Overview
Syllabus
Intro
Building and Reverse Engineering PE
Packer/Cryptor First Generation
Real Malware
Binary Obfuscation
Malware Detection - API Call Monitoring
64bit Windows
Bypassing Behavior-Based Detection
Anti-Analysis Techniques
Malware Loader
living off the Land and Mixing Technologies
Infection Overview
Resolve API functions - Part 1
Self Modifying Code Decoding encoded code from duta section and secute it
PI Call Obfuscation - API Function resolution Part 2
Basics - 64bit API calls
Obfuscate Syscalls
Basics - WoW64 - Subsystem
Heavens Gate - Obfuscation
Decrypt Payload
First Clue
Infection Chain
Powershell Loader
Initial Infection Vector
What Can Defenders Do?
Hunting for Loaders
Dynamic Data Resolver Version 1.0
Taught by
Hack In The Box Security Conference