Malware analysis - Emotet droppers:
https://maxkersten.nl/binary-analysis-course/malware-analysis/emotet-droppers/
https://maxkersten.nl/binary-analysis-course/malware-analysis/emotet-droppers/
Screenshot at 2019-06-14 11-52-11.png
297.8 KB
IDA freeware for linux now comes with a local linux debugger!
https://www.hex-rays.com/products/ida/support/download_freeware.shtml
https://www.hex-rays.com/products/ida/support/download_freeware.shtml
Xori is an automation-ready disassembly and static analysis library for PE32, 32+ and shellcode
https://github.com/endgameinc/xori
https://github.com/endgameinc/xori
GitHub
GitHub - endgameinc/xori: Xori is an automation-ready disassembly and static analysis library for PE32, 32+ and shellcode
Xori is an automation-ready disassembly and static analysis library for PE32, 32+ and shellcode - GitHub - endgameinc/xori: Xori is an automation-ready disassembly and static analysis library for P...
Karta - source code assisted fast binary matching plugin for IDA
https://github.com/CheckPointSW/Karta
https://github.com/CheckPointSW/Karta
GitHub
GitHub - CheckPointSW/Karta: Karta - source code assisted fast binary matching plugin for IDA
Karta - source code assisted fast binary matching plugin for IDA - CheckPointSW/Karta
PLASMA is an interactive disassembler. It can generate a more readable assembly (pseudo code) with colored syntax. You can write noscripts with the available Python api.
https://github.com/plasma-disassembler/plasma
https://github.com/plasma-disassembler/plasma
Operation Crack: Hacking IDA Pro Installer PRNG from an Unusual Way
https://devco.re/blog/2019/06/21/operation-crack-hacking-IDA-Pro-installer-PRNG-from-an-unusual-way-en/
https://devco.re/blog/2019/06/21/operation-crack-hacking-IDA-Pro-installer-PRNG-from-an-unusual-way-en/
hexext, a plugin to improve the output of the hexrays decompiler through microcode manipulation.
https://github.com/chrisps/hexext-releases-IDA7.0
https://github.com/chrisps/hexext-releases-IDA7.0
Technical Malware News : Direct links to new technical reports regarding malware.
@TechnicalMalwareNews
@TechnicalMalwareNews
pic2.PNG
5.2 KB
CallObfuscator : Obfuscate windows apis from static analysis tools and debuggers
https://github.com/d35ha/CallObfuscator
https://github.com/d35ha/CallObfuscator