Malware Analysis, Security News and Reverse Engineering.
218 followers 0 articles/week
What's Happening with Necurs, Dridex, and Locky?

Around the 8th of June VICE picked up the story about Necurs' downtime and wrote a great article including a tweet from Kevin Beaumont referencing my botnet tracker. I was contacted for comment and there's a few things i'd have liked to add but at the time i was in London for BSides and may or may not have been incredibly inebriated, so didn't reply...

Tue Jun 21, 2016 18:02
How Cerber's Hash Factory Works

Recently I saw a story on SecurityWeek about how the Cerber ransomware morphs every 15 seconds (each download results in a file with a new hash), which I then tracked back to the source, this article by Invincea. The various news articles made some dubious claims which can be put down to information lost in translation between reporters and an researcher...

Mon Jun 6, 2016 19:15
Infosec Without a Degree

I've seen plenty blogs from people who got into infosec through the academic route, so i figured I'd cover the other side and try to answer the three most asked questions I get via email and twitter: "Do I need a degree to get a job in infosec?", "Will a degree help me get a job in in infosec?", and "How Did You Get Into Infosec?". Though I don't have...

Tue May 31, 2016 18:21
Let's Analyze: Dridex (Part 3)

Sorry for the longer than expected delay, occasionally the Dridex group will take the servers offline during the weekend and resume normal operations on Monday; however, it appears they decided to take an extended break as the network went offline at some point a week ago, preventing me from fetching the payload. If like me you got caught out by the...

Tue May 10, 2016 17:12
Let's Analyze: Dridex (Part 2)

In the previous article we went over how to dump the names of the majority of functions dridex resolves dynamically to complicate analysis. Today we will be using some similar methods to get the other main piece of the puzzle (encrypted string). Encrypted Strings As we've already got a nice list of functions called, we can look for those involved...

Tue Apr 19, 2016 18:41
Let's Analyze: Dridex (Part 1)

Due to popular request I'm starting a new reverse engineering article series which will detail how I go about analyzing various samples, instead of just presenting my findings like I normally do. Most of the posts will be centered around IDA Pro (evaluation edition should work too) with WinDbg as a backend (you can use whatever backend you're comfortable...

Mon Mar 21, 2016 18:41

Build your own newsfeed

Ready to give it a go?
Start a 14-day trial, no credit card required.

Create account