We unpack a Dridex sample that uses process hollowing for memory execution.
Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: / struppigel
Sample on MalwareBazaar: https://bazaar.abuse.ch/sample/e30b76...
Sample on Hybrid: https://www.hybrid-analysis.com/sampl...
Dridex article: https://countuponsecurity.com/2015/12...
Process hollowing: http://www.autosectools.com/Process-H...
API Monitor: http://www.rohitab.com/apimonitor