XXX4Fans
oalabs from patreon

oalabs

patreon


oalabs posts

Live Stream VOD: Dumpulator vs. Guloader VEH Obfuscation

oalabs post Live Stream VOD: Dumpulator vs. Guloader VEH Obfuscation from patreon

In this twitch stream we take another look at Guloader's VEH obfuscation using Dumpulator. With Dumpulator we are able to bypass the obfuscation to extract the encrypted strings, as well as create a simple instruction color trace in IDA to identify...

View Post

Live Stream VOD: Unicorn Emulation Tricks (Guloader Part 5)

oalabs post Live Stream VOD: Unicorn Emulation Tricks (Guloader Part 5) from patreon

In this twitch stream we explore some of the more advanced features available for emulation with unicorn. We revisit Guloader for a fifth time and write a fully automated string decryption script with the emulator.

Sample

2023-01-13 19:34:18 +0000 UTC View Post

Live Stream VOD: Guloader ( Part 4 ) Deobfuscation

oalabs post Live Stream VOD: Guloader ( Part 4 ) Deobfuscation from patreon

In this twitch stream we take a fourth look at Guloader and finally fully deobfuscate the control flow (VEH redirect) and write a simple string decryptor.

This stream is sort of a wrap up of all the previous streams, we fully fix the control flow obfuscation and use an IDA plugin to removed the VEH redirection. We also ...

View Post

Live Stream VOD: Guloader ( Part 3 ) String Decryption and Debugging

oalabs post Live Stream VOD: Guloader ( Part 3 ) String Decryption and Debugging from patreon

In this twitch stream we take a third look at Guloader and begin our analysis of the final stage shell code. The code has been updated from the first sample we looked at but some of the same structure is present which helps with analysis (bindiff!).

Heads up: Once we get stuck on trying to find the decr...

View Post

Live Stream VOD: Reverse Engineering AMA 2022

oalabs post Live Stream VOD: Reverse Engineering AMA 2022 from patreon

This stream was a bit different... we invited eight reverse engineers on to answer your questions! Due to the nature of the stream the VOD has been edited into segments that are loosely organized around a specific question.

A big thanks to everyone who joined to help us out!


Rattle (Jesko) View Post

Live Stream VOD: Guloader NSIS Delivery Analysis

oalabs post Live Stream VOD: Guloader NSIS Delivery Analysis from patreon

In this twitch stream we take a second look at Guloader with a focus on its highly obfuscated delivery chain. An NSIS loader is used to execute multiple layers of obfuscated PowerShell which eventually lead to the Guloader shell code.

The goal of this stream is to better understand the obfuscated NSIS delivery technique...

View Post

Live Stream VOD: Guloader Shellcode Analysis

oalabs post Live Stream VOD: Guloader Shellcode Analysis from patreon

In this twitch stream we take on Guloader. Our approach combines both static and dynamic analysis to bypass the the numerous anti-analysis techniques which make this malware infamous. 

The stream goal is not a full analysis of all of the anti-analysis tricks (10 streams later lol) but instead we want to understand ...

View Post

Live Stream VOD: Brute Ratel Analysis with @BoymoderRE

oalabs post Live Stream VOD: Brute Ratel Analysis with @BoymoderRE from patreon

In this twitch stream we collaborate with @BoymoderRE and take a second look at Brute Ratel. We are using IDArling to share IDB files and while she works on the actual reve...

View Post

Live Stream VOD: More GoLang Malware Reverse Engineering - Static Strings Extraction from Titan Stealer

oalabs post Live Stream VOD:  More GoLang Malware Reverse Engineering - Static Strings Extraction from Titan Stealer from patreon

In this twitch stream we continue our GoLang reverse engineering journey with a focus on static extraction of strings with Python. The malware sample we will be testing our methods on is called Titan Stealer, a credential stealer that is sold openly on the internet.

Sample

2022-12-06 23:26:08 +0000 UTC View Post

Live Stream VOD: Reverse Engineering GO Featuring Laplas Clipper

oalabs post Live Stream VOD: Reverse Engineering GO Featuring Laplas Clipper from patreon

In this twitch stream we start to take a serious look at reverse engineering GoLang malware. We use the Laplas Clipper malware to test some IDA tools and generally get a better understanding of how to approach GO.

Note: The stream starts a bit slow and we spend the first 45 minutes doing some recon on t...

