Live Stream VOD: Reversing Dridex Shellcode Injection, and Fixing API Calls (Patreon)
Published:
2021-12-02 14:01:02
Imported:
2022-12
Flagged
Content
Twitch live stream VOD. We take a look at the (doppeldridex) Dridex loader binary and begin building out the struct that is used for it's injected code. We also realize we should have read Chong's blog and actually patched API called to save us a lot of trouble... this was a struggle stream...
Sample available on Malshare:
c7990f1e72fdfa84552f02f9d11cabb74251b0508291af5366fefcee646f9c91
Lab Notes - includes code samples: