Hosted by Dailymotion. For legal issues report at the Copyright Center, report us on DMC, or use the Instant Removal tool.
Reverse Engineering: Simple malware deobfuscation (CFG reconstruction and xrays) & analysis
J
Joxean Koret
2 Views • Mar 07, 2021
Description
In this video I show how we can create functions when IDA fails because of the usage of opaque predicates, a common anti-disassembling trick. We will also see how we can statically decrypt the malware using a technique called (by the AV industry) as X-Rays.
This malware was called "FlyStudio" by some AV companies. The MD5 hash of the sample analysed in the video is the following one: 09002944F0F0EEC37B022507919C3538. You can download the malware samples from this URL:
https://bazaar.abuse.ch/sample/8b11f853afd0119988fd2fa04e379c6d77eb9806314b198d5c92cd1258fd02f7/
The IDA Python script used in this video to decrypt the body of the malware samples is available here:
https://pastebin.com/MCQ48ghy
This malware was called "FlyStudio" by some AV companies. The MD5 hash of the sample analysed in the video is the following one: 09002944F0F0EEC37B022507919C3538. You can download the malware samples from this URL:
https://bazaar.abuse.ch/sample/8b11f853afd0119988fd2fa04e379c6d77eb9806314b198d5c92cd1258fd02f7/
The IDA Python script used in this video to decrypt the body of the malware samples is available here:
https://pastebin.com/MCQ48ghy
More from User
57:57
How do Windows 'fibers' work? Practical Reverse Engineering.
Joxean Koret
12:40
Reverse Engineering: Fake exports trick and antiemu + obfuscation
Joxean Koret
30:48
Reverse Engineering: Simple malware deobfuscation (CFG reconstruction and xrays) & analysis
Joxean Koret
Related Videos
00:30
Practical Reverse Engineering: x86, x64, ARM, Windows Kernel, Reversing Tools, and Obfuscation
dm_b7e1bfbc018a8fa9197906b71bff0a01
05:29
manual, disassembly i9105P i9105P guideSamsung disassembly disassembly Samsung S2 Plus repair, Plus
Nokia Repair
01:10
Mingletec New design brushless axial blower fan disassembly video #newdesign #newproduct #brushlessmotor #dc #axial #blower #fans #ventilation #disassembly #video #highquality #factory #warehouse #industrial #machine #manufacturer #fyp #philippines
Mingletec
01:02
BACK 2 LIFE DISASSEMBLY | Back 2 Life Disassembly EXPLAINED!
bodyaline-back-pain-machine-AhyZaGFMjgKfkILQ2
05:07
Most Wanted Android Q Mobile X800 Complete Disassembly All Qmobile disassembly
Android Official
06:03
Samsung A33 5G disassembly samsung galaxy A33 5G teardown | full disassembly
javed javed