View Post

Live Stream VOD: N00bs Night 1 - PowerShell Loader and Shellcode Markup

oalabs post Live Stream VOD: N00bs Night 1 - PowerShell Loader and Shellcode Markup from patreon

In this twitch stream we attempt our first ever N00bs Night where we cover simple reverse engineering topics with an aim to make the stream accessible to everyone! That being said... I'm not sure how well we succeeded πŸ˜…

The first half deals with extracting shell code from a PowerShell loader, and the...

View Post

Live Stream VOD: Tofsee String Decryption Another C++ Win!

oalabs post Live Stream VOD: Tofsee String Decryption Another C++ Win! from patreon

In this twitch stream we take a look at Tofsee a simple spambot written in C++ with a funny string encryption trick. We also discuss some methods for automatically locating string references in assembly.

Samples

2022-11-28 03:49:09 +0000 UTC View Post

Live Stream VOD: AgentTesla Config Extraction with Automated .NET Parsing (dnlib and Python)

oalabs post Live Stream VOD: AgentTesla Config Extraction with Automated .NET Parsing  (dnlib and Python) from patreon

In this twitch stream we use AgentTesla as an example to learn more about automated .NET parsing using dnlib and Python. We are able to locate and decrypt the strings table protected with the open source .NET obfuscator called obfuscar.


Samples

2022-11-20 18:57:18 +0000 UTC View Post

Live Stream VOD: Amadey Analysis Getting Good at C++ STL Struct Reconstruction

oalabs post Live Stream VOD: Amadey Analysis Getting Good at C++ STL Struct Reconstruction from patreon

In this twitch stream we take a look at a new variant of Amadey with an emphasis on putting our new C++ STL reversing skill to the test. We manage to create a very clean marked up IDB which significantly speeds up our RE!

Sample

18A38FA6F5B306243D99621556AF948A61DAED29619AB755E25010F9E254C6BD

Not...

View Post

Live Stream VOD: Reverse Engineering C++ STL Types (First Attempt)

oalabs post Live Stream VOD: Reverse Engineering C++ STL Types (First Attempt) from patreon

In this twitch stream we attempt to define a repeatable process for identifying  MSVC STL types in compiled C++. Dealing with these types has been an issue for us during previous malware analysis adventures and we want to figure out a sane approach... though we do make some headway we are ultimately left with three topic...

View Post

Live Stream VOD: BitRat Analysis (C++) - Part 3

oalabs post Live Stream VOD:  BitRat Analysis (C++) - Part 3 from patreon

In this twitch stream we conclude our three-part series on analyzing RitRat, a C++ RAT that is sold and generally used for eCrime activity but has also been linked to nation-stage backed targeted attacks.

The functionality of this RAT is fairly straight forward but its use of the C++ Standard Template Library makes reve...

View Post

Live Stream VOD: BitRat Analysis (C++) - Part 2

oalabs post Live Stream VOD:  BitRat Analysis (C++) - Part 2 from patreon

In this twitch stream we continue our three-part series on analyzing RitRat, a C++ RAT that is sold and generally used for eCrime activity but has also been linked to nation-stage backed targeted attacks.

The functionality of this RAT is fairly straight forward but its use of the C++ Standard Template Library makes reve...

View Post

Live Stream VOD: BitRat Analysis (C++) - Part 1

oalabs post Live Stream VOD:  BitRat Analysis (C++) - Part 1 from patreon

In this twitch stream we take our first look at RitRat, a C++ RAT that is sold and generally used for eCrime activity but has also been linked to nation-stage backed targeted attacks.

The functionality of this RAT is fairly straight forward but its use of the C++ Standard Template Library makes reverse engineering a cha...

View Post

Live Stream VOD: Building A Simple Malware Tracker for DbatLoader

oalabs post Live Stream VOD: Building A Simple Malware Tracker for DbatLoader from patreon

In this twitch stream we complete our mini two part series on Threat Intelligence by building a simple malware tracker for DbatLoader. 

Notes

2022-10-30 02:35:54 +0000 UTC View Post

Live Stream VOD: What is Threat Intelligence and Why Do We Reverse Engineer Malware

oalabs post Live Stream VOD: What is Threat Intelligence and Why Do We Reverse Engineer Malware from patreon

In this twitch stream we talk about what Threat Intelligence means in practice; how companies use intelligence products, how the products are developed, and how reverse engineering malware fits into the picture...

