Jan. 20, 2024, 7:59 a.m. | MalwareAnalysisForHedgehogs

MalwareAnalysisForHedgehogs www.youtube.com

We create a C2 extractor for APT malware Kopiluwak. For that we need to unpack two layers of code (JScript, VBA) and remove the slight obfuscation. The sample is suitable for beginners who want to train their RE skills with JScript, VBA and C2 extraction. You find the sample download below.

Malware Analysis course: https://www.udemy.com/course/windows-malware-analysis-for-hedgehogs-beginner-training/?couponCode=F880CDBE6684E44EB9F8

binary refinery: https://github.com/binref/refinery
oletools: https://github.com/decalage2/oletools
sample: https://bazaar.abuse.ch/sample/2299ff9c7e5995333691f3e68373ebbb036aa619acd61cbea6c5210490699bb6/
kopiluwak on malpedia: https://malpedia.caad.fkie.fraunhofer.de/details/js.kopiluwak

Follow me on Twitter: https://twitter.com/struppigel

00:00 Intro
01:30 Triage
02:28 VBA extraction and deobfuscation …

analysis apt beginners binary code extraction find jscript malware malware analysis obfuscation refinery remove sample skills suitable train turla unpack vba

Azure DevSecOps Cloud Engineer II

@ Prudent Technology | McLean, VA, USA

Security Engineer III - Python, AWS

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SOC Analyst (Threat Hunter)

@ NCS | Singapore, Singapore

Managed Services Information Security Manager

@ NTT DATA | Sydney, Australia

Senior Security Engineer (Remote)

@ Mattermost | United Kingdom

Penetration Tester (Part Time & Remote)

@ TestPros | United States - Remote