Malware Analysis - 3CX SmoothOperator ffmpeg.dll with Binary Ninja

Опубликовано: 13 Октябрь 2024
на канале: MalwareAnalysisForHedgehogs
2,838
97

We analyze the trojanized ffmpeg.dll that was used in the supply chain attack called SmoothOperator. Me mark up the decompiled code in Binary Ninja and decrypt the next stage.

My malware analysis course for beginners: https://www.udemy.com/course/windows-...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter:   / struppigel  

Tools:
Binary Ninja: https://binary.ninja/
PortexAnalyzerGUI: https://github.com/struppigel/PortexA...
Sysinternals: https://learn.microsoft.com/en-us/sys...

Samples:
3CXDesktopApp.msi: https://tria.ge/230330-3nzfjshc2s
ffmpeg: https://bazaar.abuse.ch/sample/7986bb...
d3dcompiler_47.dll: https://bazaar.abuse.ch/sample/11be18...

00:00 Intro
00:36 Bleepingcomputer article
03:03 3CXDesktopApp.msi unpacking
03:50 Finding the malicious code
09:00 Marking up the code in Binary Ninja
19:24 Certificate parser markup
30:51 Decryption function
33:31 Unpacking code from d3dcompiler_47.dll
36:45 Outro

#malware #malwareanalysis #reverseengineering #3cx #msi #unpacking #shellcode #binaryninja