macOS Malware Analysis — Part 2: Reverse Engineering RustBucket
In-depth analysis of a macOS sample focusing on Mach-O internals, ARM64 assembly, Swift symbols, and reverse engineering techniques used to understand its functionality.
Reverse engineering, malware analysis, and adversary tradecraft — documented through technical investigations.
In-depth analysis of a macOS sample focusing on Mach-O internals, ARM64 assembly, Swift symbols, and reverse engineering techniques used to understand its functionality.
Analysis of a modified UPX-packed executable, focusing on PE header reconstruction, section metadata, and techniques to recover a valid structure for further static analysis.
Technical analysis of Digit Stealer, examining sample artifacts, infrastructure, and key implementation details observed in the campaign.
Explore macOS Mach-O binary architecture, examining load commands, segments, and sections to build foundational reverse engineering skills.
Reverse engineer the AMOS Mach-O infostealer to uncover rolling XOR string decryption routines and extract harvested keychain and browser credentials.
Analyze a lightweight macOS infostealer that harvests browser credentials, local keychains, and cryptocurrency wallets for exfiltration via Telegram.
Decompile an obfuscated AutoIt script, analyze runtime RWX memory allocations in WinDbg, and isolate injected shellcode bypassing ASLR.
Examine the IsDebuggerPresent API in x32dbg and learn how patching the Process Environment Block BeingDebugged flag defeats basic anti-analysis checks.
Unpack a 32-bit ARM Mirai ELF variant and examine its network scanning routines, persistence mechanisms, and command-and-control infrastructure.
Decompile an ARM64 Mach-O sample in Binary Ninja to uncover embedded scripts and identify why it requires an external Python runtime environment.
Reverse engineer the BPFDoor Linux backdoor to analyze how raw sockets and Berkeley Packet Filters bypass firewalls for covert remote access.
Debug a high-entropy 64-bit loader with x64dbg, intercepting VirtualAlloc allocations to manually extract and dump an embedded Cobalt Strike beacon.
Modify binary instructions using x64dbg and Ghidra to bypass anti-analysis routines, neutralize evasion checks, and force execution down desired paths.
Trace an obfuscated Emotet shellcode loader resolving APIs dynamically through the PEB and unpacking its DLL payload via rundll32 execution.
Automate malware unpacking with mal_unpack to dynamically intercept, dump, and reconstruct obfuscated position-independent shellcode and PE payloads.
Extract and reconstruct raw 64-bit Cobalt Strike HTTP(S) stager shellcode from memory buffers, analyzing payload execution in unmapped space.
Deconstruct the WannaCry ransomware architecture, analyzing its EternalBlue SMB propagation worm, kill-switch domain check, and hybrid RSA/AES encryption.
Deconstruct custom Cobalt Strike beacon loaders in C and Rust, focusing on Early Bird APC queue injection and in-memory execution evasions.
Analyze a stealthy Regin Stage 1 kernel loader driver, uncovering embedded XOR configurations, kernel module resolution, and staging mechanisms.
Analyze the WhisperGate wiper to examine how it overwrites the Master Boot Record and permanently corrupts files while masquerading as ransomware.
Reverse engineer the EtherRAT JavaScript loader and emulate its decryption routines in Python to uncover smart-contract-based C2 infrastructure.
Examine how NotPetya overwrites the Master Boot Record and weaponizes PsExec and WMI for rapid lateral movement across enterprise networks.
Trace a packed Windows trojan using Ghidra and x64dbg to observe self-modifying code, dynamic API resolution, and in-memory PE header reconstruction.
Decode the custom-encrypted gpca.dat payload used in the Bangladesh cyber heist, analyzing how the nroff b.exe loader interacts with financial systems.
Set targeted memory breakpoints in x64dbg to intercept payload injection, locate unencrypted memory buffers, and dump hidden Cobalt Strike beacons.
Investigate a supply-chain attack using a trojanized Notepad++ update installer to insert dynamic API hooks and establish persistent backdoor access.
Analyze an RTF exploit weaponized to drop Agent Tesla, tracing how the in-memory .NET payload harvests credentials across browsers and email clients.
Unpack a packed Emotet loader in x64dbg by bypassing anti-debugging checks and dumping the decrypted core binary directly from process memory.
Trace Qakbot unpacking routines to bypass multi-layer code obfuscation, decrypt embedded PE resources, and recover the core banking trojan payload.
Compare Conti and LockBit Green binaries using Ghidra and BinDiff to identify shared code, cryptographic overlaps, and architectural differences.
Walk the Windows PEB to locate NTDLL in memory, parse Export Address Tables, and dynamically reconstruct Import Address Tables without static imports.
Identify pre-computed checksum algorithms, trace hashing logic, and resolve Windows APIs dynamically in binaries stripped of import tables and strings.
Automate raw shellcode triage using CAPA and Binary Ninja with HashDB plugins to rapidly decode hashed API calls and map malicious capabilities.
Automate malware string deobfuscation in x64dbg using conditional breakpoints and logging commands to extract decoded strings at runtime without scripts.
Investigate API unhooking techniques in the Gazprom ransomware, demonstrating how malware neutralizes EDR inline hooks to execute evasive system calls.
Analyze a supply-chain RAT distributed through a typosquatted npm package, examining cross-platform Node.js execution and developer environment targeting.
Solve three reverse engineering CTF challenges, covering 32-bit ELF UPX recovery, Binary Ninja XOR decoding, and x86 assembly register tracing.