"I'm attaching the data in the attachment" 💌
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
Static resolution of imports 👨💻 Dynamic resolution of imports by hash sums in malware is a well-worn topic, but to perform static analysis it is necessary to l…
Mount point. Pt 2 Hello! We decided to talk about disk mounting again. Today we'll tell you how to work with LVM containers. Here's a short manual so you don't…
😏 Useful tools: Mandiant capa Imagine the situation: you are a malware analyst or an incident response specialist and you need to analyze a large volume of bina…
Mount Point — pt.1 🙂 Any investigation is an analysis of operating system artifacts. And to obtain them, you often have to work with virtual machine images, suc…
What exactly is wrong with this AES? ❔ Attackers often use encryption to obfuscate parts of malware samples that may be of greatest interest during research. Wh…
Ngrok. Finding and understanding it 🔍 In the process of investigating numerous incidents, we repeatedly encounter a tool such as ngrok. It is a convenient legit…
Learning to Recover VMProtect Imports ⚙️ VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only si…
SSH-IT. Guide to detecting a popular tool 🔭 In the course of investigating numerous incidents involving the compromise of Linux nodes, we sometimes discover var…
An endless chain of redirects ♾️ Quite often, when sending phishing links via email, attackers do not attach them explicitly to the email but use various redire…
How to fix CFG 🔧 In the process of reverse engineering malware, we encounter cases where obfuscation hinders understanding the overall algorithm. One example is…
📫 X-Filtering of User Data In the process of analyzing email traffic, we periodically encounter the implementation of unusual malicious techniques. Today we wan…