ch
Feedback
Reverse Engineering

Reverse Engineering

前往频道在 Telegram

Everything is open-source. The official community group: @reverseengineeringz

显示更多
未指定国家技术与应用20 250
4 786
订阅者
无数据24 小时
+127
+5430
帖子存档
PE Section Header Injection using Code Cave https://link.medium.com/RJy2Yazks1

Online regex tester, debugger with highlighting for PHP, PCRE, Python, Golang and JavaScript. https://regex101.com/

Learn regex the easy way. Regular expression is a group of characters or symbols which is used to find a specific pattern fro
Learn regex the easy way. Regular expression is a group of characters or symbols which is used to find a specific pattern from a text. https://github.com/ziishaned/learn-regex/blob/master/README.md

A Deep Dive into the Emotet Malware Emotet is a trojan that is primarily spread through spam emails. During its lifecycle, it
A Deep Dive into the Emotet Malware Emotet is a trojan that is primarily spread through spam emails. During its lifecycle, it has gone through a few iterations. Early versions were delivered as a malicious JavaScript file. Later versions evolved to use macro-enabled Office documents to retrieve a malicious payload from a C2 server. https://www.fortinet.com/blog/threat-research/deep-dive-into-emotet-malware.html

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files) a
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files) and Zeek logs. https://github.com/idaholab/Malcolm

Reverse Engineering Gootkit with Ghidra Part I https://dannyquist.github.io/gootkit-reversing-ghidra/
Reverse Engineering Gootkit with Ghidra Part I https://dannyquist.github.io/gootkit-reversing-ghidra/

Corona DDoS bot In this article, multiple phases will be described using the usual step-by-step approach. Firstly, the main function is analysed in order to get an overview of the malware’s lay-out. Secondly, the local address is obtained. Thirdly, the mutex that is used by the malware is described. Fourthly, the decryption routine for the encrypted strings will be analysed and rewritten in Java. Using this decryptor, the actual values of the encrypted strings can be obtained. Fifthly, the bot’s registration at the command & control server will be analysed, including a connectivity check. Sixthly, the process of dispatching incoming commands will be analysed. Lastly, a conclusion is made based upon the findings https://maxkersten.nl/binary-analysis-course/malware-analysis/corona-ddos-bot/

Embed and hide any file in HTML: https://github.com/Arno0x/EmbedInHTML

Indicators of Compromise vs. Tactics, Techniques, and Procedures https://azeria-labs.com/iocs-vs-ttps/

Auto-renaming dummy-named functions, which have one API call or jump to the imported API https://github.com/a1ext/auto_re
Auto-renaming dummy-named functions, which have one API call or jump to the imported API https://github.com/a1ext/auto_re

Malware Configuration And Payload Extraction https://github.com/ctxis/CAPE

Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way
Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do. https://github.com/a0rtega/pafish

Here is a quick video demonstrating how @MalScanBot can be used to quickly analyze xls file for malicious indicators from your mobile device.

IDAPython-7.x_cheatsheet_print_en.png2.68 MB