Click here to download all references as Bib-File.•
2024-06-16
⋅
cocomelonc
⋅
Malware development trick 40: Stealing data via legit Telegram API. Simple C example. |
2024-06-12
⋅
cocomelonc
⋅
Malware development trick 39: Run payload via EnumDesktopsA. Simple Nim example. |
2024-06-01
⋅
cocomelonc
⋅
Malware and cryptography 28: RC4 payload encryption. Simple Nim example. |
2023-12-13
⋅
cocomelonc
⋅
Malware in the wild book AsyncRAT Babuk BlackCat BlackLotus Carbanak HelloKitty Paradise Stealc WinDealer |
2023-12-10
⋅
cocomelonc
⋅
Malware development: persistence - part 23. LNK files. Simple Powershell example. Emotet |
2023-11-23
⋅
cocomelonc
⋅
Malware and cryptography 22: encrypt/decrypt payload via XTEA. Simple C++ example. |
2023-11-07
⋅
cocomelonc
⋅
Malware development trick - part 37: Enumerate process modules via VirtualQueryEx. Simple C++ example. |
2023-10-20
⋅
cocomelonc
⋅
Malware and cryptography 21: encrypt/decrypt payload via WAKE. Simple C++ example. |
2023-09-25
⋅
cocomelonc
⋅
Malware development trick - part 36: Enumerate process modules. Simple C++ example. 4h_rat Aria-body |
2023-08-28
⋅
Github (cocomelonc)
⋅
Malware and cryptography 20: encrypt/decrypt payload via Skipjack. Simple C++ example. |
2023-08-13
⋅
Github (cocomelonc)
⋅
Malware and cryptography 1: encrypt/decrypt payload via RC5. Simple C++ example. |
2023-07-26
⋅
cocomelonc
⋅
Malware development trick - part 35: Store payload in alternate data streams. Simple C++ example. Valak POWERSOURCE Gazer PowerDuke |
2023-07-16
⋅
Github (cocomelonc)
⋅
Malware development: persistence - part 22. Windows Setup. Simple C++ example. |
2023-07-15
⋅
MSSP Lab
⋅
Malware source code investigation: BlackLotus - part 1 BlackLotus |
2023-07-13
⋅
MSSP Lab
⋅
Malware analysis report: BlackCat ransomware BlackCat BlackCat |
2023-07-07
⋅
Github (cocomelonc)
⋅
Malware development trick - part 34: Find PID via WTSEnumerateProcesses. Simple C++ example. |
2023-06-26
⋅
Github (cocomelonc)
⋅
Malware AV/VM evasion - part 18: encrypt/decrypt payload via modular multiplication-based block cipher. Simple C++ example. |
2023-06-23
⋅
MSSP Lab
⋅
Malware source code investigation: Paradise Ransomware Paradise |
2023-06-19
⋅
Github (cocomelonc)
⋅
Malware AV/VM evasion - part 17: bypass UAC via fodhelper.exe. Simple C++ example. Glupteba |
2023-06-15
⋅
Github (cocomelonc)
⋅
Malware analysis report: Babuk ransomware Babuk |