Malware Analysis - When De4dot fails, Removing Anti Tamper from NullShield

Опубликовано: 12 Октябрь 2024
на канале: MalwareAnalysisForHedgehogs
14,418
197

Decompilation fails and de4dot cannot deobfuscate this trojan spy named Evrial. We discover code in the module's constructor (.cctor) that fixes the assembly.

My malware analysis course for beginners: https://www.udemy.com/course/windows-...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter:   / struppigel  

sample virusbay: https://beta.virusbay.io/sample/brows...
sample malshare: https://malshare.com/sample.php?actio...
sample HA: https://www.hybrid-analysis.com/sampl...
de4dot: https://github.com/0xd4d/de4dot
dnSpy: https://github.com/0xd4d/dnSpy/releases
ILSpy: https://github.com/icsharpcode/ILSpy
Reflexil: http://reflexil.net/