Malware analysis (hybrid) of RAT and Keylogger
Автор: CyberSecAdventures
Загружено: 2023-07-08
Просмотров: 322
Описание:
This video demonstrates hybrid malware analysis tools and techniques using a new tool in my arsenal - Noriben. We analyze a two stage RAT (Remote Access Trojan) and keylogger using process logs, windows registry logs, ILSpy decompiler and more. We primarily use Remnux and FlareVM for studying this malware sample.
00:00 Intro
01:25 Setting up Noriben
02:54 Detonating stage1 bad.vbs
04:12 Stage1 Noriben Logs
04:59 Stage2 links from Powershell
08:06 Stage2 dll decrypt
09:14 Stage2 logs
10:27 UDP 2 C2?
11:21 Registry persistence
12:30 Strings
12:49 Get Functions
15:18 ILSpy
16:10 C2 address and port
18:40 dnlib
19:40 End
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: