Media Summary: The class materials are available at Follow us on Twitter for class news ... The newest ROKRAT variant injects its shellcode into cmd.exe, which will in turn decrypt a PE image. We debug the Get the class materials to follow along at Follow us on Twitter ...

Malware Analysis Hook Injection Poc By Robert Kuster - Detailed Analysis & Overview

The class materials are available at Follow us on Twitter for class news ... The newest ROKRAT variant injects its shellcode into cmd.exe, which will in turn decrypt a PE image. We debug the Get the class materials to follow along at Follow us on Twitter ... by Ralf Hund Microsoft Common Object Model (COM) is a technology for providing a binary programming interface for Windows ... The strings of this trojan-spy are obfuscated. We figure out that this is a monoalphabethic substitution cipher and patch the trojan ... Episode 4 takes a deep, cinematic dive into the advanced architecture of an infection. We move beyond basic

Our Security Advisor Magnus K. Stubman presenting at OWASP Copenhagen. Talk 1 is "Discount Phish Burn Better" is a talk ... We look at signs that this sample is packed and how we can see that it uses RunPE to This video is a summary about my paper “Phantom Malware: Conceal Malicious Actions From

Photo Gallery

Malware Analysis - Hook Injection PoC by Robert Kuster
2013 Day2P04 LoB: IAT Hooking Demo
Malware Theory - Process Injection
Malware Analysis - ROKRAT Unpacking from Injected Shellcode
Hook Analyser 2 1 Demo
Dynamic Malware Analysis D2P14 Maneuvering IAT EAT Inline Hooking Overview
Malware Analysis   Hook Analyser 1 4
The Beast Within - Evading Dynamic Malware Analysis Using Microsoft COM
Preview - Hook Analyser 3.1 :  Cyber Threat Intelligence
Hook Analyser 1.1
Malware Analysis - Deobfuscating Loyeetro Trojan-Spy
Malware Analysis - Code Injection via CreateRemoteThread & WriteProcessMemory
Sponsored
Sponsored
View Detailed Profile
Sponsored
Sponsored