Professional Documents
Culture Documents
Yevgeny Kulakov
@p_h_0_e_n_i_x
About Me
sandbox development
Demo
Future work
Malware vs Reverser
Make me suffer
Some examples of
annoying behaviour
Code (un)packing
Stack-based execution
API based
device enumeration
ASM based
svchost.exe
watchdog
Sample explorer.exe
operational CnC, rootkit
deployment
Kernel
Permission
Elevation
Obfuscate at rest
MazeWalker Tool
PinTool
Callbacks on everything
instructions
VM in essence API calls
Image loading
Multi-platform
Threads, Exceptions
memory read/writes
Code unpacking - memory
Harder to detect
Configurable
OpenProcess API
Control Flow Graph
Navigate
the execution flow
Work on Memory
Part Only
Focus