🚀 Build real confidence analyzing malware. Join the waitlist. 🚀
https://go.themalwarelab.co/join
📄 Get my malware analysis template 📄
https://go.themalwarelab.co/get-template
🎥 Video Description 🎥
In this video, we explore a malware evasion technique - API unhooking.
⏱️ Timestamps ⏱️
00:00 - Intro
00:37 - Inline hooking explained
02:04 - Introducing frida-trace
04:12 - Static analysis of Gazprom ransomware
06:18 - Patching Gazprom sample
07:37 - Hooking Gazprom with frida-trace
09:50 - Identifying API unhooking code using x64dbg
12:14 - Reviewing API unhooking code using Ghidra
19:39 - Debugging API unhooking code using x64dbg
😈 Sample: https://github.com/as0ni/youtube-file...
🔑 Password: infected
Unzipped SHA-256: 32ec301f02dfa21932679726f07e30f9c807391aaf1044278c0e0b2c0dc8ebdf
Description: Gazprom Ransomware Sample
🛠️ Tools 🛠️
Frida: https://frida.re/
PEStudio: https://www.winitor.com/download
Process Hacker: https://processhacker.sourceforge.io/...
x64dbg: https://x64dbg.com/
Ghidra: https://ghidra-sre.org/
📞 Follow Anuj on LinkedIn: / sonianuj
On this page of the site you can watch the video online Malware Evasion Techniques: API Unhooking (Malware Analysis & Reverse Engineering) with a duration of hours minute second in good quality, which was uploaded by the user Anuj Soni 21 December 2023, share the link with friends and acquaintances, this video has already been watched 6,718 times on youtube and it was liked by 423 viewers. Enjoy your viewing!