Malware Evasion Techniques: API Unhooking (Malware Analysis & Reverse Engineering)

Publié le: 21 décembre 2023
sur la chaîne: Anuj Soni
6,718
423

🚀 Build real confidence analyzing malware. Join the waitlist. 🚀
https://go.themalwarelab.co/join

📄 Get my malware analysis template 📄
https://go.themalwarelab.co/get-template

🎥 Video Description 🎥
In this video, we explore a malware evasion technique - API unhooking.

⏱️ Timestamps ⏱️
00:00 - Intro
00:37 - Inline hooking explained
02:04 - Introducing frida-trace
04:12 - Static analysis of Gazprom ransomware
06:18 - Patching Gazprom sample
07:37 - Hooking Gazprom with frida-trace
09:50 - Identifying API unhooking code using x64dbg
12:14 - Reviewing API unhooking code using Ghidra
19:39 - Debugging API unhooking code using x64dbg

😈 Sample: https://github.com/as0ni/youtube-file...
🔑 Password: infected
Unzipped SHA-256: 32ec301f02dfa21932679726f07e30f9c807391aaf1044278c0e0b2c0dc8ebdf
Description: Gazprom Ransomware Sample

🛠️ Tools 🛠️
Frida: https://frida.re/
PEStudio: https://www.winitor.com/download
Process Hacker: https://processhacker.sourceforge.io/...
x64dbg: https://x64dbg.com/
Ghidra: https://ghidra-sre.org/

📞 Follow Anuj on LinkedIn:   / sonianuj  


Sur cette page du site, vous pouvez voir la vidéo en ligne Malware Evasion Techniques: API Unhooking (Malware Analysis & Reverse Engineering) durée heure minute seconde en bonne qualité , qui a été Téléchargé par l'utilisateur Anuj Soni 21 décembre 2023, Partagez le lien avec vos amis et connaissances, sur youtube cette vidéo a déjà été regardée 6,718 fois et il a aimé 423 téléspectateurs. Bon visionnage!