No spam. Unsubscribe anytime.
Sharing my learning in Malware Analysis journey. All the articles focus on 0x1 topic so it’s security-in-bits.
Most Popular
AdaptixC2 Defender
Deobfuscate PowerShell using MinusOne
Unpack RedLine stealer using dnSpyEx – Part 3
Parent PID Spoofing (Stage 2) Ataware Ransomware – Part 0x3
Discovery using nltest, net and whoami
Join for free. Practical security bits you can act on the same day. No theory, no fluff.
Detection Engineering and Threat Hunting
wbadmin NTDS.dit dump detection for Domain Controllers
LSASS Dump via comsvcs.dll: Defender Detection Guide
Discovery using nltest, net and whoami
How to set up Sigma rules for Elasticsearch SIEM
Malware Analysis Series
Java Malware Analysis – Qealler/Pyrogenic
This series discuss about Pyrogenic/Qealler which is heavily obfuscated Java based Infostealer but the techniques/methods used in the series can be applied to any Java malware. Part 0x1 start with static analysis of first layer of obfuscation, next part 0x2 you will learn unpacking using Java agent and in the last part 0x3 we find similarity between Qealler/Pyrogenic variants based on static code analysis.
Qealler Infostealer static analysis – Part 0x1
Unpacking Pyrogenic/Qealler using Java agent -Part 0x2
Similarity between Qealler/Pyrogenic variants -Part 0x3
Unique Infection vector from Excel 4.0 Macro to Ransomware – Ataware
This series cover infection chain of very interesting ransomware with unique infection vector xls -> Excel 4.0 Macro(XLM) -> mshta -> Dropbox url -> hta -> VBScript -> PowerShell -> Dropbox url -> exe . This series uses Ghidra for reversing PE files and uses Sysmon for dynamic analysis.
Part 0x1 start with basics of analysing steps for hta, VBScript & PowerShell, next part 0x2 you will learn about UAC bypass using CMSTPLUA COM interface using Ghidra and in the last part 0x3 we find analyse the binary from WinMain to Parent PID Spoofing technique. This is one of the best sample from which you can learn different techniques.
Excel 4.0 Macro, hta, VBScript & PowerShell Analysis Ataware Ransomware – Part 0x1
UAC bypass analysis (Stage 1) Ataware Ransomware – Part 0x2
Parent PID Spoofing (Stage 2) Ataware Ransomware – Part 0x3
Deobfuscation of Macro & PowerShell – Emotet
This video series cover the of deobfuscation of Office Macro and PowerShell used in Emotet infection chain Email ->doc -> Macro -> PowerShell -> exe. Part 0x1 will show you process to analyse obfuscated malicious macro embedded in Emotet downloader office document and next part 0x2 will deobfuscate PowerShell extracted from Macro.
Deobfuscate malicious macro – Part 0x1
Deobfuscate Emotet PowerShell – Part 0x2
Tips
This posts cover the tips/techniques which you can use to speed up your Malware Analysis.




















