首页
社区
课程
招聘
[原创]ARTeam: [ARTUT] Introduction To Malware Techniques and Logics Part 1
发表于: 2009-8-28 21:43 2730

[原创]ARTeam: [ARTUT] Introduction To Malware Techniques and Logics Part 1

2009-8-28 21:43
2730
Hi all,
a new tutorial from Gunther has been published on our site.


Following the great works by EvilCry, I have decided it’s time to release some of my past and present works on Malware Analysis (some of them will be coming soon). This is in the hope of igniting some interests in Malware Analysis via Reverse Engineers’ mindset.
This tutorial is written to provide a better understanding of where to find information and what is the aim of most Trojans. Their aim is simply to steal information or to act as a Bot in a Botnet. Please note that this article has been written for learning purposes and not for complex functionality. In the early days, there were many incidents where users received emails with malicious CHM (Microsoft Compiled HTML Help) and DOC (Microsoft Office Word Document) attachments containing Trojan Riler which is also known as BackDoor-BCB.
So I have decided to impart some of my knowledge on Forensics in order to complete this tutorial, writing “Introduction to Malware Techniques and Logics part 1”. The tutorial will cover different issues:

  • How to decompile .CHM files.
  • How to detect and analyse the shellcode
  • How to dump the backdoor components
  • How to discover the communication protocol

  • I hope that this could begin a new chapter in the ongoing series of Reverse Engineering and Forensics guides from ARTeam and spark a new interest.


    available for download here:

    http://www.accessroot.com/arteam/site/download.php?view.312

    [培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

    收藏
    免费 0
    支持
    分享
    最新回复 (3)
    雪    币: 1407
    活跃值: (17)
    能力值: ( LV2,RANK:10 )
    在线值:
    发帖
    回帖
    粉丝
    2
    Thx for sharing,but i cant get the password.
    2009-8-28 22:41
    0
    雪    币: 433
    活跃值: (1875)
    能力值: ( LV17,RANK:1820 )
    在线值:
    发帖
    回帖
    粉丝
    3
    support!
    2009-8-28 23:56
    0
    雪    币: 93908
    活跃值: (200199)
    能力值: (RANK:10 )
    在线值:
    发帖
    回帖
    粉丝
    4
    Thanks.
    2009-8-29 02:01
    0
    游客
    登录 | 注册 方可回帖
    返回
    //