exercise. 
Laser-sharp focus: During his army service, he won the Junior Mr. Europe contest.

True inspirational continues...

Post by

Saturday, March 7, 2020

Analysis of latest Trickbot malware sample - served in excel attachment

Twitter link:

The malware sample of trickbot was already submitted in the anyrun online sandbox for malware analysis.

We collected this malware sample and performed a manual analysis. The file details are:

Searched this hash in the VirusTotal for detection hits:

File name: Unpaid_invoice_1462.xls

File size: 109.5 KB
SHA256: 9e777e1e2e80909b5054c1eca935edc7046feb7d4546f40d392549e2f481d08e
MD5: 1f38f17810621dbff93a4e8cbd2ea1bf

This excel embedded with a macro that connects to a suspicious URL. We executed the malware in our VM, it prompts to enable the macro. After enabling, it to try to connect the following Link:

URL: pnxkntdl(.)xyz/KJSDBViad7

Currently, it didn’t download any other payloads.

Post made by

Setting up breakpoints in VirtualAlloc and VirtualProtect during malware analysis:

 Malware analysts add breakpoints in functions like `VirtualProtect` and `VirtualAlloc` for several key reasons: Understanding Malware Behav...