Bypassing BlackMatter Anti-Debug With x64dbg [Patreon Unlocked]

  Рет қаралды 31,165

OALabs

OALabs

Күн бұрын

In this tutorial we demonstrate how to bypass the anti-debug checks in BlackMatter ransomware with x64dbg. Expand for more...
-----
OALABS DISCORD
/ discord
OALABS PATREON
/ oalabs
OALABS GITHUB
github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
www.unpac.me/#/
-----
BlackMatter sample:
malshare.com/s...

Пікірлер: 31
@robbie2044
@robbie2044 2 жыл бұрын
Excellent video. A tip for those who want to "automate" the skip so you don't have to change the IP every time. Check the function out and if it is just calling NtSetInformationThread or some other anti-debug code and it doesn't contain important malware code (which it usually doesn't since it is isolated anti-debug function) you can simply NOP the whole call and skip over that check every time you restart the exe\dll in the debugger.
@OALABS
@OALABS 2 жыл бұрын
Nice tip!
@sylvesterangiho9146
@sylvesterangiho9146 Жыл бұрын
Pls I want to learn software how can you help me please
@az2252
@az2252 2 жыл бұрын
I never thought about using graph view while using x64 lol As always, your vids are the best.
@OALABS
@OALABS 2 жыл бұрын
Thanks! Sometimes it's very useful to see see the control flow from another perspective.
@surajsawant6469
@surajsawant6469 2 жыл бұрын
this is amazing... nice work. thanks for sharing.
@pedrobarthacking
@pedrobarthacking 3 ай бұрын
Amazing content! Please do more videos Reverse engineering context! thank you.
@mytechnotalent
@mytechnotalent 2 жыл бұрын
Brilliant as always!
@qweoiwjewiodc1954
@qweoiwjewiodc1954 2 жыл бұрын
Excellent video
@Axcmotora
@Axcmotora 2 жыл бұрын
Thank you for this Good turtorial :)
@hannahprobably5765
@hannahprobably5765 2 жыл бұрын
features ! love them all 🚩❤
@_why_3881
@_why_3881 2 жыл бұрын
What would be the approach when the exe reproduces itself and its threads (like in process explore you can see 6times the same process)
@OALABS
@OALABS 2 жыл бұрын
That's a completely different topic ;) You may want to check out some of our process injection unpacking tutorials.
@lucasjulianlacognata6670
@lucasjulianlacognata6670 2 жыл бұрын
Thanks Teacher, have you considered writing a book about reversing?
@OALABS
@OALABS 2 жыл бұрын
No books, just live workshops and videos : )
@wittingsun7856
@wittingsun7856 3 ай бұрын
Couldn't you have inserted a jump instead of the push 0?
@dmitriydibenko5529
@dmitriydibenko5529 Жыл бұрын
Almost the same trick, as Enigma does to detach from the debugger. However, if I remember correctly, Enigma uses ZwSetInformationThread instead
@sylvesterangiho9146
@sylvesterangiho9146 Жыл бұрын
Hi please help me crack my software
@dmitriydibenko5529
@dmitriydibenko5529 Жыл бұрын
May I ask you to make a video about Software Nanomites?)
@OALABS
@OALABS Жыл бұрын
No, lol
@AbacateSexy
@AbacateSexy 3 жыл бұрын
Thanks for making these videos free, I love them! Have u considered making a video analyzing the ransomware as a whole? D:
@OALABS
@OALABS 3 жыл бұрын
That's actually next up ... we have been laying the groundwork with the last few tutorials ;)
@AbacateSexy
@AbacateSexy 3 жыл бұрын
@@OALABS Patreon only or u gonna make it public? :c
@OALABS
@OALABS 3 жыл бұрын
Live stream was recorded: kzbin.info/www/bejne/Zl7Tp5euqaiqnKc
@AbacateSexy
@AbacateSexy 3 жыл бұрын
​@@OALABS you are amazing!
@SilentGaming-SG
@SilentGaming-SG 11 ай бұрын
Can this method remove the x63dbg (32bit) virus???
@Sezdik
@Sezdik 2 жыл бұрын
hello, is there someone sleeping while you record? there is background voice.. like snoring ... just sayn
@OALABS
@OALABS 2 жыл бұрын
Haha that's my bulldog Boris. If you check out our streams on Twitch you will see he sleeps beside my desk and has his own doggo cam
@atoma8921
@atoma8921 Жыл бұрын
Where is the part II?
@OALABS
@OALABS Жыл бұрын
On our Patreon : ) www.patreon.com/posts/analyzing-anti-57443723
@nonskeetuser760
@nonskeetuser760 2 жыл бұрын
I think i want to marry this man
Debugging a DLL Export With x64dbg [Patreon Unlocked]
11:15
Когда отец одевает ребёнка @JaySharon
00:16
История одного вокалиста
Рет қаралды 13 МЛН
My Daughter's Dumplings Are Filled With Coins #funny #cute #comedy
00:18
Funny daughter's daily life
Рет қаралды 29 МЛН
I Reverse Engineered this Program and Generated Infinite CD Keys
11:39
How to Crack Software (Reverse Engineering)
16:16
Eric Parker
Рет қаралды 616 М.
Reverse Engineering RollerCoaster Tycoon | How does it work?
38:54
Nathan Baggs
Рет қаралды 249 М.
Learn Reverse Engineering (for hacking games)
7:26
cazz
Рет қаралды 1,1 МЛН
Self-Learning Reverse Engineering in 2022
9:09
LiveOverflow
Рет қаралды 388 М.
How To Defeat Anti-VM and Anti-Debug Packers With IDA Pro
48:37
How I Debug DLL Malware (Emotet)
11:12
Anuj Soni
Рет қаралды 14 М.
6 Horribly Common PCB Design Mistakes
10:40
Predictable Designs
Рет қаралды 206 М.