Skip to content

Latest commit

 

History

215 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Malware Analysis and Reverse Engineering


54bda352b17744efa1f6898040455423

Malware analysis and malware reports...

Analyses are organized by target platform: Windows, Linux, macOS, and Cross-Platform.


🪟 Windows

# Malware / Topic Platform / Type
1 Reverse Engineering a Packed Trojan Malware Reverse Engineering
2 Bangladesh GPCA Targeted Cyber Espionage
3 Cobalt Strike Beacon Command-and-Control Framework
4 Patching a Malware Malware Modification Technique
5 Regin Malware Advanced Persistent Threat (APT)
6 RansomWare WannaCry Ransomware Malware
7 Qak bot Malware Unpacking Advanced Loader / Unpacking
8 notepad++ Chrysalis Backdoor Supply Chain Attack / APT Backdoor
9 Agent Tesla InfoStealer / Remote Access Trojan
10 Shellcode Extraction Cobalt Strike / Loader Analysis
11 Automated Unpacking Automated Unpacking using mal_unpack tool
12 DLL Malware DLL Malware Emotet
13 Debugging Malware Debugging Malware: Manually Extracting a Hidden Cobalt Strike Beacon
14 Deconstructing Emotet Deconstructing Emotet Malware - Manual Unpacking
15 API Unhooking Reverse engineered a Gazprom ransomware sample to study its API unhooking
16 Analyzing WhisperGate MBR Wiper Destructive malware targeting Ukraine
17 NotPetya Ransomware Ransomware
18 Bypassing IsDebuggerPresent How to bypass IsDebuggerPresent
19 Reversing a Packed AutoIt Malware Sample Reverse engineering walkthrough of a packed AutoIt malware sample covering anti-debugging bypass, RWX memory analysis, shellcode extraction, and dynamic API resolution.
20 Reversing Hash-Based API Resolution How Malware Resolves APIs Using Pre-Computed Hashes: No Imports, No Strings
21 Dynamic API Resolution Analyze code that locates the image base of NTDLL , Demonstrate how to dynamically explore related structures, Begin to understand how an import table is dynamically constructed
22 Shellcode Triage and API Resolution Shellcode Triage and API Resolution with capa and Binary Ninja
23 Malware Binary Diffing Malware Binary Diffing with Ghidra & BinDiff: Comparing Conti and LockBit Green
24 Extracting a Hidden Malware Payload with x64dbg Dynamic malware analysis using x64dbg to trace VirtualAlloc, monitor memory allocation, and extract a hidden Cobalt Strike Beacon payload from process memory.
25 Malware String Deobfuscation with x64dbg Conditional Breakpoints Learn how to use x64dbg conditional breakpoints to automatically log deobfuscated malware strings and quickly identify executable memory regions during dynamic malware analysis.
26 EtherRAT: Ethereum-Based C2 Analysis Technical analysis of EtherRAT covering multi-stage payload extraction and decryption, reverse engineering, Ethereum smart-contract C2 configuration, historical C2 infrastructure, persistence, and randomized HTTP communication.
27 Unpacking Modified UPX Malware Learn how to identify and unpack malware protected with a modified UPX packer, analyze the custom packing modifications, locate the original entry point (OEP), dump the unpacked payload, and perform post-unpacking analysis using x64dbg and reverse-engineering techniques.

🍎 macOS

# Malware / Topic Platform / Type
1 AMOS MacOS Malware Atomic MacOS Malware Analysis - Reversing Xor encryption, decrypting strings.
2 Macho static analysis Reverse Engineering a Malware That Refused to Run Without Python
3 Kitty Stealer macOS infostealer targeting browser credentials and cryptocurrency wallets.
4 Digit Stealer multi-stage macOS malware campaign functions as a full-spectrum infostealer and crypto-hijacker (targeting browsers, keychains, Telegram, VPNs, and Ledger Live) that uses native AppleScript/JXA for credential phishing and data exfiltration.
5 RustBucket (Part 1) PART-1 Mach-O internals, Universal Binary, ARM64/x86_64, static triage
6 RustBucket (Part 2) PART-2 From Swift Symbols to ARM64 Assembly: Uncovering RustBucket's Execution Chain, runtime reversing, Ghidra decompilation, and detection rules

🐧 Linux

# Malware / Topic Platform / Type
1 Mirai Botnet Reversing Mirai Botnet
2 Linux Backdoor BPFDoor Stealthy Linux Backdoor

🌐 Cross-Platform

# Malware / Topic Platform / Type
1 NPM Axios NPM Supply Chain Attack (Windows / macOS / Linux RAT)
2 Cyber Talents CTFs Malware Reversing CTF Challenges
3 Other Reports Miscellaneous Analysis Reports

About

Malware Analysis and Reverse Engineering, Malware Analysis Reports..........

Topics

Resources

Stars

2 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages