Home Artists Posts Import Register
Patreon importer is back online! Tell your friends ✅

Content

In this twitch stream we begin our triage of the Matanbuchus loader malware. First, we resolve the API hashes, and decrypt the strings, then we attempt to build a Yara rule and and automated config extractor.

Stream Bookmarks

  • 00:31:00  We conclude our research and begin reverse engineering.
  • 01:09:00  We start using Dumpulator and run into some issues.
  • 03:55:00  Duncan shows up and give us some code for Dumpulator and we finish our string extraction.

Sample

f8cc2cf36e193774f13c9c5f23ab777496dcd7ca588f4f73b45a7a5ffa96145e

Notes

Matanbuchus Triage Notes 


Files

Live Stream VOD: Matanbuchus Triage - Part 1

This is "Live Stream VOD: Matanbuchus Triage - Part 1" by OALABS on Vimeo, the home for high quality videos and the people who love them.

Comments

j0s3

Watched the whole thing. Funny episode ;)

RussianPanda

Great stream! I missed the second part though :(