ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

Overcome Self-Defending Malware - Tools, Techniques and Lab Setup

Автор: cybercdh

Загружено: 2017-10-07

Просмотров: 17377

Описание: Here I demonstrate how to overcome a simple self-defence tactic that some malware samples commonly utilise to target their victims and prevent sandbox / VM analysis.

I demonstrate how to setup two Virtual Machines to capture networking requests from Windows using fakedns and inetsim, both of which are pre-installed on REMnux. Then, we use ProcMon and Process Hacker to look at running processes, APIMon to capture the API calls used by the malware and x64dbg to disassemble and debug it.

Next I show you how to quickly patch the malware to remove the anti-analysis trick and this enables you to illicit networking IOCs from the sample which are super-useful for you to protect against in your own environment.

Finally I demonstrate a super-cool x64dbg plugin called BreakpointUnresolved which allows you to set a breakpoint on API calls that aren't in the IAT, i.e. API calls that the malware loads and references at runtime. This is a brilliant plugin and one very worthy of putting in your toolkit.

Sample:
MD5: c72228712e3955a28f5ea1ccbcb93b74

Tools Used:
Process Hacker - http://processhacker.sourceforge.net/
Process Monitor - https://docs.microsoft.com/en-us/sysi...
API Mon - http://www.rohitab.com/apimonitor
x64dbg - https://x64dbg.com/#start
PEStudio - https://www.winitor.com/
REMnux - https://remnux.org/
BreakpointUnresolved - I've uploaded compiled versions here: http://jmp.sh/8muSqjs

If you like the video, click Like.
If you loved it, subscribe!
You can also follow me   / cybercdh  

Thanks for watching!

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
Overcome Self-Defending Malware - Tools, Techniques and Lab Setup

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]