data:image/s3,"s3://crabby-images/0e232/0e232d87d4986aa2658b82b88368eae2ffa545be" alt="Reversing a NSIS dropper using quick and dirty shellcode emulation"
Reversing a NSIS dropper using quick and dirty shellcode emulation
We will statically unpack and emulate a malicious NSIS installer running multiple shellcodes, up to the final Lokibot password stealer and its configuration.
Read more →
data:image/s3,"s3://crabby-images/c85f1/c85f10ccc4869acf6f72622fe601a7ca196a9f70" alt="Cutting corners against a Dridex downloader"
Cutting corners against a Dridex downloader
When one faces obfuscated code, it is sometimes more efficient to focus on the data instead. By using Malcat's different views and analyses (and a bit of guessing as well), we will show how to statically unpack an excel downloader and the following obfuscated native dropper without (much) reverse engineering.
Read more →
data:image/s3,"s3://crabby-images/bb381/bb38120e36d0f59a8381c37e368d9f5a292361d2" alt="Exploit, steganography and Delphi: unpacking DBatLoader"
Exploit, steganography and Delphi: unpacking DBatLoader
We will unroll a maldoc spam exploiting CVE-2018-0798 leading to a multi-staged Delphi dropper abusing steganography and cloud services to conceal its payload
Read more →
data:image/s3,"s3://crabby-images/3c6c4/3c6c4361ace2b612ea097d4d041819ba3cc342ae" alt="Statically unpacking a simple .NET dropper"
Statically unpacking a simple .NET dropper
Our target is a 2-layers .NET dropper using multiple cipher passes (XOR, AES ECB and AES CBC + PBKDF2) to finally drop a Loki sample. Without even starting a debugger, we will show how to unpack it 100% statically using Malcat's builtin transformations and the python scripting engine.
Read more →