Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 03-07-2025, 17:39
ldmd ldmd is offline
Friend
 
Join Date: Sep 2023
Location: What's that?
Posts: 13
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 8
Thanks Rcvd at 26 Times in 6 Posts
ldmd Reputation: 3
Unhappy Malware Analysis

Recently, I shifted from working on crackmes to malware analysis. I tried to write a blog covering some aspects, as detailing everything I did would have made it too long. However, I’m not quite satisfied with what I have written. I’d really appreciate it if you could take a look and provide feedback.

Blog: https://www.mblog.pro/blog/malware

The sample I analyzed is from MalwareBazaar, and here is a VirusTotal link:
https://www.virustotal.com/gui/file/3fef5c7fa519f5384de6f61c954ead6dfd4da727005bfec954dc801bd120a938
Reply With Quote
The Following User Says Thank You to ldmd For This Useful Post:
tonyweb (03-09-2025)
  #2  
Old 03-08-2025, 02:24
sendersu sendersu is offline
VIP
 
Join Date: Oct 2010
Posts: 1,305
Rept. Given: 337
Rept. Rcvd 237 Times in 127 Posts
Thanks Given: 340
Thanks Rcvd at 652 Times in 357 Posts
sendersu Reputation: 200-299 sendersu Reputation: 200-299 sendersu Reputation: 200-299
hmm
is your site kind of ctf?

https://prnt.sc/xne6zKOkRfXf
Reply With Quote
  #3  
Old 03-08-2025, 17:51
ldmd ldmd is offline
Friend
 
Join Date: Sep 2023
Location: What's that?
Posts: 13
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 8
Thanks Rcvd at 26 Times in 6 Posts
ldmd Reputation: 3
Quote:
Originally Posted by sendersu View Post
hmm
is your site kind of ctf?

https://prnt.sc/xne6zKOkRfXf
Nope, https://prnt.sc/A_2ouiw-OdHf
Reply With Quote
  #4  
Old 03-08-2025, 20:33
JMP-JECXZ JMP-JECXZ is offline
Friend
 
Join Date: Mar 2017
Posts: 123
Rept. Given: 0
Rept. Rcvd 5 Times in 4 Posts
Thanks Given: 15
Thanks Rcvd at 150 Times in 69 Posts
JMP-JECXZ Reputation: 5
you need to activate javascript otherwise site is broken.
Reply With Quote
  #5  
Old 03-08-2025, 22:50
ldmd ldmd is offline
Friend
 
Join Date: Sep 2023
Location: What's that?
Posts: 13
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 8
Thanks Rcvd at 26 Times in 6 Posts
ldmd Reputation: 3
Quote:
Originally Posted by JMP-JECXZ View Post
you need to activate javascript otherwise site is broken.
I didn't intend for the blog to be for a js-disabled browser, so sorry.

Last edited by ldmd; 03-08-2025 at 23:16.
Reply With Quote
  #6  
Old 03-09-2025, 01:58
tonyweb tonyweb is offline
Family
 
Join Date: Jan 2009
Posts: 199
Rept. Given: 200
Rept. Rcvd 96 Times in 37 Posts
Thanks Given: 2,201
Thanks Rcvd at 305 Times in 125 Posts
tonyweb Reputation: 96
A quick look can be taken if you execute something like the following in your browser console:
Code:
document.querySelectorAll(".animate").forEach( elem => { elem.style.opacity = 1 } );
__________________
Want to learn unpacking ... but I'm too stupid

Last edited by tonyweb; 03-09-2025 at 01:59. Reason: Redacted
Reply With Quote
  #7  
Old 03-09-2025, 02:55
sendersu sendersu is offline
VIP
 
Join Date: Oct 2010
Posts: 1,305
Rept. Given: 337
Rept. Rcvd 237 Times in 127 Posts
Thanks Given: 340
Thanks Rcvd at 652 Times in 357 Posts
sendersu Reputation: 200-299 sendersu Reputation: 200-299 sendersu Reputation: 200-299
@tonyweb - means no JS in my lovely Opera?
I dont remember I've deliberately turned it OFF hm hm

https://prnt.sc/0uUfVEVg9SQT
Reply With Quote
  #8  
Old 03-09-2025, 18:42
tonyweb tonyweb is offline
Family
 
Join Date: Jan 2009
Posts: 199
Rept. Given: 200
Rept. Rcvd 96 Times in 37 Posts
Thanks Given: 2,201
Thanks Rcvd at 305 Times in 125 Posts
tonyweb Reputation: 96
@sendersu
I don't see errors in your screenshot (that warning is there to avoid the average user executing whichever javascript snippet found online, without understanding what it does).

Of course you can do it "manually", locating the suitable "main" child-tag inside page source and unchecking the opacity rule.

https://gcdnb.pbrd.co/images/0nwENvl9sHJU.png
__________________
Want to learn unpacking ... but I'm too stupid
Reply With Quote
Reply

Tags
malware, malware analysis, security

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ahk malware analysis dion General Discussion 0 12-20-2021 08:50
Malware Sample analysis Aesculapius Source Code 2 02-13-2018 19:35


All times are GMT +8. The time now is 06:09.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )