malwareresearch | Unsorted

Telegram-канал malwareresearch - Malware Research

9630

Group for Malware Analysts. Pinned message with resources and rules: https://t.me/MalwareResearch/38033

Subscribe to a channel

Malware Research

Best bet would be to contact the author

Читать полностью…

Malware Research

Hmn, that is different

Читать полностью…

Malware Research

You mean the initialize_pure_virtual_call_handler?

Читать полностью…

Malware Research

IDA might mistakenly identify the first call

Читать полностью…

Malware Research

But does the disassembly also show that to you?

Читать полностью…

Malware Research

Yeah decompiled code

Читать полностью…

Malware Research

Yeah this is my disassembly

Читать полностью…

Malware Research

Did you check the assembly to verify what the decompiler says?

Читать полностью…

Malware Research

I did download the same sample, referred in this blog, would appreciate if anyone could help me out with it, thanks a bunch

Читать полностью…

Malware Research

I didnt find any function installed to jump to malicious code looks like ordinary CRT code

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Omar Khaled
User ID: 627790635
Reason: asking for cracked software

Читать полностью…

Malware Research

Hello, I need help in an application for windows.
It's called "SHERAeasy model"
I have the files but can't find it cracked.

Читать полностью…

Malware Research

Proper comedy, thank you for that

Читать полностью…

Malware Research

Any one know how to know Avatar singles?

Читать полностью…

Malware Research

New FedBan
Fed: Libra's Empire
FedAdmin: ❤🦦
User: Linda
User ID: 7007124069
Reason: for ignoring warning

Читать полностью…

Malware Research

Well unlike blog it looks different

Читать полностью…

Malware Research

Because your function looks identical to the blog screenshot, the name of the first function just differs

Читать полностью…

Malware Research

How does it look like in the decompiler?

Читать полностью…

Malware Research

are you using the public FLIRT signature server?

Читать полностью…

Malware Research

But there's no signs of the function being called

Читать полностью…

Malware Research

No this is your decompiler

Читать полностью…

Malware Research

Seems like the screenshot above is of the same, but without the call at the start

Читать полностью…

Malware Research

and your decompilation differs from this one?

Читать полностью…

Malware Research

https://alpine-sec.medium.com/hijackloader-targets-hotels-a-technical-analysis-c2795fc4f3a3

Читать полностью…

Malware Research

Guys, need a small help, did anyone reversed HijackLoader, if so am trying to reverse it, some of the writeups say that the code is hooking CRT library's code, specifically the CRT initialization library but I didnt really find any call or indirect jmp to any function

Читать полностью…

Malware Research

Hello people,

Check this and tell me what do you think about it :

https://x.com/S0fianeHamlaoui/status/1801486680404251023

Thank you in advance.

Читать полностью…

Malware Research

Originally responded to:

Читать полностью…

Malware Research

Hello everyone me I can hack any vulnerability exists. i hack to express, not to impress. welcome to the world of code and chords 😊

Читать полностью…

Malware Research

Stay on-topic, and use search engines

Читать полностью…

Malware Research

learn to use a search engine, it will be very helpful

Читать полностью…
Subscribe to a channel