14.01.2018
The Big Zeus Family Similarity Showdown
›
Dear followers of this blog, I wish you a happy new year! About a month ago, I have launched my latest project: Malpedia ( slides here )....
1 Kommentar:
16.05.2017
Quick analysis write-up on the "link" between Lazarus and WannaCry
›
Here is a short post on what I found out about the "link" between Lazarus and WannaCry. To me, the function referenced looks a lo...
2 Kommentare:
10.04.2017
ApiScout: Painless Windows API information recovery
›
After hacking away for some days in the code chamber, I'm finally satisfied with the outcome and happy to announce the release of my n...
1 Kommentar:
05.02.2017
Knowledge Fragment: Hardening Win7 x64 on VirtualBox for Malware Analysis
›
After some abstinence, I thought it might be a good idea to write something again. The perfect occasion came yesterday when I decided to bui...
12 Kommentare:
18.08.2015
Knowledge Fragment: Fobber Inline String Decryption
›
In the other blog post on Fobber, I have demonstrated how to batch decrypt function code, which left us with IDA recognizing a fair amount ...
1 Kommentar:
Knowledge Fragment: Unwrapping Fobber
›
About two weeks ago I came across an interesting sample using an interesting anti-analysis pattern. The anti-analysis technique can be best...
1 Kommentar:
15.04.2015
Knowledge Fragment: Bruteforcing Andromeda Configuration Buffers
›
This blog post details how the more recent versions of Andromeda store their C&C URLs and RC4 key and how this information can be brutef...
‹
›
Startseite
Web-Version anzeigen