Город МОСКОВСКИЙ
00:16:06

Reverse Engineering Anti-VM Detections in Malware - Subscriber Request Part 2

Аватар
Python творец
Просмотры:
26
Дата загрузки:
03.12.2023 17:55
Длительность:
00:16:06
Категория:
Обучение

Описание

Open Analysis Live! This is Part 2 of a two part subscriber request asking us to determine "Why didn't the malware run in my sandbox?". We use IDA Pro with the remote debugger to identify the virtual machine detections. Then we patch out the detection with a hex editor so the malware will run in our sandbox.

-----
OALABS DISCORD
https://discord.gg/6h5Bh5AMDU

OALABS PATREON
https://www.patreon.com/oalabs

OALABS TIP JAR
https://ko-fi.com/oalabs

OALABS GITHUB
https://github.com/OALabs

UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/

-----

In Part 1we unpacked the malware so we could analyze it. You can watch the tutorial here:
https://youtu.be/HfSQlC76_s4

Packed sample:
Sha256: 16540597E03AC70BEA055AA72BF83A7DC3276CF6A64CD6CAFDB09E05EBCC198B
https://malshare.com/sample.php?action=detail&hash=f834f898969cd65da702f4b4e3d83dd0

Unpacked sample (what we are analyzing in the video):
https://malshare.com/sample.php?action=detail&hash=002fe8e54c6dcf7160843282e6052aca

Patched sample (will run in sandbox):
http://malshare.com/sample.php?action=detail&hash=9c8e3500e013982a4cbe2ba6fea801f4

NtShutdownSystem docs:
http://undocumented.ntinternals.net/index.html?page=UserMode%2FUndocumented%20Functions%2FHardware%2FNtShutdownSystem.html

How to stop malware from shutting down your system:
https://blogs.technet.microsoft.com/brad_rutkowski/2007/08/25/how-to-catch-shutdowns-that-dont-go-to-debugger-or-cause-bugchecks/

Common virtual machine detection techniques:
https://shasaurabh.blogspot.ca/2017/07/virtual-machine-detection-techniques.html

Tutorial of how to patch a binary with a hex editor:
https://youtu.be/Zb8rkVjj-mQ

Feedback, questions, and suggestions are always welcome : )

Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw

As always check out our tools, tutorials, and more content over at http://www.openanalysis.net

Рекомендуемые видео