This is Part 1 of a two part series where we build a simple botnet tracker for dbatloader.

Notes View Post

Live Stream VOD: Icarus Stealer Analysis

oalabs post Live Stream VOD: Icarus Stealer Analysis from patreon

In this twitch stream we take a look at a new .NET RAT openly sold as Icarus. The stream takes an interesting turn when we discover the C2 infrastructure is incorrectly configured...

Samples

2022-10-16 22:58:26 +0000 UTC View Post

Live Stream VOD: Building a Config Extractor for ISFB

oalabs post Live Stream VOD: Building a Config Extractor for ISFB from patreon

In this twitch stream we take a look at Gozi / ISFB / RM3 etc. and develop a config extractor which works on the latest variants. This is mostly a coding stream where we update an old extractor and make it work with modern samples.

Samples

2022-10-16 22:54:41 +0000 UTC View Post

Process Memory Basics for Reverse Engineers Module 3 - Memory Protections

oalabs post Process Memory Basics for Reverse Engineers Module 3 - Memory Protections from patreon

This is the third and final part in our three-part series on process memory with a focus on tracking memory with a debugger. In this tutorial we look at process memory protections and specifically how the PAGE_GUARD works, and what a memory "breakpoint" is in x64dbg.

Further Reading

Process Memory Basics for Reverse Engineers Module 2 - Heap Memory

oalabs post Process Memory Basics for Reverse Engineers Module 2 - Heap Memory from patreon

This is the second part in our short three-part series on process memory with a focus on tracking memory with a debugger. In this tutorial we look at the heap and how to investigate heap memory with x64dbg.

Further Reading

Live Stream VOD: Leaked LockBit Ransomware Builder Analyzed

oalabs post Live Stream VOD: Leaked LockBit Ransomware Builder Analyzed from patreon

In this Twitch stream we take a look at the recently leaked LockBit Ransomware Builder. We compare our previous RE analysis of the ransomware binary with the actual builder config (some surprises, but we were mostly correct). And we take a look the possibility of the building being used by individual unaffiliated Threat Actor...

View Post

Process Memory Basics for Reverse Engineers Module 1 - Watching Memory Allocations With a Debugger

oalabs post Process Memory Basics for Reverse Engineers Module 1 - Watching Memory Allocations With a Debugger from patreon

This is the first in a short three-part series on memory allocation with a focus on tracking memory with a debugger. In this tutorial we look at the basics, how is memory allocated, and how to follow memory allocations with x64dbg.


Further Reading

Live Stream VOD: Clipboard Hijacking Detection

oalabs post Live Stream VOD: Clipboard Hijacking Detection from patreon

In this Twitch stream we take a look at a simple malware (great for practicing RE) that is used to steal crypto by substituting wallet addresses that are copy pasted from the clipboard. 

We analyze the malware functionality and build some static detection with a Yara rule so we can generically identify this behavio...

View Post

Live Stream VOD: PrivateLoader Analysis

oalabs post Live Stream VOD: PrivateLoader Analysis from patreon

In this twitch stream we take a look at PrivateLoader, a pay-per-install malware that contains a lot of anti-analysis tricks (junk code, stack strings, etc.) Our main focus in the stream is building a working string decryption tool that doesn't rely on IDA. 

Sample

2022-09-22 16:50:55 +0000 UTC View Post

Live Stream VOD: DbatLoader Analysis

oalabs post Live Stream VOD: DbatLoader Analysis from patreon

In this twitch stream we take a look at dbatloader, a simple Delphi downloader that is used to download and execute other malware. This would be a straightforward analysis except the binary is written in Delphi and requires a lot of time to untangle... jump ahead to around 3:30 to get to the part where we begin to make progre...

View Post

Live Stream VOD: SmokeLoader Analysis Part 3 - Stage 3 Decrypted and Config Extracted

oalabs post Live Stream VOD: SmokeLoader Analysis Part 3 - Stage 3 Decrypted and Config Extracted from patreon

The conclusion to our analysis of SmokeLoader! All the secrets are revealed and it's grrr-eat! We finally figure out the missing piece for the API hashes and resolve them. This leads us to the missing piece of the puzzle for extracting Stage 3 - LZSA2 decompression! 

Once we have decrypted and decompressed Stage 3 ...

View Post