Yara-Yara
Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…
[ ARCHIVE ]
Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…
Yara Yara Daze Anyone involved in malware analysis is certainly familiar with a tool like YARA 😉. With its help, many companies 🔴 build sets of signature rules…
Truly subtle interaction 🕊 During reverse engineering of the protocol of one of the Brazilian banking trojans, the use of an interesting network framework was d…
Did you know that malicious actors don't like LNK file parsers? 👿 In March we wrote about XDSpy attacks on Russian organizations. The LNK files used in this att…
@The malware got into the system... @The malware wants to pull a prank... @The malware calls a WinAPI and... @The EDR system detects it and starts screaming ver…
PT ESC has discovered a new Joking Wolf campaign 🐺 The jokesters infiltrate popular (and not-so-popular) Telegram channels and publish non-existent news. The ma…
How to Fix CFG. Part Two 🛠 Earlier we described how to restore a Control Flow Graph (CFG) when it has been obfuscated. However, often during analysis, even of n…
⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability The vulnerability CVE-2025-24071, affecting a wide range of Windows operati…
Graphics with a Surprise: When Vectors Hide Malicious Code 🤨 In this post, we will examine an example of a phishing email in which malicious content was deliver…
.NET Reactor: The Evolution of Protection from 6.7 to 7.0 and Methods for Removing Obfuscation 🔄 .NET Reactor is a powerful tool for protecting executables writ…
[SCCM NTLM Relay] Hello everyone! 👋 My article about SCCM attacks was recently published. It describes in sufficient detail the testing lab, the attacks themsel…
Do you automate debugging? 🧐 The PT Sandbox expert team often has to debug various Windows kernel components in their work, and a kernel debugger is indispensab…