malware analysis #7 ( radare2 ESIL ) - heap functional analysis r2

Опубликовано: 20 Март 2026
на канале: ReverseiT
594
28

Today we will simulate the second half of the opcode in the heap and help ESIL up a bit, by patching the binary. Radare2 opcode analysis of unveiled code in the heap.

table of contents:
00:00 intro
00:36 chapter I - find name pointer
03:15 chapter II - create export addresses
04:45 chapter III - addresses or names, that is the question
06:11 chapter IV - last code block heap
10:05 outro

hardware
microphone: MXL 990 Condenser Microphone
interface: Audient iD4 Audio USB-Interface

software
recording: Open Broadcaster Software
cut: Shotcut

❤ Thankfully, Kampret Botak reminded me that the seventh part was a simple copy of the sixth part. Thank you so much.