Malware Analysis - 3CX SmoothOperator ffmpeg.dll with Binary Ninja

  Рет қаралды 2,900

MalwareAnalysisForHedgehogs

MalwareAnalysisForHedgehogs

Күн бұрын

Пікірлер: 15
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
We analyze the trojanized ffmpeg.dll that was used in the supply chain attack called SmoothOperator. Me mark up the decompiled code in Binary Ninja and decrypt the next stage. Buy me a coffee: ko-fi.com/struppigel Follow me on Twitter: twitter.com/struppigel Tools: Binary Ninja: binary.ninja/ PortexAnalyzerGUI: github.com/struppigel/PortexAnalyzerGUI/releases/tag/0.12.9 Sysinternals: learn.microsoft.com/en-us/sysinternals/downloads/strings Samples: ffmpeg: bazaar.abuse.ch/sample/7986bbaee8940da11ce089383521ab420c443ab7b15ed42aed91fd31ce833896 d3dcompiler_47.dll: bazaar.abuse.ch/sample/11be1803e2e307b647a8a7e02d128335c448ff741bf06bf52b332e0bbf423b03
@EvilSapphireR
@EvilSapphireR Жыл бұрын
Just found a sample in our AV company. Will complement my analysis with yours. Thank you!
@naveenjkondeti4214
@naveenjkondeti4214 Жыл бұрын
Great video, I wish I'm as fast as you.
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
I cut out very long silences so I am probably not as fast as you think. You can check out OALabs on Twitch for some live reversing to get a feel of the actual pace of reversing :D
@sven957
@sven957 Жыл бұрын
love your videos!
@tonymack651
@tonymack651 Жыл бұрын
Where can I get an infected msi file from?
@bhumiputra6108
@bhumiputra6108 Жыл бұрын
vx-underground
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
I did not upload it at malwarebazaar because it is too big for that. But it seems there is another page that can do that: tria.ge/230330-3nzfjshc2s
@tonymack651
@tonymack651 Жыл бұрын
Thanks! You’re the best!
@bhumiputra6108
@bhumiputra6108 Жыл бұрын
I am a noob at malware analysis and lost you when you started renaming the functions. I still have no clue how you know where to look in the binary. Anyways would be watching this multiple time thanks for this informative video.
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
Thank you for your comment. You are welcome. It is not the best sample for beginners in reversing. You might want to get back at it later, then it will make more sense. A lot of the reversing process is pattern recognition which comes only with experience.
@_zproxy
@_zproxy Жыл бұрын
have ye ever looked at tiberian sun game exe?
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
I haven't done game reversing so far
@_zproxy
@_zproxy Жыл бұрын
@@MalwareAnalysisForHedgehogs have ye ever seen blowfish encryption being used?
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
@@_zproxy I do not specifically remember that. But that does not mean I haven't seen it. I am forgetful.
Malware Analysis - 3CX SmoothOperator Authenticode Abuse
9:22
MalwareAnalysisForHedgehogs
Рет қаралды 1,1 М.
Malware Analysis - Unpacking AutoIt stub with large obfuscated script
40:05
MalwareAnalysisForHedgehogs
Рет қаралды 2,3 М.
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 148 МЛН
Une nouvelle voiture pour Noël 🥹
00:28
Nicocapone
Рет қаралды 9 МЛН
Cat mode and a glass of water #family #humor #fun
00:22
Kotiki_Z
Рет қаралды 42 МЛН
this vulnerability shouldn’t even exist
14:33
Low Level
Рет қаралды 241 М.
An Intro to Binary Ninja (Free) for Malware Analysis
20:03
Anuj Soni
Рет қаралды 6 М.
Episode 5 - Backdoors, Apple, and the FBI
27:03
Hacked
Рет қаралды 3,4 М.
FAKE Antivirus? Malware Analysis of Decoy 'kaspersky.exe'
1:28:19
John Hammond
Рет қаралды 277 М.
Malware Analysis - Writing x64dbg unpacking scripts
20:51
MalwareAnalysisForHedgehogs
Рет қаралды 1,8 М.
How to Crack Software (Reverse Engineering)
16:16
Eric Parker
Рет қаралды 859 М.
What Enterprise-Grade malware looks like
20:09
Eric Parker
Рет қаралды 74 М.
Showing Scammers Their Own CCTV Cameras On My Computer!
18:26
The Perfect Dependency - SQLite Case Study
19:32
Tom Delalande
Рет қаралды 84 М.
Why More People Dont Use Linux
18:51
ThePrimeTime
Рет қаралды 348 М.
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 148 МЛН