estrellas

548 posts

estrellas banner
estrellas

estrellas

@CryptDeriveKey

Reverse engineer mostly interested in SAT/SMT solvers, Program Analysis, and Obfuscation. Views are my own.

انضم Mart 2020
847 يتبع363 المتابعون
estrellas
estrellas@CryptDeriveKey·
@BlinkzSec This is likely APT-C-36/Blind Eagle.
English
0
0
0
119
blinkz
blinkz@BlinkzSec·
Let's now take a look at the .bat file. #malware sha256:dbe95eb55c806cad0b0914da8a5003cb464e23a4c8c8289c97d514be76823f24 bazaar.abuse.ch/sample/dbe95eb… This uses a kind of set/goto obfuscation. In the end, a PowerShell script comes out of it.
blinkz tweet media
English
2
3
17
1.1K
estrellas
estrellas@CryptDeriveKey·
estrellas tweet mediaestrellas tweet media
QME
0
0
2
266
смех
смех@0x6D6172636F·
🫠
смех tweet media
QME
24
282
3.1K
107.5K
Drew
Drew@bugfireIO·
@0x6D6172636F Is it a publicly available podcast? Would definitely take a listen.
English
1
0
2
52
смех
смех@0x6D6172636F·
weekly podcast appearances are now by far the most stressful part of my job lol. how do people do this for a living. i sound like a cartoon character.
English
2
0
9
768
estrellas
estrellas@CryptDeriveKey·
@belabs_james Appreciate the feedback! Do you have any resources on doing so? I've also been thinking about implementing value tracking for tail call detection purposes.
English
1
0
0
96
James
James@belabs_james·
@CryptDeriveKey Neat. Careful with that ‘is_stack_access’ function though. That segment is not useful on x64, and certainly does not indicate stack access. You’ll need real value tracking across the whole cfg to implement a function like that.
English
1
0
2
191
estrellas
estrellas@CryptDeriveKey·
Lately I've been working in my very own binary lifter... As part of the documentation process, I decided to write a few words about my implementation of static recovery of a given function's control flow graph. Hope you enjoy it! deobfuscation.club/blog/on-static…
estrellas tweet media
English
2
10
45
6.1K
estrellas
estrellas@CryptDeriveKey·
@netspooky Pyarmor's BCC mode transpiles python to C, producing an ELF afterwards (even for Windows applications). The ELF can also be a wrapper around GNU Lightning (JIT assembler) if certain options are marked in the obfuscation process
English
0
1
7
1.1K
Battle Programmer Yuu
Battle Programmer Yuu@netspooky·
What's the most unexpected or interesting place you have seen the ELF format used? Especially non-Linux use cases (eg Firehose programmers)
English
2
1
19
2.5K
John Scott-Railton
John Scott-Railton@jsrailton·
NEW: 🇰🇵DPRK has begun hiding malware on blockchain. Result, decentralized, immutable malware. Nearly impossible to remove. Research by @Mandiant
John Scott-Railton tweet mediaJohn Scott-Railton tweet mediaJohn Scott-Railton tweet media
English
91
666
3K
371.1K
celeste
celeste@vmfunc·
my cat just died
English
16
0
42
2.3K
estrellas
estrellas@CryptDeriveKey·
@vector35 @RussianPanda9xx Mostly these. They are: Search options (text, byte pattern, imm), Segments view, Graphs editor (zoom, fit to window, proximity browser), Graphs view (XREFs, Function calls), and "Windows management" (Imports, Exports, Strings)
estrellas tweet media
English
0
0
1
58
Vector 35
Vector 35@vector35·
@CryptDeriveKey @RussianPanda9xx Which icons in the toolbar do you use most often? Have you tried using the command-palette as an alternative? Variable naming is good feedback -- definitely something we can change to make the transition easier.
English
1
0
0
51
estrellas
estrellas@CryptDeriveKey·
@vector35 @RussianPanda9xx I am honestly not a big fan of the r64_N syntax for variables, the lack of icons for functionalities, as well as not having brackets😅... But I do appreciate being able to go through many different IL's, and IL forms
English
1
0
0
68
Leandro Fróes
Leandro Fróes@leandrofr0es·
Some career news: some weeks ago I decided to move to a new path and try a kind of hidden dream I have since years. Instead of malware research and RE now I’ll be doing windows development and research in both user and kernel. 🥹
English
5
0
20
333
смех
смех@0x6D6172636F·
Non Appetít
смех tweet media
Magyar
3
0
9
370