Deep dive into imports: continuing to explore static resolution methods
Deep Dive into Imports: Continuing to Explore Static Resolution Techniques 🕵️♂️ Earlier we discussed how static import resolution can be implemented. However…
Deep Dive into Imports: Continuing to Explore Static Resolution Techniques 🕵️♂️ Earlier we discussed how static import resolution can be implemented. However…
Truly subtle interaction 🕊 During reverse engineering of the protocol of one of the Brazilian banking trojans, the use of an interesting network framework was d…
@The malware got into the system... @The malware wants to pull a prank... @The malware calls a WinAPI and... @The EDR system detects it and starts screaming ver…
How to Fix CFG. Part Two 🛠 Earlier we described how to restore a Control Flow Graph (CFG) when it has been obfuscated. However, often during analysis, even of n…
Are you using cryptography correctly? 🔓 The Advanced Threat Research Group of the Threat Intelligence department often has to solve interesting tasks in the pro…
Static resolution of imports 👨💻 Dynamic resolution of imports by hash sums in malware is a well-worn topic, but to perform static analysis it is necessary to l…
📑 TaxOff: looks like you have… a backdoor In the third quarter, specialists from the TI department of the Positive Technologies Expert Security Center (PT Exper…
How to fix CFG 🔧 In the process of reverse engineering malware, we encounter cases where obfuscation hinders understanding the overall algorithm. One example is…
🛠 Reverse Engineering Delphi without IDR When you're actively involved in reverse engineering, sooner or later you encounter an executable file written in Delph…
🔦 How We Found the ITW Exploit for CVE-2024-38178 As part of our monthly review of freshly patched vulnerabilities, our team in ESC-VR pays close attention to v…
👏 One-two — and done. Generating FLIRT signatures And we do this to avoid wasting time on recognizing the library code of PureBasic, in which the COM-DLL-Droppe…
Rapid decryption of data from an NSIS script 🗄 When there's no time to identify the encryption algorithm and implement a decryption algorithm, a debugger comes…