Two more analyses: https://www.countercept.com/blog/analysis-shadowhammer-asus-attack-first-stage-payload/ https://skylightcyber.com/2019/03/28/unleash-the-hash-shadowhammer-mac-list/ Nothing new though, except for the almost complete list of targeted MAC addresses: https://github.com/skylightcyber/...

360 security did some cracking or hash calculations:

Source: https://twitter.com/360TIC/status/1110797967621914625

Yeah, would be interesting to know. Also, earlier samples are patched in a different way, more primitive. 6aedfef62e7a8ab7b8ab3ff57708a55afa1a2a6765f86d581bc99c738a68fc74 The difference to the previous sample is that not the call of ___crtCorExitProcess in ___crtExitProcess was patched, but instead ...

Nice analysis! Want to add some additional details. 9a72f971944fcb7a143017bc5c6c2db913bbb59f923110198ebd5a78809ea5fc (from Kaspersky blog post) The attacker patched the original call to ___crtCorExitProcess inside ___crtExitProcess with a call to some injected code at the end of the .text section: O...

Hi folks, the last point on the list of board modernizations was a new and more modern theme. I have chosen a dark theme and think it looks much better than the default phpBB theme. Apologies for any inconvenience. Edit: Switched to a light color theme as some people didn't like the dark one. Edit2:...

Hi, as you can see, I reorganized the forums a bit to remove the previous unorganized flat structure. Now, you can see the board structure from the beginning and not only after visited a forum. As all the other recent changes, this was also long overdue. Apologies for any inconvenience. Regards, R13...

Hi, as you can see, I finally enabled encrypted HTTPS for the forum which was long overdue. As a consequence, you have to login again as all sessions were deleted and a new cookie has to be created. It took a little longer to install the TLS/SSL certificate (Let's Encrypt) than expected, but at the ...

as some may have noticed we did a forum maintenance yesterday (20:15:00, 3rd of March 2019, +1 UTC). It took a little longer than expected, however at the end everything was successful. Apologies for any inconvenience.



