Home Artists Posts Import Register
Join the new SimpleX Chat Group!

Content

This is our first look at SmokeLoader, we begin with analysis of Stage 2 (unpacked automatically). The binary is obfuscated using a mixture of simple opaque predicates, and encrypted functions that are decrypted on the fly. 


Honestly, this is a very slow paced stream. We do make progress and end up with a binary that is fully deobfuscated but there are many tricks still before we can extract Stage 3! You can skip ahead about 2h to get to the real deobuscation work. 

Samples

Notes

SmokeLoader Triage 

Files

Live Stream VOD: SmokeLoader Analysis Part 1 - Deobfuscation

This is "Live Stream VOD: SmokeLoader Analysis Part 1 - Deobfuscation" by OALABS on Vimeo, the home for high quality videos and the people who love them.

Comments

No comments found for this post.