Malware Analysis - ZPAQ to .NET downloader to Injector DLL unpacking
A phishing attempt with an unusual archive format named ZPAQ leads to an interesting malware downloader. We debloat the sample and decrypt the downloaded .wav file with binary refinery. It turns out to be an injection DLL. We use powershell to execute it and deal with its obfuscation. Although the injector fails, we unpack the payload.
Tools: zpaq, DnSpy, IlSpy, binary refinery, PortexAnalyzer, HxD
Malware course:
ZPAQ article:
ZPAQ sample:
.WAV file:
Twitter:
00:00 Intro
01:27 Original article
02:33 Unpacking ZPAQ and debloating
05:35 Downloader analysis
09:14 Malware course
09:40 Decrypting the .wav file
11:49 injector analysis
16:38 String decryption with PowerShell
21:23 Unpacking the payload
0 views
0
0
8 months ago 00:09:02 1
Павел Таратынов: зачем “Лаборатории Касперского“ свой SIEM и что от него ожидать
8 months ago 00:41:39 7
(Не)безопасность Open Source пакетов: о доверии, культуре и инструментах DevSecOps
9 months ago 00:31:23 0
Demystifying Modern Windows Rootkits
9 months ago 00:08:27 0
How to Fix Google Ads Disapproved for Compromised Site 2024 🚫🔄 (Case Study) 📈🔓
10 months ago 00:08:01 0
new attack leaks secrets using RAM as a radio
10 months ago 02:27:57 0
Повышение квалификации специалистов по информационной безопасности
11 months ago 00:06:50 0
lol crowdstrike just destroyed the internet
12 months ago 00:28:31 0
Project Golden Dragon 2/3
12 months ago 00:31:10 0
Project Golden Dragon 1/3
12 months ago 00:32:12 0
Project Golden dragon 3/3
1 year ago 00:20:53 0
Players are in Danger
1 year ago 00:57:39 0
⚠️ Полный гайд по компьютерным вирусам для хакера или безопасника | Люди PRO
1 year ago 00:08:03 0
you will never ask about pointers again after watching this video
1 year ago 00:15:34 0
ОН ВАМ НЕ ГУСЬ! | РАЗОБЛАЧЕНИЕ Empire of Geese | ПЕРЕЗАЛИВ с канала VirusCheck
1 year ago 00:08:28 4
secret backdoor found in open source software (xz situation breakdown)
1 year ago 00:08:32 5
researchers find unfixable bug in apple computers
1 year ago 00:34:11 0
Malware Analysis - JS to PowerShell to XWorm with Binary Refinery
1 year ago 00:01:15 0
coding in c until I go completely insane
1 year ago 00:39:13 0
REDIScovering HeadCrab - A Technical Analysis of a Novel Malware and the Mind Behind It
1 year ago 02:34:41 0
Master Wireshark: Your Ultimate Guide to Hunting Cyber Villains! 🌐🦸♂️
1 year ago 00:05:30 0
Binary Ninja - Fix unresolved stack pointer
1 year ago 00:34:03 0
Linux for Hackers: LINUX commands you need to know (with OTW) // Ep 6
1 year ago 00:13:11 0
This MINI PC ships with SPYWARE! 🦠 ⚠️ I almost lost everything 😳
1 year ago 00:40:05 0
Malware Analysis - Unpacking AutoIt stub with large obfuscated script