Browsing Category

Reverse Engineering


german-trojan 8

Malware Analysis – Follow along reversing the German government’s “Bundestrojaner”

Introduction I’m reasonably sure that anyone reading this particular article has heard about viruses, worms, trojans and malware; as well as numerous antivirus products like

April 13, 2012 Reverse Engineering
malwareanalysis-book 0

Book Excerpt: Practical Malware Analysis – The Hands-on Guide to Dissecting Malicious Software

Another excellent publisher has offered up a generous sample of a book we’ve been talking about. This is Chapter 12 from Practical Malware Analysis – The

March 09, 2012 Reverse Engineering
rootsmart 0

RootSmart Android Malware

Summary Android’s increasing popularity, combined with the possibility to create alternative markets, makes this platform a fertile ground for malware authors. While most of these

ak 5

Writing Self-Modifying Code Part 3: Antivirus Evasion

This is the third article in a series on the topic of self-modifying code

January 30, 2012 Hacking, Reverse Engineering
android 1

Under the Hood: Reversing Android Applications

For several years now, there has been an explosive increase in the use of mobile applications. Included in this staggering increase of mobile software are

AFewWords 2

A Few Words on Malware – The Sality Way

Malware comes in different sizes and shapes. Trojans, worms, viruses, downloaders, and others are becoming more common than common cold medicine. These malware are mixed

Rootkit Detector Features: Malicious System Threads and Debug Registers

Introduction: In my last article, we’d discussed the most important ways in which a rootkit enters a system and subsequently masks its presence so it

December 16, 2011 Forensics, Reverse Engineering

Writing Self-Modifying Code Part 2: Using extended assembly – Practice

Part 1 is here: http://resources.infosecinstitute.com/writing-self-modifying-code-part-1/ All the code for this tutorial is on github. Links for particular components are interspersed, or you can just pull

December 15, 2011 Hacking, Reverse Engineering

REVERSING RORPIAN – DHCP Hijacking Malware

We have seen our fair share of malware codes from time to time. With the help of disassemblers and debuggers, we have a shot of

December 06, 2011 Reverse Engineering

Writing Self-modifying Code Part 1: C Hello world with RWX and in-line assembly

To follow along with this tutorial, download all source files here In the first part of this tutorial, we’ll be making a basic C scaffold

November 21, 2011 Hacking, Reverse Engineering

Rootkit Detection with Tuluka Kernel Inspector

Introduction A rootkit is a piece of software that is written by someone, who at the very least, wants to spy on specific system calls

AntiCloud Trojan Reverse Engineering Analysis

Introduction In this paper we are going to talk about the Anticloud Trojan, also know as the TrojanDropper:Win32/Bohu.A and B variant. This malware originated in China

Android malware analysis

The advance in technology brought us mobile phones with almost the same power and features as our personal computers. Something that criminal minds will find

Egghunter Exploitation Tutorial

This tutorial will cover the process of writing a buffer overflow exploit for a known vulnerability in the Vulnserver application. This is the fifth article

Mutexes, part two: Using WinDbg to Begin Reverse Engineering Unknown Malware from Memory

Part Two in a multi-part series on holistic, multi-disciplinary analysis and reversing. You can read part one of this series here. The last post, “Mutex

June 13, 2011 Reverse Engineering

Mutexes, part one: The Canary in the Coal Mine and Discovering New Families of Malware

Part One in a multi-part series on holistic, multi-disciplinary analysis and reversing. This post is based on a presentation I gave at the last Thotcon,

June 13, 2011 Reverse Engineering

TDSS part 1: The x64 Dollar Question

In the two years since the Win32/Olmarik family of malware programs (also known as TDSS, TDL and Alureon) started to evolve, its authors have implemented

April 19, 2011 Hacking, Reverse Engineering

Malware Analysis: Classifying with ClamAV and YARA

On a daily basis,we are encountering thousands of new types of malware with unknown content. This malware can come from honeypots, infected websites or even

April 06, 2011 Reverse Engineering

ZeroAccess Malware Part 4: Tracing the Crimeware Origins by Reversing Injected Code

Part 1: Introduction and De-Obfuscating and Reversing the User-Mode Agent Dropper Part 2: Reverse Engineering the Kernel-Mode Device Driver Stealth Rootkit Part 3: Reverse Engineering

November 15, 2010 Reverse Engineering

ZeroAccess Malware Part 3: The Device Driver Process Injection Rootkit

Part 1: Introduction and De-Obfuscating and Reversing the User-Mode Agent Dropper Part 2: Reverse Engineering the Kernel-Mode Device Driver Stealth Rootkit Part 3: Reverse Engineering

November 15, 2010 Reverse Engineering

ZeroAccess Malware Part 2: The Kernel-Mode Device Driver Stealth Rootkit

Part 1: Introduction and De-Obfuscating and Reversing the User-Mode Agent Dropper Part 2: Reverse Engineering the Kernel-Mode Device Driver Stealth Rootkit Part 3: Reverse Engineering

November 15, 2010 Reverse Engineering

Step-by-Step Reverse Engineering Malware: ZeroAccess / Max++ / Smiscer Crimeware Rootkit

(quick plug – to all current & future reverse engineers – check out our Reverse Engineering Training Course. We’d love to publish your work next!) Part

November 12, 2010 Reverse Engineering
Back to Top Copyright © 2012 - InfoSec Institute