Open in app
Home
Notifications
Lists
Stories

Write
Mohammad Amr Khan
Mohammad Amr Khan

Home
About

Sep 20, 2021

CVE-2021–40444 CyberChef Recipe

This is a quick cyberchef receipe to extract defanged URLs from the maldocs that are used as the first stage of CVE-2021–40444’s exploitation https://gchq.github.io/CyberChef/#recipe=Unzip('',false)Regular_expression('User%20defined','Target%3D%22mhtml:%5B%5E!%5D%2B!x-usc:%5B%5E!%20%22%5D%2B',true,true,false,false,false,false,'List%20matches')Find_/_Replace(%7B'option':'Regex','string':'Target%3D%22mhtml:'%7D,'',true,false,true,false)Find_/_Replace(%7B'option':'Regex','string':'!x-usc:'%7D,'%5C%5Cn',true,false,true,false)Unique('Line%20feed')Defang_URL(true,true,true,'Valid%20domains%20and%20full%20URLs')…

Cyberchef

2 min read

CVE-2021–40444 CyberChef Recipe
CVE-2021–40444 CyberChef Recipe

Sep 18, 2021

Analysis of 1d4a1bc1cf53be8e18789b4c6c351c6f0ee88e14cf4fbde0adc55e0b39010bdc (maldoc)

The samples included in this analysis were obtained from MalwareBazaar. This writeup will look at two different files. The first file is a .vbs file and the second is a .ps1 script that is downloaded by the vbs file. Summary This is an analysis of two malicious files that are used…

Malware Analysis

3 min read

Analysis of 1d4a1bc1cf53be8e18789b4c6c351c6f0ee88e14cf4fbde0adc55e0b39010bdc (maldoc)
Analysis of 1d4a1bc1cf53be8e18789b4c6c351c6f0ee88e14cf4fbde0adc55e0b39010bdc (maldoc)

Sep 18, 2021

Installing MISP

MISP is a great threat intelligence platform, for users/organizations of all sizes. One of the major advantages that it has going for it, is the rapid pace at which it is developing. Every single release is packed with more updates and new features that are creating and impressive tool. I’ve…

Misp

4 min read

Installing MISP
Installing MISP

Aug 31, 2021

Phishing Analysis 1 — MoonFruit UofT

The email was delivered from what appears to be a student mailbox since the domain is prepended by a term that is used for student emails. The email itself is not directed at the any user in particular and does not contain any greeting message or personalization. …

Phishing Email

2 min read

Phishing Analysis 1 — MoonFruit UofT
Phishing Analysis 1 — MoonFruit UofT

Aug 30, 2021

Setting Up Flare VM

This post will detail how I went about setting up Flare VM for static analysis. The first step was to setup a Windows 7 VM and this was done using VirtualBox. The specs that I used are listed below (these are limited by the equipment that I have access to): …

Malware

3 min read

Setting Up Flare VM
Setting Up Flare VM
Mohammad Amr Khan

Mohammad Amr Khan

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable