-
-
[转帖]How Malware Walks The PEB To Find Modules By Hash
-
发表于: 2021-2-4 11:45 7146
-
How Malware Walks The PEB To Find Modules By Hash
In this video, we will learn how to recognize a common obfuscation technique malware uses; walking the PEB to find loaded modules by hash. This technique is often used in shellcode, packers, and to thwart AV scanners. Learning to quickly recognize the technique and understand how to deal with it is an important technique to know to advance your malware analysis skills.
Download the malware samples at https://malshare.com to review in your own analysis lab:
1. Example 1: 5d267403191a8786db2062584f298478ba59aa7b4d23adcf850a2c14a55c6d97
2. Example 2: 58e923ff158fb5aecd293b7a0e0d305296110b83c6e270786edcc4fea1c8404c
https://www.youtube.com/watch?v=Tk3RWuqzvII&feature=youtu.be
赞赏
他的文章
- [转帖]IDM.Computer.Solutions.UltraEdit.Enterprise.v2024.1.0.36.x64.Incl.Keyfilemaker-BTCR 1732
- [转帖]IDM.Computer.Solutions.UEStudio.Enterprise.v2024.1.0.36.x64.Incl.Keyfilemaker-BTCR 1741
- [转帖]IDM.Computer.Solutions.UltraFinder.Enterprise.v2023.0.0.17.x64.Incl.Keyfilemaker-BTCR 1624
- [转帖]JEB Decompiler 5.20.0.202411121942 mod by CXV 1624
- [转帖]Tenorshare.4uKey.for.Android.v2.1.1-AMPED 923
看原图
赞赏
雪币:
留言: