Malware Theory - How Packers Work, Polymorphism and Misconceptions

  Рет қаралды 6,457

MalwareAnalysisForHedgehogs

MalwareAnalysisForHedgehogs

Күн бұрын

Пікірлер: 17
@cruelsister1
@cruelsister1 Жыл бұрын
Superb! Thank you for the time it took you to write and produce this video. Education is a wonderful thing.
@christauff
@christauff Жыл бұрын
This was very clear and easy to follow. Thank you.
@clemdem4572
@clemdem4572 Жыл бұрын
Very good video thanks for this clear to the point explanation !
@yungdawwg7081
@yungdawwg7081 4 ай бұрын
hello, i have a question regarding the case of using new malware code which is essentially a zero day but packing it with a "tagged" stub, that will result with the file being detected as mw. My question then is it possible for a malware writer to know which stub is unused, or it's impossible since it depends on the packer which chooses randomly, then we are left with two options either there is a packer in the dark web used by hackers which removes a stub each time they sell it to a buyer. or the malware owner tries his packed file with multiple AVs many times until it's not detected ? sorry if i turned it into a monolog i just got lost speaking outloud.
@seif9923
@seif9923 Жыл бұрын
hey man, I have a question, how do I test the malware that I made I don't want to upload it virustotal obviously I just want to test without it getting detected.
@IIIIII-ke3lo
@IIIIII-ke3lo Жыл бұрын
Kleenscan
@banannadb2213
@banannadb2213 Жыл бұрын
You mentioned common malware actors will use packers, but APTs would not. What would APTs use or otherwise do to serve the same purpose?
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
I misspoke. I meant samples for targeted attacks. Malware that is spread on masse needs packing for evasion in the long run, but not malware that is used once or twice for a specific target. So often targeted samples are not packed.
@IIIIII-ke3lo
@IIIIII-ke3lo Жыл бұрын
Couldnt a malware devloper use a c2 to create self morphing malware by having the malware send a request to the c2 to reobfuscate and recompile the malware then send the new malware back and have it replace the old one, this would allow for long time persistence because even if the original stub gets detected it would have already changed completely
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
Sure, but that is not called packing.
@firos5381
@firos5381 Жыл бұрын
could u ever do a demo vedio of al this packking and all of mayb a simple metsploit payload or smthg common u see everytime
@MalwareAnalysisForHedgehogs
@MalwareAnalysisForHedgehogs Жыл бұрын
I think that's a good idea if coupled with how to unpack those again. But I cannot promise anything. I am currently very involved with other projects.
@bhumiputra6108
@bhumiputra6108 Жыл бұрын
Thanks for the explanation. 😘
@johnczech7074
@johnczech7074 Жыл бұрын
Thanks!
@hassnainjaved7399
@hassnainjaved7399 Жыл бұрын
Kindly more videos
Malware Theory - Packer identifiers don"t tell you if a file is packed
9:57
MalwareAnalysisForHedgehogs
Рет қаралды 3,9 М.
Malware Theory - Five Unpacking Methods and a Generic Unpacking Approach
13:26
MalwareAnalysisForHedgehogs
Рет қаралды 2,7 М.
IL'HAN - Qalqam | Official Music Video
03:17
Ilhan Ihsanov
Рет қаралды 700 М.
СИНИЙ ИНЕЙ УЖЕ ВЫШЕЛ!❄️
01:01
DO$HIK
Рет қаралды 3,3 МЛН
Snip3 Crypter/RAT Loader - DcRat MALWARE ANALYSIS
1:42:04
John Hammond
Рет қаралды 507 М.
Malware Analysis - Unpacking AutoIt stub with large obfuscated script
40:05
MalwareAnalysisForHedgehogs
Рет қаралды 2,2 М.
Absolute beginner's guide for Data Mining
10:16
Absolute Beginner's Guide
Рет қаралды 17
Malware Theory - PE Malformations and Anomalies
18:08
MalwareAnalysisForHedgehogs
Рет қаралды 5 М.
Malware Theory - Process Injection
9:26
MalwareAnalysisForHedgehogs
Рет қаралды 25 М.
Practical Malware Analysis Essentials for Incident Responders
50:49
RSA Conference
Рет қаралды 152 М.
How to Crack Software (Reverse Engineering)
16:16
Eric Parker
Рет қаралды 815 М.
Triaging Files on VirusTotal
30:44
MalwareAnalysisForHedgehogs
Рет қаралды 2,7 М.
Malware Analysis - Writing x64dbg unpacking scripts
20:51
MalwareAnalysisForHedgehogs
Рет қаралды 1,6 М.
Cracking Enigma in 2021 - Computerphile
21:20
Computerphile
Рет қаралды 2,5 МЛН
IL'HAN - Qalqam | Official Music Video
03:17
Ilhan Ihsanov
Рет қаралды 700 М.